FasterXML Jackson-databindÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-23

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12384£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬CVSS·ÖÖµ£º5.9 


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


FasterXML jackson-databind 2.0.0 ¨C 2.9.9


Îó²î¸ÅÊö


FasterXML JacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£Jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£¡£¡£¡£


Jackson-databind¿ÉÄÜÔÊÐí¹¥»÷Õßͨ¹ýʹÓÃÎÞ·¨×èÖ¹logback-coreÀà¾ÙÐжà̬·´ÐòÁл¯¶ø±¬·¢ÖÖÖÖÓ°Ïì¡£¡£¡£¡£Æ¾Ö¤Àà·¾¶ÄÚÈÝ£¬£¬£¬£¬¿ÉÒÔÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttps://blog.doyensec.com/2019/07/22/jackson-gadgets.html¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://github.com/FasterXML/jackson-databind/commit/c9ef4a10d6f6633cf470d6a469514b68fa2be234¡£¡£¡£¡£ 


»º½â²½·¥£º


´ËÎó²îÒÀÀµÓÚÓ¦ÓóÌÐòµÄClassPathÖб£´æµÄlogback-core(ch.qos.logback.core)¡£¡£¡£¡£×èֹʹÓñ£´ælogback-coreµÄjackson-databindÓ¦ÓóÌÐò¿É×èÖ¹´ËÎó²îµÄÓ°Ïì¡£¡£¡£¡£


²Î¿¼Á´½Ó


http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201906-867