Apache Dubbo·´ÐòÁл¯·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-12

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-17564£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


2.7.0 <= Apache Dubbo <= 2.7.4

2.6.0 <= Apache Dubbo <= 2.6.7

Apache Dubbo = 2.5.x


·ì϶¸ÅÊö


Apache DubboÊÇÒ»¸öÉ¢²¼Ê½¿ò¼Ü£¬ÖÂÁ¦ÓÚÌṩ¸ß»úÄÜͨÃ÷»¯µÄRPCÔ¶³Ì·þÎñŲÓù滮£¬ÒÔ¼°SOA·þÎñÖÎÀí¹æ»®¡£Apache DubboÔÚÏÖʵÀûÓó¡¾°ÖÐÖØÒªÕÆ¹Ü½â¾öÉ¢²¼Ê½µÄÓйØÐèÒª¡£


Apache Dubbo´æÔÚ·´ÐòÁл¯·ì϶£¬Apache DubboÖ§³Ö¶àÖÖºÍ̸£¬¹Ù·½ÍƼöʹÓà Dubbo ºÍ̸£¬´Ë·ì϶ÊÇÊôÓÚApache Dubbo HTTPºÍ̸ÖеÄÒ»¸ö·´ÐòÁл¯·ì϶£¬ÖØÒªÔ­ÒòÔÚÓÚµ±Apache DubboÆôÓÃHTTPºÍ̸֮ºó£¬Apache DubboÔÚ½ÓÊÜÀ´×ÔÏû·ÑÕßµÄÔ¶³ÌŲÓÃÒªÇóµÄʱ³½´æÔÚÒ»¸ö²»°²È«µÄ·´ÐòÁл¯ÐÐΪ£¬×îÖÕµ¼ÖÂÁËÔ¶³ÌËÁÒâ´úÂëÖ´ÐС£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼а汾½¨¸´·ì϶£¬Ç뾡¿ì×°ÖúÍÀûÓøüУºhttps://github.com/apache/dubbo/releases/tag/dubbo-2.7.5¡£


²Î¿¼Á´½Ó


https://www.mail-archive.com/dev@dubbo.apache.org/msg06225.html