CVE-2020-13957 | Apache Solr ConfigSet APIÎļþÉÏ´«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-10-130x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-13957 | ʱ ¼ä | 2020-10-13 |
Àà ÐÍ | ÎļþÉÏ´« | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Apache solr 6.6.0ÖÁ6.6.5 7.0.0ÖÁ7.7.3 8.0.0ÖÁ8.6.2 |
Apache SolrÊÇÓÉJava˵»°¿ª·¢¡¢ÔËÐÐÓÚApache Tomcat»òJettyµÈServletÈÝÆ÷µÄÒ»¸ö¶ÀÁ¢µÄÈ«ÎÄËÑË÷·þÎñÆ÷¡£ËüÖØÒª»ùÓÚHTTPºÍApache LuceneʵÏÖ¡£ÖØÒªÖ°ÄÜÔ̺¬È«ÎļìË÷¡¢ÉäÖбêʾ¡¢·ÖÃæËÑË÷¡¢¶¯Ì¬¾ÛÀà¡¢Êý¾Ý¿â¼¯³É£¬ÒÔ¼°¸»Îı¾µÄ´¦Öá£
0x01 ·ì϶ÏêÇé

2020Äê10ÔÂ12ÈÕ£¬Apache Solr°ä²¼°²È«²¼¸æ£¬ConfigSet API´æÔÚÎļþÉÏ´«·ì϶£¬·ì϶׷×ÙΪCVE-2020-13957¡£¹¥»÷ÕßÄܹ»½áºÏʹÓÃUPLOAD/CREATE²Ù×÷À´Èƹý²é³£¬ÒÔ»ñÈ¡·þÎñÆ÷ȨÏÞ¡£³É¹¦ÀûÓô˷ì϶¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
0x02 ´ëÖý¨Òé
1. ÈôÊÇδʹÓÃConfigSets API£¬Ôò½«ÏµÍ³ÊôÐÔconfigset.upload.enabledÉèÖÃΪfalseÒÔ½ûÓÃUPLOADºÅÁî¡£
²Î¿¼Á´½Ó£º
https://lucene.apache.org/solr/guide/8_6/configsets-api.html
2. ʹÓÃÉí·ÝÑéÖ¤/ÊÚȨ£¬²¢È·±£ÒªÇóºÏ·¨¡£
²Î¿¼Á´½Ó£º
https://lucene.apache.org/solr/guide/8_6/authentication-and-authorization-plugins.html
3. ½«SolrÉý¼¶µ½ 8.6.3»ò¸ü¸ß°æ±¾¡£ÈôÊÇÎÞ·¨Éý¼¶£¬ÔòÀûÓÃSOLR-14663²¼¸æÖеIJ¹¶¡£º
²Î¿¼Á´½Ó£º
https://issues.apache.org/jira/browse/SOLR-14663
4. ²»½«Solr API£¨Ô̺¬Admin UI£©Ïò²»ÊÜÐÅÀµµÄµÚÈý·½¹«¿ª¡£µ÷Õû·À»ðǽսÊõ£¬È·±£Ö»ÓÐÊÜÐÅÀµµÄÍÆËã»úºÍÓû§ÄÜÁ¦½Ó¼û¡£
0x03 ²Î¿¼Á´½Ó
https://www.mail-archive.com/announce@apache.org/msg06149.html
https://issues.apache.org/jira/browse/SOLR-14925
0x04 ¹¦·òÏß
2020-10-12 Apache°ä²¼°²È«²¼¸æ
2020-10-13 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ