CVE-2018-1270:spring-messagingÄ£¿éÔ¶³Ì´úÂëÖ´ÐÐÎó²î
2018-04-12
Pivotal Spring¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬Spring¿ò¼ÜÖб£´æÈý¸öÎó²îÆäÖбàºÅΪCVE-2018-1270µÄÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÔÚÒýÈëÇÒʹÓÃspring-messaging×é¼þʱ¹¥»÷Õß¿Éͨ¹ýWebSocketÏò·þÎñÆ÷¶Ë·¢ËÍЯ´øÓжñÒâ´úÂëµÄSTOMP±¨ÎÄ£¬Ö±½Ó»ñÈ¡·þÎñÆ÷¿ØÖÆÈ¨ÏÞ¡£
Pivotal Spring¹Ù·½4ÔÂ9ÈÕ¶Ô֮ǰÐû²¼µÄͨ¸æ¾ÙÐÐÁ˲¿·ÖÐÞ¶©£¬ÊÜCVE-2018-1270Îó²îÓ°ÏìµÄ°æ±¾ÐÞ¶©ÎªSpring Framework 4.3.15¼°5.0.4¡£
ÏêÇéÇë²Î¿¼ÈçÏÂÁ´½Ó£º
https://pivotal.io/security/cve-2018-1275
Îó²îÓ°Ïì
ÏÖÔÚÒÑÖªÊÜÓ°ÏìµÄPivotal²úÆ·¼°°æ±¾Îª£º
- Spring Framework 5.0 to 5.0.4
- Spring Framework 4.3 to 4.3.15
- ÔçÆÚ¹Ù·½ÒѲ»Ö§³ÖµÄ°æ±¾
²»ÊÜÓ°ÏìµÄ°æ±¾Îª£º
- Spring Framework 5.0.5 to 5.0.6
- Spring Framework 4.3.16 to 4.3.17
Ó°ÏìÅŲé
Îó²î±¬·¢ÓÚspring-messaging×é¼þ£¬¹ØÓÚʹÓÃSpring¿ò¼ÜµÄÓ¦ÓÃϵͳ£¬Ê×ÏÈÅŲéÊÇ·ñÒýÈëÁËspring-messaging×é¼þ²¢ÊµÏÖSTOMPÐÂÎÅ´«Ë͹¦Ð§£¬Éó²éSpring FrameworkµÄ°æ±¾ÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ¡£
ÔÚÓ¦ÓÃϵͳÖÐÖ±½ÓÉó²éMaven/GradleÖÐÒýÈëµÄSpring Framework°æ±¾£¬È磺
org.springframeworkspring-context5.0.4.RELEASE
½â¾ö½¨Òé
Pivotal Spring¹Ù·½ÒѾÔÚа汾ÖжԱ¬³öµÄÎó²î¾ÙÐÐÁËÐÞ¸´£¬ÊÜÎó²îÓ°ÏìµÄÓû§Ç뾡¿ìÉý¼¶¿ò¼Ü°æ±¾¡£
Spring¹Ù·½µØµã£º
https://projects.spring.io/spring-framework/
¿ª·¢Ö°Ô±¿Éͨ¹ýÉèÖÃMaven»òÕßGradleµÄ·½·¨£¬Éý¼¶¿ò¼Ü²¢±àÒëÐû²¼¡£
MavenÉèÖÃ
org.springframeworkspring-context5.0.5.RELEASEGradleÉèÖÃ
dependencies { compile 'org.springframework:spring-context:5.0.5.RELEASE' }
Îó²î¼òÎö
spring-messagingÄ£¿éʵÏÖSTOMP£¨Simple Text-Orientated Messaging Protocol£©ÐÒ飬ͨ¹ýWebSocket¾ÙÐÐSTOMP±¨ÎĵÄÊý¾Ý½»»¥¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½¨ÉèWebSocketÅþÁ¬²¢·¢ËÍÒ»ÌõÐÂÎÅÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£

AG¹«Ë¾ÔÆ





