ºìÁªLinuxÃÅ»§
Linux°ïÖú

Struts 2ÔÙÆØÔ¶³Ì´úÂëÖ´ÐЩ¶´S2-037

·¢²¼Ê±¼ä:2016-06-22 12:20:08À´Ô´:ºìÁª×÷Õß:Ronny
½ñÄê4Ô·ݣ¬Apache Stuts 2Ö®ÉÏ·¢ÏÖµÄS2-033Ô¶³Ì´úÂëÖ´ÐЩ¶´£¬ÒÔѸÀײ»¼°ÑÚ¶úÖ®ÊÆÏ¯¾í¶øÀ´¡£ÆäÀûÓôúÂëºÜ¿ì¾ÍÔÚ¶Ìʱ¼äÄÚѸËÙ´«²¥¡£¶øÇÒ¹Ù·½Õë¶ÔÕâ¸ö¸ßΣ©¶´µÄÐÞ¸´·½°¸»¹ÊÇÎÞЧµÄ¡£

±¯¾çµÄÊÂÇé½ñÌìÓÖÔÙ¶È·¢ÉúÁË£¬Õâ´Î·¢ÏÖµÄStruts 2Щ¶´±àºÅΪCVE-2016-4438¡£ ÕâÊÇÓÖÒ»¸öºÜÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£ºÊ¹ÓÃÁËREST²å¼þµÄÓû§¾Í»áÔâÓö¸ÃÎÊÌ⣬Óйظé¶´µÄÏêÇéÈçÏ£º

Apache Struts 2 S2-037 Ô¶³Ì´úÂëÖ´ÐÐ

©¶´±àºÅ£ºCVE-2016-4438

©¶´Î£º¦£ºÔì³ÉÔ¶³Ì´úÂëÖ´ÐÐ

©¶´µÈ¼¶£º¸ßΣ

Ó°Ïì°æ±¾£ºApache struts 2.3.20 - 2.3.28.1 °æ±¾Ê¹ÓÃÁËREST²å¼þµÄÓû§

ÐÞ¸´·½°¸£º¼ÓÈëcleanupActionName·½·¨½øÐйýÂË »òÕß ¸üÐÂÖÁ¹Ù·½struts2.3.29



Apache Struts 2ÊÇÊÀ½çÉÏ×îÁ÷ÐеÄJava Web·þÎñÆ÷¿ò¼ÜÖ®Ò»¡£Struts 2ÊÇStrutsµÄ»»´ú²úÆ·¡£ÔÚStruts 1ºÍWebWorkµÄ¼¼Êõ»ù´¡ÉÏ£¬½øÐкϲ¢²úÉúȫеÄStruts 2¿ò¼Ü¡£ÆäȫеÄStruts 2µÄÌåϵ½á¹¹ÓëStruts 1µÄÌåϵ½á¹¹²î±ð¾Þ´ó¡£Struts 2ÒÔWebWorkΪºËÐÄ£¬²ÉÓÃÀ¹½ØÆ÷µÄ»úÖÆ´¦ÀíÓû§µÄÇëÇó£¬ÕâÑùµÄÉè¼ÆÒ²Ê¹µÃÒµÎñÂß¼­¿ØÖÆÆ÷Äܹ»Óë ServletAPIÍêÈ«ÍÑÀ뿪£¬ËùÒÔStruts 2¿ÉÒÔÀí½âΪWebWorkµÄ¸üвúÆ·¡£ËäÈ»´ÓStruts 1µ½Struts 2ÓÐ×ÅÌ«´óµÄ±ä»¯£¬µ«ÊÇÏà¶ÔÓÚWebWork£¬Struts 2µÄ±ä»¯ºÜС¡£

FreeBuf½«³ÖÐø¸ú×Ù±¨µÀ¸Ã©¶´Ï¸½Ú¼°ºóÐø¶¯Ì¬£¬Çë¹Ø×¢¡£



Ä¿Ç°ÍøÌÙ©¶´¸Ð֪ϵͳ£¨ cvs.vulbox.com £©ÒÑÖ§³Ö¸Ã©¶´¼ì²â¡£Äú¿ÉÒÔ Ãâ·ÑÉêÇëÊÔÓÃÍøÌÙ©¶´¸ÐÖª·þÎñ¡£

±¾ÎĵØÖ·£ºhttp://www.linuxprobe.com/struts2-bug-s2037.htm
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 1 ÌõÆÀÂÛ

  1. Ronny ÓÚ 2016-06-22 12:20:29·¢±í:

    ©¶´ÎÊÌâÖµµÃ¹Ø×¢(o):tx