¡¾·ì϶¹«¸æ¡¿Spring Frameworkõè¾¶±éÀú·ì϶£¨CVE-2024-38816£©
°ä²¼¹¦·ò 2024-09-13Ò»¡¢¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Spring Frameworkõè¾¶±éÀú·ì϶ | ||
CVE ID | CVE-2024-38816 | ||
·ì϶ÀàÐÍ | õè¾¶±éÀú | ·¢ÏÖ¹¦·ò | 2024-09-13 |
·ì϶ÆÀ·Ö | 7.5 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Spring Framework ÊÇÒ»¸öÖ°ÄÜ׳´óµÄ Java ÀûÓ÷¨Ê½¿ò¼Ü£¬£¬Ö¼ÔÚÌṩ¸ßЧÇÒ¿ÉÀ©´óµÄ¿ª·¢»·¾³¡£¡£
2024Äê9ÔÂ13ÈÕ£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Spring FrameworkÖÐÐÞ¸´ÁËÒ»¸öõè¾¶±éÀú·ì϶£¨CVE-2024-38816£©£¬£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.5¡£¡£
Spring FrameworkÊÜÓ°Ïì°æ±¾ÖУ¬£¬Ê¹ÓÃWebMvc.fn »ò WebFlux.fn£¨ÔÚSpring Web MVC»òSpring WebFlux¿ò¼ÜÖУ©Ìṩ¾²Ì¬×ÊÔ´µÄÀûÓ÷¨Ê½ÈÝÒ×Êܵ½õè¾¶±éÀú¹¥»÷£¬£¬µ±Web ÀûÓ÷¨Ê½Ê¹ÓÃRouterFunctionsÌṩ¾²Ì¬×ÊÔ´²¢ÇÒÀûÓ÷¨Ê½Ê¹ÓÃFileSystemResource»òÀàËÆµÄÅäÖÃÀ´´ÓÎļþϵͳÌṩ¾²Ì¬Îļþʱ£¬£¬ÍþвÕ߿ɻú¹Ø¶ñÒâHTTPÒªÇó½Ó¼ûÖ¸±êÎļþϵͳÉÏSpring ÀûÓ÷¨Ê½¹ý³ÌÓÐȨ½Ó¼ûµÄËÁÒâÎļþ£¬£¬´Ó¶øµ¼ÖÂÊý¾Ýй¶¡£¡£
¶þ¡¢¡¢Ó°ÏìÁìÓò
Spring Framework 5.3.0 - 5.3.39
Spring Framework 6.0.0 - 6.0.23
Spring Framework 6.1.0 - 6.1.12
ÒÔ¼°²»ÊÜÖ§³ÖµÄ¾É°æ±¾¡£¡£
Èý¡¢¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ¸Ã·ì϶ÒѾÐÞ¸´£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º£º£º
Spring Framework 5.3.x£º£º£ºÉý¼¶µ½5.3.40£¨½öÏÞÆóÒµÖ§³Ö£©
Spring Framework 6.0.x£º£º£ºÉý¼¶µ½6.0.24£¨½öÏÞÆóÒµÖ§³Ö£©
Spring Framework 6.1.x£º£º£ºÉý¼¶µ½6.1.13»ò¸ü¸ß°æ±¾
ÏÂÔØÁ´½Ó£º£º£º
https://github.com/spring-projects/spring-framework/tags
3.2 һʱ´ëÊ©
µ±Âú×ãÒÔÏÂÈÎһǰÌáʱ£¬£¬¶ñÒâÒªÇó»á±»×èÖ¹ºÍ»Ø¾ø£º£º£º
l ÀûÓ÷¨Ê½ÖÐÆôÓÃSpring Security HTTP ·À»ðǽ£»£»£»
l ÀûÓ÷¨Ê½ÔÚTomcat »ò Jetty ÉÏÔËÐС£¡£
Òò¶ø£¬£¬ÎÞ·¨Á¢¼´Éý¼¶µÄÊÜÓ°ÏìÓû§¡¢¡¢²»ÊÜÖ§³ÖµÄ¾É°æ±¾Óû§¿Éͨ¹ýÔÚÆäÀûÓ÷¨Ê½ÖÐÆôÓà Spring Security ·À»ðǽ£¬£¬»òÕßÇл»µ½Ê¹Óà Tomcat »ò Jetty ×÷Ϊ Web ·þÎñÆ÷À´»Ø¾ø´ËÀà¶ñÒâÒªÇ󣬣¬´Ó¶ø»º½â¸Ã·ì϶¡£¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÖÆ£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬¹Ø±Õ·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÖÆºÍ×îСȨÏÞ×¼Ôò£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£
3.4 ²Î¿¼Á´½Ó
https://spring.io/security/cve-2024-38816
https://nvd.nist.gov/vuln/detail/CVE-2024-38816
ËÄ¡¢¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-09-13 | ³õ´Î°ä²¼ |
Îå¡¢¡¢¸½Â¼
5.1 OG¶«·½Ìü¼ò½é
OG¶«·½Ìü³ÉÁ¢ÓÚ1996Ä꣬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°OG¶«·½Ìü´óÏ㬣¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£¡£ÔÚÈ«¹ú¸÷Ê¡¡¢¡¢ÊС¢¡¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢¡¢ÇþµÀϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÀö½ÖÐС°å¹ÒÅÆÉÏÊС£¡££¨¹ÉƱ´úÂ룺£º£º002439£©
¶àÄêÀ´£¬£¬OG¶«·½ÌüÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£
5.2 ¹ØÓÚOG¶«·½Ìü
OG¶«·½Ìü°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£¡£
¹Ø×¢ÎÒÃÇ£º£º£º



¾©¹«Íø°²±¸11010802024551ºÅ