Apache ShardingSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-1947 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apache ShardingSphere < 4.0.1


Îó²î¸ÅÊö


Apache ShardingSphereÊÇÒ»Ì׿ªÔ´µÄÂþÑÜʽÊý¾Ý¿âÖÐÐļþ½â¾ö¼Æ»®×é³ÉµÄÉú̬Ȧ £¬ËüÓÉSharding-JDBC¡¢Sharding-ProxyºÍSharding-Sidecar£¨ÍýÏëÖУ©Õâ3¿îÏ໥×ÔÁ¦ £¬È´ÓÖÄܹ»»ìÏý°²ÅÅÅäºÏʹÓõIJúÆ·×é³É¡£ËüÃǾùÌṩ±ê×¼»¯µÄÊý¾Ý·ÖƬ¡¢ÂþÑÜʽÊÂÎñºÍÊý¾Ý¿âÖÎÀí¹¦Ð§ £¬¿ÉÊÊÓÃÓÚÈçJavaͬ¹¹¡¢Òì¹¹ÓïÑÔ¡¢ÔÆÔ­ÉúµÈÖÖÖÖ¶àÑù»¯µÄÓ¦Óó¡¾°¡£


Apache ShardingSphere±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î £¬¾­ÓÉÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÌá½»í§ÒâYAML´úÂëʵÏÖÔ¶³Ì´úÂëÖ´ÐС£Apache ShardingSphereºǫ́µÄÖÎÀíÕ˺ÅÃÜÂëĬÈϾùΪadmin¡£


ͨ¹ý¶ÔApache ShardingSphere´úÂëÆÊÎö £¬·¢Ã÷¿ª·¢Ö°Ô±Ö±½ÓʹÓÃunmarshalÒªÁì¶ÔÊäÈëµÄYAMLÖ±½Ó¾ÙÐÐÆÊÎö £¬Ã»ÓÐ×öУÑé¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


±ÈÕÕ²¹¶¡·¢Ã÷ÐÂÔöClassFilterConstructorÀ´¶Ô´Ë¾ÙÐÐУÑé¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Îó²îÑéÖ¤


PoC:https://github.com/Imanfeng/CVE-2020-1947¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÒÑÐû²¼×îа汾ÐÞ¸´¸ÃÎó²î £¬½¨ÒéÓû§¾¡¿ìÉý¼¶£ºhttps://github.com/apache/incubator-shardingsphere/releases¡£


²Î¿¼Á´½Ó


https://github.com/apache/incubator-shardingsphere/releases