Apache Dubbo·´ÐòÁл¯Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-12Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-17564£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
2.7.0 <= Apache Dubbo <= 2.7.4
2.6.0 <= Apache Dubbo <= 2.6.7
Apache Dubbo = 2.5.x
Îó²î¸ÅÊö
Apache DubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³ÌЧÀÍŲÓüƻ®£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°SOAЧÀÍÖÎÀí¼Æ»®¡£¡£¡£¡£¡£¡£¡£Apache DubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇ󡣡£¡£¡£¡£¡£¡£
Apache Dubbo±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬£¬Apache DubboÖ§³Ö¶àÖÖÐÒ飬£¬£¬£¬£¬£¬£¬¹Ù·½ÍƼöʹÓà Dubbo ÐÒ飬£¬£¬£¬£¬£¬£¬´ËÎó²îÊÇÊôÓÚApache Dubbo HTTPÐÒéÖеÄÒ»¸ö·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÔµ¹ÊÔÓÉÔÚÓÚµ±Apache DubboÆôÓÃHTTPÐÒéÖ®ºó£¬£¬£¬£¬£¬£¬£¬Apache DubboÔÚ½ÓÊÜÀ´×ÔÏûºÄÕßµÄÔ¶³ÌŲÓÃÇëÇóµÄʱ¼ä±£´æÒ»¸ö²»Çå¾²µÄ·´ÐòÁл¯ÐÐΪ£¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÁËÔ¶³Ìí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾ÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬Ç뾡¿ì×°ÖúÍÓ¦ÓøüУºhttps://github.com/apache/dubbo/releases/tag/dubbo-2.7.5¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.mail-archive.com/dev@dubbo.apache.org/msg06225.html