Apache Solr JMX·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-11-19·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12409£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Linux°æµÄSolr 8.1.1ÖÁ8.2.0°æ±¾¡£
·ì϶¸ÅÊö
Apache SolrÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚLucene£¨Ò»¿îÈ«ÎÄËÑË÷ÒýÇæ£©µÄËÑË÷·þÎñÆ÷¡£Í¬Ê±¶ÔÆä½øÐÐÁËÀ©´ó£¬ÌṩÁ˱ÈLucene¸üΪ·á˶µÄ²éÎÊ˵»°£¬Í¬Ê±ÊµÏÖÁË¿ÉÅäÖᢿÉÀ©´ó²¢¶Ô²éÎÊ»úÄܽøÐÐÁËÓÅ»¯£¬²¢ÇÒÌṩÁËÒ»¸öÃÀÂúµÄÖ°ÄÜÖÎÀí½çÃæ£¬ÊÇÒ»¿î¼«¶ÈÓÅÁ¼µÄÈ«ÎÄËÑË÷ÒýÇæ¡£
Apache SolrµÄ8.1.1ºÍ8.2.0°æ±¾µÄ×Ô´øÅäÖÃÎļþsolr.in.shÖдæÔÚ²»°²È«µÄÑ¡ÏîENABLE_REMOTE_JMX_OPTS="true"¡£ÈôÊÇÊܺ¦ÕßʹÓÃÁ˸ÃĬÈÏÅäÖã¬Ôò»áÔÚĬÈ϶˿Ú18983Ê¢¿ªJMX·þÎñ£¬ÇÒĬÈÏ먦ÆôÈÏÖ¤¡£ÈκοɽӼû´Ë¶Ë¿ÚµÄ¹¥»÷Õß¿ÉÀûÓô˷ì϶ÏòÊÜÓ°Ïì·þÎñÌáÒé¹¥»÷£¬Ö´ÐÐËÁÒâ´úÂë¡£
·ì϶ÑéÖ¤
EXP: https://github.com/mogwailabs/mjet
½¨¸´½¨Òé
Éý¼¶Solrµ½8.3.0°æ±¾£ºhttps://lucene.apache.org/solr/downloads.html¡£
һʱ½¨¸´½¨Ò飺
1¡¢¹Ø¹Ø18983¶Ë¿Ú¶Ô±íÊ¢¿ª£»
2¡¢ÈçÐè¶Ô±íÊ¢¿ª£¬Îñ±ØÉèÖÃJMX admin roleÇ¿¿ÚÁ
3¡¢ÉèÖÃsolr.in.shÖÐµÄ ENABLE_REMOTE_JMX_OPTS=false, ¶øºó³ÁÆôsolr¡£
²Î¿¼Á´½Ó
http://lucene.apache.org/solr/news.html


¾©¹«Íø°²±¸11010802024551ºÅ