Jackson-databindÔ¶³Ì´úÂëÖ´ÐÐÎó²î £¨CVE-2017-17485£©
¿ËÈÕ£¬Jackson-databindÓÖÆØ³öÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¸ÃÎó²îΪ֮ǰÎó²î£¨CVE-2017-7525£©µÄºóÐø£¬ÐÎòÁËÁíÒ»ÖÖÕë¶ÔJackson-databindµÄ¹¥»÷£¬
¹¥»÷Õß¿ÉÒÔͨ¹ýJacksonÀÄÓÃSpring classesµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
https://www.securityfocus.com/archive/1/541652
https://github.com/irsl/jackson-rce-via-spel/
ÊÜÓ°ÏìµÄ°æ±¾
? Jackson-databind version 2.9.3
? Jackson-databind version 2.7.9.1
? Jackson-databind version 2.8.10
²»ÊÜÓ°ÏìµÄ°æ±¾
? Jackson-databind version 2.9.3.1
? Jackson-databind version 2.7.9.2
? Jackson-databind version 2.8.11
¹Ù·½½«ÔÚа汾ÖÐͨ¹ýÀ©Õ¹ºÚÃûµ¥µÄ·½·¨À´ÐÞ¸´¸ÃÎó²î£¬ÊÜÓ°ÏìµÄÓû§Ç뾡¿ìÉý¼¶µ½Ð°汾¾ÙÐзÀ»¤¡£
ÁíÍ⣬δÀ´Jackson-dababindµÄ×îÐÂÖ÷Òª°æ±¾£¨3.x£©½«Ê¹ÓÃеÄAPI£¬¸ÃAPI layer¿ÉÒÔÌṩһÖÖ»ùÓÚ°×Ãûµ¥µÄÐòÁл¯·½·¨À´´¦Öóͷ£¶à̬Àࣨpolymorph classes£©£¬ÒԴ˽â¾ö¸ÃϵÁÐÎó²î¡£
²Î¿¼Á´½Ó£º
https://github.com/FasterXML/jackson-databind/releases
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ





