ʱ¼ä£º2022-11-02 ×÷ÕߣºÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT
ÖÂÁ¦ÓÚµÚһʱ¼äΪÆóÒµ¼¶Óû§ÌṩÇ徲Σº¦Í¨¸æºÍÓÐÓýâ¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£
Ç徲ͨ¸æ
SpringSecurityÊÇÒ»¸öÄܹ»Îª»ùÓÚSpringµÄÆóÒµÓ¦ÓÃϵͳÌṩÉùÃ÷ʽµÄÇå¾²»á¼û¿ØÖƽâ¾ö¼Æ»®µÄÇå¾²¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT¼à²âµ½Spring¹Ù·½Ðû²¼SpringSecurityÉí·ÝÈÏÖ¤ÈÆ¹ýÎó²î(CVE-2022-31692)ͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬µ±SpringSecurity´¦Öóͷ£forward»òincludeת·¢µÄÇëÇóʱ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܱ£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÈÆ¹ýÊÚȨ¹æÔò¡£¡£¡£¡£¡£¡£¡£¼øÓÚ´ËÎó²îÓ°Ïì¹æÄ£½Ï´ó£¬£¬£¬£¬£¬£¬£¬£¬½¨Òé¿Í»§¾¡¿ì×öºÃ×Բ鼰·À»¤¡£¡£¡£¡£¡£¡£¡£
ÍþвÆÀ¹À
´¦Öóͷ£½¨Òé
1¡¢°æ±¾Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÓпɸüа汾£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶ÖÁ£º
SpringSecurity>=5.6.9
SpringSecurity>=5.7.5
2¡¢»º½â¼Æ»®
ÎÞ·¨Éý¼¶µÄÓû§½¨ÒéÉèÖÃauthorizeRequests().filterSecurityInterceptorOncePerRequest(false)È¡´úauthorizeHttpRequests().shouldFilterAllDispatcherTypes(true)
SpringSecurity<5.7.0°æ±¾shouldFilterAllDispatcherTypes²»¿ÉÓ㬣¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýÌí¼ÓObjectPostProcessor»º½â´ËÎó²î£º
authorizeHttpRequests().withObjectPostProcessor(new
ObjectPostProcessor(){
@Override
publicOpostProcess(Ofilter){
filter.setObserveOncePerRequest(false);
filter.setFilterAsyncDispatch(true);
filter.setFilterErrorDispatch(true);
returnfilter;
²Î¿¼×ÊÁÏ
[1]https://tanzu.vmware.com/security/cve-2022-31692
ʱ¼äÏß
2022Äê11ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERTÐû²¼Ç徲Σº¦Í¨¸æ¡£¡£¡£¡£¡£¡£¡£
µ½Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!NOX-Çå¾²¼à²âƽ̨ÅÌÎʸü¶àÎó²îÏêÇé
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
¿ì½Ý´°¿Ú
ÆìÏÂÍøÕ¾
¹ØÓÚÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!
95015ЧÀÍÈÈÏß
΢ÐŹ«ÖÚºÅ
Á¬Ã¦²¦´ò