Apache Solr JMX·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-11-19

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12409£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Linux°æµÄSolr 8.1.1ÖÁ8.2.0°æ±¾¡£


·ì϶¸ÅÊö


Apache SolrÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚLucene£¨Ò»¿îÈ«ÎÄËÑË÷ÒýÇæ£©µÄËÑË÷·þÎñÆ÷¡£Í¬Ê±¶ÔÆä½øÐÐÁËÀ©´ó£¬ÌṩÁ˱ÈLucene¸üΪ·á˶µÄ²éÎÊ˵»°£¬Í¬Ê±ÊµÏÖÁË¿ÉÅäÖᢿÉÀ©´ó²¢¶Ô²éÎÊ»úÄܽøÐÐÁËÓÅ»¯£¬²¢ÇÒÌṩÁËÒ»¸öÃÀÂúµÄÖ°ÄÜÖÎÀí½çÃæ£¬ÊÇÒ»¿î¼«¶ÈÓÅÁ¼µÄÈ«ÎÄËÑË÷ÒýÇæ¡£


Apache SolrµÄ8.1.1ºÍ8.2.0°æ±¾µÄ×Ô´øÅäÖÃÎļþsolr.in.shÖдæÔÚ²»°²È«µÄÑ¡ÏîENABLE_REMOTE_JMX_OPTS="true"¡£ÈôÊÇÊܺ¦ÕßʹÓÃÁ˸ÃĬÈÏÅäÖã¬Ôò»áÔÚĬÈ϶˿Ú18983Ê¢¿ªJMX·þÎñ£¬ÇÒĬÈÏ먦ÆôÈÏÖ¤¡£ÈκοɽӼû´Ë¶Ë¿ÚµÄ¹¥»÷Õß¿ÉÀûÓô˷ì϶ÏòÊÜÓ°Ïì·þÎñÌáÒé¹¥»÷£¬Ö´ÐÐËÁÒâ´úÂë¡£


·ì϶ÑéÖ¤


EXP: https://github.com/mogwailabs/mjet


½¨¸´½¨Òé


Éý¼¶Solrµ½8.3.0°æ±¾£ºhttps://lucene.apache.org/solr/downloads.html¡£


һʱ½¨¸´½¨Ò飺


1¡¢¹Ø¹Ø18983¶Ë¿Ú¶Ô±íÊ¢¿ª£»

2¡¢ÈçÐè¶Ô±íÊ¢¿ª£¬Îñ±ØÉèÖÃJMX admin roleÇ¿¿ÚÁ

3¡¢ÉèÖÃsolr.in.shÖÐµÄ ENABLE_REMOTE_JMX_OPTS=false, ¶øºó³ÁÆôsolr¡£


²Î¿¼Á´½Ó


http://lucene.apache.org/solr/news.html