Apache SolrÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-08-07? Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0193£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
? Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ÊÊÓÃÓÚApache Solr < 8.2.0¡£¡£¡£¡£¡£¡£
? Îó²î¸ÅÊö
Apache SolrÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚLucene£¨Ò»¿îÈ«ÎÄËÑË÷ÒýÇæ£©µÄËÑË÷ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¸Ã²úÆ·Ö§³Ö²ãÃæËÑË÷¡¢±ÊÖ±ËÑË÷¡¢¸ßÁÁÏÔʾËÑË÷Ч¹ûµÈ¡£¡£¡£¡£¡£¡£
´Ë´ÎÎó²î·ºÆðÔÚApache SolrµÄDataImportHandler£¬£¬£¬£¬¸ÃÄ£¿£¿£¿éÊÇÒ»¸ö¿ÉÑ¡µ«³£ÓõÄÄ£¿£¿£¿é£¬£¬£¬£¬ÓÃÓÚ´ÓÊý¾Ý¿âºÍÆäËûÔ´ÖÐÌáÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÔ´ÓÚÓû§ÔÚsolrconfig.xmlÎļþÖÐÉèÖÃÁËDataImportHandler£¬£¬£¬£¬¿ªÆôÁËDataImport¹¦Ð§¡£¡£¡£¡£¡£¡£DataImportHandlerÄ£¿£¿£¿éÔÊÐíÓû§×Ô¼º°üÀ¨¾ç±¾£¬£¬£¬£¬À´¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄ¾ç±¾½»ÓÉת»»Æ÷¾ÙÐÐÆÊÎö£¬£¬£¬£¬ÔÚSolrÆÊÎöµÄÀú³ÌÖв¢Î´¶ÔÓû§µÄÊäÈë×ö¼ì²é£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßÔ¶³ÌÔÚSolrЧÀÍÆ÷ÉÏÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£
? Îó²îÑéÖ¤
EXP: https://github.com/xConsoIe/CVE-2019-0193¡£¡£¡£¡£¡£¡£
? ÐÞ¸´½¨Òé
½«Apache SolrÉý¼¶ÖÁ8.2.0»ò¸ü¸ßµÄ°æ±¾¡£¡£¡£¡£¡£¡£
ÔÝʱÐÞ¸´½¨Ò飺
1¡¢±à¼solrconfig.xml£¬£¬£¬£¬½«ËùÓÐÓÃÀο¿ÖµÉèÖõÄDataImportHandlerÓ÷¨ÖеÄdataConfig²ÎÊýÉèÖÃΪ¿Õ×Ö·û´®£»£»£»£»£»£»
2¡¢È·±£ÍøÂçÉèÖÃÖ»ÔÊÔÊÐíÐŵÄÁ÷Á¿ÓëSolr¾ÙÐÐͨѶ£¬£¬£¬£¬ÌØÊâÊÇÓëDIHÇëÇó´¦Öóͷ£³ÌÐòµÄͨѶ¡£¡£¡£¡£¡£¡£
? ²Î¿¼Á´½Ó
https://issues.apache.org/jira/browse/SOLR-13669


¾©¹«Íø°²±¸11010802024551ºÅ