FusionAuthÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-04

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-7799£¬£¬£¬£¬ £¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apache FusionAuth <= 1.10


Îó²î¸ÅÊö


¿ËÈÕ£¬£¬£¬£¬ £¬£¬£¬ £¬Apache FusionAuthÐû²¼Ð°汾ÐÞ¸´ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£·¢Ã÷ÔÚFusionAuthÖо­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒԱ༭µç×ÓÓʼþÄ£°å(Home->Settings->Email Templates)»òÖ÷Ìâ(Home->Settings->Themes)£¬£¬£¬£¬ £¬£¬£¬ £¬´Ó¶øÍ¨¹ý´¦Öóͷ£×Ô½ç˵ģ°åµÄApache FreeMarkerÒýÇæÖеÄfreemarker.template.utility.ExecuteÔڵײã²Ù×÷ϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£


FusionAuthÊÇÏÖ´úµÄ»á¼ûÖÎÀí¿ªÔ´Ó¦ÓóÌÐò£¬£¬£¬£¬ £¬£¬£¬ £¬¿ÉÒÔÓë¶àÖÖÊÖÒÕÇ徲̨¼¯³É¡£¡£¡£¡£¡£¡£¿£¿£¿£¿ÉÒÔͨ¹ýÖÎÀíÒDZí°åÒÔ¶àÖÖ·½·¨ÉèÖúÍ×Ô½ç˵FusionAuth£¬£¬£¬£¬ £¬£¬£¬ £¬ÎªÈκÎÓ¦ÓóÌÐòÌṩÉí·ÝÑéÖ¤¡¢ÊÚȨºÍÓû§ÖÎÀí£»£» £»£»£»ÓÉÓÚʹÓÃApache FreeMarkerÄ£°åÒýÇæ£¬£¬£¬£¬ £¬£¬£¬ £¬ÇÒδ¶ÔÓû§ÊäÈëÊý¾Ý¾ÙÐйýÂË£¬£¬£¬£¬ £¬£¬£¬ £¬´ËÎó²î½«¶ÔЧÀÍÆ÷Çå¾²Ôì³ÉÑÏÖØÍþв¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


EXP£ºhttps://cxsecurity.com/issue/WLB-2020010208¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾FusionAuth 1.11ÐÞ¸´Îó²î£¬£¬£¬£¬ £¬£¬£¬ £¬ÊÜÓ°ÏìµÄÓû§Ç뾡¿ì¸üÐÂÉý¼¶¾ÙÐзÀ»¤£ºhttps://fusionauth.io/docs/v1/tech/installation-guide/upgrade¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://lab.mediaservice.net/advisory/2020-03-fusionauth.txt