±¯¾çµÄÊÂÇé½ñÌìÓÖÔÙ¶È·¢ÉúÁË£¬Õâ´Î·¢ÏÖµÄStruts 2Щ¶´±àºÅΪCVE-2016-4438¡£ ÕâÊÇÓÖÒ»¸öºÜÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£ºÊ¹ÓÃÁËREST²å¼þµÄÓû§¾Í»áÔâÓö¸ÃÎÊÌ⣬Óйظé¶´µÄÏêÇéÈçÏ£º
Apache Struts 2 S2-037 Ô¶³Ì´úÂëÖ´ÐÐ
©¶´±àºÅ£ºCVE-2016-4438
©¶´Î£º¦£ºÔì³ÉÔ¶³Ì´úÂëÖ´ÐÐ
©¶´µÈ¼¶£º¸ßΣ
Ó°Ïì°æ±¾£ºApache struts 2.3.20 - 2.3.28.1 °æ±¾Ê¹ÓÃÁËREST²å¼þµÄÓû§
ÐÞ¸´·½°¸£º¼ÓÈëcleanupActionName·½·¨½øÐйýÂË »òÕß ¸üÐÂÖÁ¹Ù·½struts2.3.29

Apache Struts 2ÊÇÊÀ½çÉÏ×îÁ÷ÐеÄJava Web·þÎñÆ÷¿ò¼ÜÖ®Ò»¡£Struts 2ÊÇStrutsµÄ»»´ú²úÆ·¡£ÔÚStruts 1ºÍWebWorkµÄ¼¼Êõ»ù´¡ÉÏ£¬½øÐкϲ¢²úÉúȫеÄStruts 2¿ò¼Ü¡£ÆäȫеÄStruts 2µÄÌåϵ½á¹¹ÓëStruts 1µÄÌåϵ½á¹¹²î±ð¾Þ´ó¡£Struts 2ÒÔWebWorkΪºËÐÄ£¬²ÉÓÃÀ¹½ØÆ÷µÄ»úÖÆ´¦ÀíÓû§µÄÇëÇó£¬ÕâÑùµÄÉè¼ÆÒ²Ê¹µÃÒµÎñÂß¼¿ØÖÆÆ÷Äܹ»Óë ServletAPIÍêÈ«ÍÑÀ뿪£¬ËùÒÔStruts 2¿ÉÒÔÀí½âΪWebWorkµÄ¸üвúÆ·¡£ËäÈ»´ÓStruts 1µ½Struts 2ÓÐ×ÅÌ«´óµÄ±ä»¯£¬µ«ÊÇÏà¶ÔÓÚWebWork£¬Struts 2µÄ±ä»¯ºÜС¡£
FreeBuf½«³ÖÐø¸ú×Ù±¨µÀ¸Ã©¶´Ï¸½Ú¼°ºóÐø¶¯Ì¬£¬Çë¹Ø×¢¡£

Ä¿Ç°ÍøÌÙ©¶´¸Ð֪ϵͳ£¨ cvs.vulbox.com £©ÒÑÖ§³Ö¸Ã©¶´¼ì²â¡£Äú¿ÉÒÔ Ãâ·ÑÉêÇëÊÔÓÃÍøÌÙ©¶´¸ÐÖª·þÎñ¡£
±¾ÎĵØÖ·£ºhttp://www.linuxprobe.com/struts2-bug-s2037.htm
Ronny ÓÚ 2016-06-22 12:20:29·¢±í:
©¶´ÎÊÌâÖµµÃ¹Ø×¢(o):tx