¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.07.26-2021.08.01£©
2021-08-23
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½XStream¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬¹ûÕæÁËXStreamÖеÄ14¸öÇå¾²Îó²î£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÔì³É¾Ü¾ø·þÎñ¡¢SSRF¡¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
XStreamÊÇÒ»¸öJava¹¤¾ßºÍXMLÏ໥ת»»µÄ¹¤¾ß£¬ÔÚ½«JavaBeanÐòÁл¯¡¢»ò½«XMLÎļþ·´ÐòÁл¯Ê±£¬Ëü²»ÐèÒªÆäËü¸¨ÖúÀàºÍÓ³ÉäÎļþ£¬ÕâʹµÃXMLÐòÁл¯²»ÔÙ·±Ëö¡£
CVE-2021-39140:
¹¥»÷Õß¿ÉÒÔʹÓÃÒÑ´¦Öóͷ£µÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬Õâ»áµ¼ÖÂÒ»¸öÎÞÐÝÖ¹µÄÑ»·£¬´Ó¶øÔì³É¾Ü¾ø·þÎñ¹¥»÷¡£
CVE-2021-39144:
¹¥»÷Õß¿ÉÒÔ²Ù×÷ÒÑ´¦Öóͷ£µÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬´Ó¶øÔÚ·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐÐÏÂÁî¡£
CVE-2021-39139¡¢CVE-2021-39141¡¢CVE-2021-39145¡¢CVE-2021-39146¡¢CVE-2021-39147¡¢CVE-2021-39148¡¢CVE-2021-39149¡¢CVE-2021-39151¡¢CVE-2021-39153¡¢CVE-2021-39154£º
¹¥»÷Õß¿ÉÒÔʹÓÃÒÑ´¦Öóͷ£µÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬´Ó¶øÖ´ÐдÓÔ¶³Ì·þÎñÆ÷¼ÓÔØµÄí§Òâ´úÂë¡£
CVE-2021-39150¡¢CVE-2021-39152£º
¹¥»÷Õß¿ÉÒÔʹÓÃÒÑ´¦Öóͷ£µÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬´Ó¶øÊµÏÖ·þÎñ¶ËÇëÇóαÔì¡£
²Î¿¼Á´½Ó£º
https://x-stream.github.io/security.html#workaround
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
Xstream <= 1.4.17
²»ÊÜÓ°Ïì°æ±¾
Xstream = 1.4.18
Èý. Îó²î·À»¤
3.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÔÚ×îа汾ÖнÓÄɰ×Ãûµ¥µÄ·½·¨ÐÞ¸´ÁËÒÔÉÏÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£ºhttps://x-stream.github.io/download.html
3.2 ÔÝʱ·À»¤²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐÐÉý¼¶²Ù×÷£¬Ò²¿ÉʹÓùٷ½ÌṩµÄ¼Æ»®¾ÙÐÐÔÝʱ»º½â£º
https://x-stream.github.io/security.html#example
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







