¡¾·ì϶¹«¸æ¡¿RuoYi v4.7.9 ÈÏÖ¤Óû§SQL×¢Èë·ì϶(CVE-2024-57521)
°ä²¼¹¦·ò 2025-12-24Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | RuoYi v4.7.9 ÈÏÖ¤Óû§SQL×¢Èë·ì϶ | ||
CVE ID | CVE-2024-57521 | ||
·ì϶ÀàÐÍ | SQL×¢Èë | ·¢ÏÖ¹¦·ò | 2025-12-24 |
·ì϶ÆÀ·Ö | 10 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
RuoYiÊÇÒ»¿î»ùÓÚJavaµÄ¼±¾ç¿ª·¢¿ò¼Ü£¬ÖØÒªÓÃÓÚ¹¹½¨ÆóÒµ¼¶ÖÎÀíϵͳ¡£ËüѡȡSpring Boot¡¢MyBatisµÈ¼¼Êõ£¬Ö§³Öǰºó¶Ë·ÖÀ룬¾ß±¸È¨ÏÞÖÎÀí¡¢´úÂëÌìÉú¡¢Êý¾Ýͳ¼ÆµÈÖ°ÄÜ¡£RuoYiÌṩÁË·á˶µÄ»ù´¡Ö°ÄܺͲå¼þ£¬¿É¼±¾ç´î½¨ºó¶ÜÖÎÀíϵͳ£¬ºÏÓÃÓÚ¸÷ÀàÒµÎñ³¡¾°¡£¿ò¼ÜÄÚÖÃÃÀÂúµÄ°²È«»úÔ죬ÈçȨÏÞ½ÚÔìºÍÈÕÖ¾ÖÎÀí£¬ÊʺÏÖÐÓ×ÐÍÆóÒµºÍ¿ª·¢ÍŶӽøÐж¨Ô컯¿ª·¢¡£RuoYiÓµÓнϸߵĿÉÀ©´óÐԺͽýÝÐÔ£¬¿í·ºÀûÓÃÓÚÆóÒµÐÅÏ¢»¯½¨ÉèÖС£
¶þ¡¢Ó°ÏìÁìÓò
RuoYi <= v4.7.9
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://gitee.com/y_project/RuoYi/releases/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


¾©¹«Íø°²±¸11010802024551ºÅ