Apache ShardingSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-11Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-1947£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache ShardingSphere < 4.0.1
Îó²î¸ÅÊö
Apache ShardingSphereÊÇÒ»Ì׿ªÔ´µÄÂþÑÜʽÊý¾Ý¿âÖÐÐļþ½â¾ö¼Æ»®×é³ÉµÄÉú̬Ȧ£¬£¬£¬£¬£¬£¬ËüÓÉSharding-JDBC¡¢Sharding-ProxyºÍSharding-Sidecar£¨ÍýÏëÖУ©Õâ3¿îÏ໥×ÔÁ¦£¬£¬£¬£¬£¬£¬È´ÓÖÄܹ»»ìÏý°²ÅÅÅäºÏʹÓõIJúÆ·×é³É¡£¡£¡£¡£¡£¡£¡£¡£ËüÃǾùÌṩ±ê×¼»¯µÄÊý¾Ý·ÖƬ¡¢ÂþÑÜʽÊÂÎñºÍÊý¾Ý¿âÖÎÀí¹¦Ð§£¬£¬£¬£¬£¬£¬¿ÉÊÊÓÃÓÚÈçJavaͬ¹¹¡¢Òì¹¹ÓïÑÔ¡¢ÔÆÔÉúµÈÖÖÖÖ¶àÑù»¯µÄÓ¦Óó¡¾°¡£¡£¡£¡£¡£¡£¡£¡£
Apache ShardingSphere±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¾ÓÉÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÌá½»í§ÒâYAML´úÂëʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£Apache ShardingSphereºǫ́µÄÖÎÀíÕ˺ÅÃÜÂëĬÈϾùΪadmin¡£¡£¡£¡£¡£¡£¡£¡£
ͨ¹ý¶ÔApache ShardingSphere´úÂëÆÊÎö£¬£¬£¬£¬£¬£¬·¢Ã÷¿ª·¢Ö°Ô±Ö±½ÓʹÓÃunmarshalÒªÁì¶ÔÊäÈëµÄYAMLÖ±½Ó¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬£¬Ã»ÓÐ×öУÑé¡£¡£¡£¡£¡£¡£¡£¡£
±ÈÕÕ²¹¶¡·¢Ã÷ÐÂÔöClassFilterConstructorÀ´¶Ô´Ë¾ÙÐÐУÑé¡£¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
PoC:https://github.com/Imanfeng/CVE-2020-1947¡£¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐû²¼×îа汾ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÉý¼¶£ºhttps://github.com/apache/incubator-shardingsphere/releases¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://github.com/apache/incubator-shardingsphere/releases


¾©¹«Íø°²±¸11010802024551ºÅ