Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!

Spring SecurityÉí·ÝÈÏÖ¤ÈÆ¹ýÎó²î(CVE-2022-31692)Ç徲Σº¦Í¨¸æ

ʱ¼ä£º2022-11-02 ×÷ÕߣºÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT

·ÖÏíµ½£º

Spring SecurityÉí·ÝÈÏÖ¤ÈÆ¹ýÎó²î(CVE-2022-31692)Ç徲Σº¦Í¨¸æ

    Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT

    ÖÂÁ¦ÓÚµÚһʱ¼äΪÆóÒµ¼¶Óû§ÌṩÇ徲Σº¦Í¨¸æºÍÓÐÓýâ¾ö¼Æ»®¡£¡£ ¡£¡£¡£¡£¡£

    Ç徲ͨ¸æ

    SpringSecurityÊÇÒ»¸öÄܹ»Îª»ùÓÚSpringµÄÆóÒµÓ¦ÓÃϵͳÌṩÉùÃ÷ʽµÄÇå¾²»á¼û¿ØÖƽâ¾ö¼Æ»®µÄÇå¾²¿ò¼Ü¡£¡£ ¡£¡£¡£¡£¡£

    ¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT¼à²âµ½Spring¹Ù·½Ðû²¼SpringSecurityÉí·ÝÈÏÖ¤ÈÆ¹ýÎó²î(CVE-2022-31692)ͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬µ±SpringSecurity´¦Öóͷ£forward»òincludeת·¢µÄÇëÇóʱ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܱ£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÈÆ¹ýÊÚȨ¹æÔò¡£¡£ ¡£¡£¡£¡£¡£¼øÓÚ´ËÎó²îÓ°Ïì¹æÄ£½Ï´ó£¬£¬£¬£¬£¬£¬£¬£¬½¨Òé¿Í»§¾¡¿ì×öºÃ×Բ鼰·À»¤¡£¡£ ¡£¡£¡£¡£¡£

    ÍþвÆÀ¹À

    ´¦Öóͷ£½¨Òé

    1¡¢°æ±¾Éý¼¶

    ÏÖÔÚ¹Ù·½ÒÑÓпɸüа汾£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶ÖÁ£º

    SpringSecurity>=5.6.9

    SpringSecurity>=5.7.5

    2¡¢»º½â¼Æ»®

    ÎÞ·¨Éý¼¶µÄÓû§½¨ÒéÉèÖÃauthorizeRequests().filterSecurityInterceptorOncePerRequest(false)È¡´úauthorizeHttpRequests().shouldFilterAllDispatcherTypes(true)

    SpringSecurity<5.7.0°æ±¾shouldFilterAllDispatcherTypes²»¿ÉÓ㬣¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýÌí¼ÓObjectPostProcessor»º½â´ËÎó²î£º

    authorizeHttpRequests().withObjectPostProcessor(new

    ObjectPostProcessor(){

    @Override

    publicOpostProcess(Ofilter){

    filter.setObserveOncePerRequest(false);

    filter.setFilterAsyncDispatch(true);

    filter.setFilterErrorDispatch(true);

    returnfilter;

    ²Î¿¼×ÊÁÏ

    [1]https://tanzu.vmware.com/security/cve-2022-31692

    Ê±¼äÏß

    2022Äê11ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERTÐû²¼Ç徲Σº¦Í¨¸æ¡£¡£ ¡£¡£¡£¡£¡£

    µ½Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!NOX-Çå¾²¼à²âƽ̨ÅÌÎʸü¶àÎó²îÏêÇé

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015ÍøÂçÇ徲ЧÀÍÈÈÏß

95015ÍøÂçÇ徲ЧÀÍÈÈÏß

ɨһɨ¹Ø×¢

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! ÔÚÏ߿ͷþ Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015

Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ

ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿