Apache Struts2ÎļþÉÏ´«·ì϶£¨CVE-2024-53677£©À´Ï®£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÌṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2024-12-18Struts2¿ò¼ÜÊÇÒ»¸öÓÃÓÚ¿ª·¢Java EEÍøÂçÀûÓ÷¨Ê½µÄÊ¢¿ªÔ´´úÂëÍøÒ³ÀûÓ÷¨Ê½¼Ü¹¹¡£¡£¡£¡£¡£¡£ËüÀûÓò¢ÑÓ³¤ÁËJava Servlet API£¬£¬£¬£¬£¬£¬£¬£¬¼¤Àø¿ª·¢ÕßѡȡMVC¼Ü¹¹¡£¡£¡£¡£¡£¡£Apache Struts 2´æÔÚÒ»¸öÑϳÁµÄÎļþÉÏ´«µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶S2-067£¬£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄ¹¥»÷ÕßÄܹ»°Ñ³ÖÎļþÉÏ´«²ÎÊýÀ´ÆôÓÃõè¾¶±éÀú£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÉÏ´«¿ÉÓÃÓÚÖ´ÐÐÔ¶³Ì´úÂëµÄ¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£
2024Äê12Ô£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅ¼à¿Øµ½Apache¹Ù·½°ä²¼·ì϶·çÏÕ¹«¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÔ¶³Ì·þÎñÆ÷´úÂëÖÐʹÓÃÁËFileUploadInterceptor×÷ΪÎļþÉÏ´«×é¼þʱ£¬£¬£¬£¬£¬£¬£¬£¬Apache StrutsÔÚÎļþÉÏ´«Âß¼ÉÏ´æÔÚ·ì϶¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶½øÐÐõè¾¶±éÀú£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶Äܹ»Ê¹¹¥»÷Õß¿ÉÄÜÉÏ´«¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£

·ì϶¸´ÏÖ½ØÍ¼

Ó°Ïì°æ±¾
2.0.0 <= Apache Struts <= 2.3.37 (EOL)
2.5.0 <= Apache Struts <= 2.5.33
6.0.0 <= Apache Struts <= 6.3.0.2
°ÑÎÈ£º²»Ê¹ÓÃFileUploadInterceptorÄ£¿£¿£¿£¿£¿£¿éµÄÀûÓò»Êܸ÷ì϶ӰÏì¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ò»¡¢¹Ù·½½¨¸´¹æ»®
Ŀǰ¹Ù·½ÒÑÓпɸüа汾£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾£º
Éý¼¶µ½ Struts 6.4.0 »ò¸ü¸ß°æ±¾²¢Ç¨á㵽еÄÎļþÉÏ´«»úÔì¡£¡£¡£¡£¡£¡£
¹Ù·½ÏÂÔØµØÖ·£º
https://struts.apache.org/download.cgi
ÎļþÉÏ´«»úÔìǨáãÁ´½Ó£º
https://struts.apache.org/core-developers/file-upload
¶þ¡¢8827Ì«Ñô¼¯ÍŹ滮
1¡¢8827Ì«Ñô¼¯Íżì²âÀà²úÆ·¹æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEB°²È«ÀûÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬£¬£¬£¬£¬£¬£¬£¬Éý¼¶µ½×îа汾¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ£¬£¬£¬£¬£¬£¬£¬£¬ÊÂÎñ¿âÏÂÔØµØÖ·£º
ÊÂÎñ¿âÏÂÔØµØÖ·£ºhttps://venustech.download.venuscloud.cn/
2¡¢8827Ì«Ñô¼¯ÍÅ©ɨ²úÆ·¹æ»®
£¨1£©¡°8827Ì«Ñô¼¯ÍÅ·ì϶ɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè¡£¡£¡£¡£¡£¡£

£¨2£©8827Ì«Ñô¼¯ÍÅ·ì϶ɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè

3¡¢8827Ì«Ñô¼¯ÍÅ×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®
8827Ì«Ñô¼¯ÍÅ×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÈë¿â×ʲúApache Struts2ÎļþÉÏ´«·ì϶£¨CVE-2024-53677£©½øÐÐÖÎÀí¡£¡£¡£¡£¡£¡£

4¡¢8827Ì«Ñô¼¯ÍŰ²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®
Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬£¬£¬£¬£¬£¬£¬½øÐйØÁªÕ½ÊõÅäÖ㬣¬£¬£¬£¬£¬£¬£¬½áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø·¢ÏÖ¡°Apache Struts2ÎļþÉÏ´«·ì϶¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£¡£¡£¡£¡£¡£
1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°Apache Struts2ÎļþÉÏ´«·ì϶¡±·ì϶ɨÃ蹤×÷£¬£¬£¬£¬£¬£¬£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄ³ÁÒª×ʲú£»£»£»£»£»

2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿£¿£¿£¿£¿£¿éÖУ¬£¬£¬£¬£¬£¬£¬£¬Ôö³¤¡°L2_Apache Struts2ÎļþÉÏ´«·ì϶¡±£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý8827Ì«Ñô¼¯Íżì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖ±í²¿¹¥»÷ÐÐΪ£º

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_Apache Struts2ÎļþÉÏ´«·ì϶"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬£¬£¬£¬£¬£¬£¬£¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓ㻣»£»£»£»
3£©Ôö³¤¡°L3_Apache Struts2ÎļþÉÏ´«·ì϶¡±£¬£¬£¬£¬£¬£¬£¬£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÅ×Ú»òÔ̺¬¡°L2_Apache Struts2ÎļþÉÏ´«·ì϶¡±£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Á˾ֵÅ×Ú¡°¹¥»÷³É¹¦¡±£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶȡ£¡£¡£¡£¡£¡£



¾©¹«Íø°²±¸11010802024551ºÅ