FusionAuthÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-04Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-7799£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache FusionAuth <= 1.10
Îó²î¸ÅÊö
¿ËÈÕ£¬Apache FusionAuthÐû²¼Ð°汾ÐÞ¸´ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£·¢Ã÷ÔÚFusionAuthÖоÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒԱ༵ç×ÓÓʼþÄ£°å(Home->Settings->Email Templates)»òÖ÷Ìâ(Home->Settings->Themes)£¬´Ó¶øÍ¨¹ý´¦Öóͷ£×Ô½ç˵ģ°åµÄApache FreeMarkerÒýÇæÖеÄfreemarker.template.utility.ExecuteÔڵײã²Ù×÷ϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£
FusionAuthÊÇÏÖ´úµÄ»á¼ûÖÎÀí¿ªÔ´Ó¦ÓóÌÐò£¬¿ÉÒÔÓë¶àÖÖÊÖÒÕÇ徲̨¼¯³É¡£¿ÉÒÔͨ¹ýÖÎÀíÒDZí°åÒÔ¶àÖÖ·½·¨ÉèÖúÍ×Ô½ç˵FusionAuth£¬ÎªÈκÎÓ¦ÓóÌÐòÌṩÉí·ÝÑéÖ¤¡¢ÊÚȨºÍÓû§ÖÎÀí£»ÓÉÓÚʹÓÃApache FreeMarkerÄ£°åÒýÇæ£¬ÇÒδ¶ÔÓû§ÊäÈëÊý¾Ý¾ÙÐйýÂË£¬´ËÎó²î½«¶Ô·þÎñÆ÷Çå¾²Ôì³ÉÑÏÖØÍþв¡£
Îó²îÑéÖ¤
EXP£ºhttps://cxsecurity.com/issue/WLB-2020010208¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾FusionAuth 1.11ÐÞ¸´Îó²î£¬ÊÜÓ°ÏìµÄÓû§Ç뾡¿ì¸üÐÂÉý¼¶¾ÙÐзÀ»¤£ºhttps://fusionauth.io/docs/v1/tech/installation-guide/upgrade¡£
²Î¿¼Á´½Ó
https://lab.mediaservice.net/advisory/2020-03-fusionauth.txt


¾©¹«Íø°²±¸11010802024551ºÅ