FusionAuthÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-04·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-7799£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache FusionAuth <= 1.10
·ì϶¸ÅÊö
½üÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Apache FusionAuth°ä²¼Ð°汾½¨¸´ÁËÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£·¢´Ë¿ÌFusionAuthÖо¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»±à×ëµç×ÓÓʼþÄ£°å(Home->Settings->Email Templates)»òÖ÷Ìâ(Home->Settings->Themes)£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÍ¨¹ý´¦ÖÃ×Ô½ç˵ģ°åµÄApache FreeMarkerÒýÇæÖеÄfreemarker.template.utility.ExecuteÔڵײã²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£
FusionAuthÊÇÏÖ´úµÄ½Ó¼ûÖÎÀí¿ªÔ´ÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»Óë¶àÖÖ¼¼ÊõºÍƽ̨¼¯³É¡£¡£¡£¡£¡£¿£¿£¿£¿£Äܹ»Í¨¹ýÖÎÀíÒDZí°åÒÔ¶àÖÖ·½Ê½ÅäÖúÍ×Ô½ç˵FusionAuth£¬£¬£¬£¬£¬£¬£¬£¬ÎªÈκÎÀûÓ÷¨Ê½ÌṩÉí·ÝÑéÖ¤¡¢ÊÚȨºÍÓû§ÖÎÀí£»£»£»£»£»£»£»ÓÉÓÚʹÓÃApache FreeMarkerÄ£°åÒýÇæ£¬£¬£¬£¬£¬£¬£¬£¬ÇÒδ¶ÔÓû§ÊäÈëÊý¾Ý½øÐйýÂË£¬£¬£¬£¬£¬£¬£¬£¬´Ë·ì϶½«¶Ô·þÎñÆ÷°²È«Ôì³ÉÑϳÁÍþв¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
EXP£ºhttps://cxsecurity.com/issue/WLB-2020010208¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼а汾FusionAuth 1.11½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§Ç뾡¿ì¸üÐÂÉý¼¶½øÐзÀ»¤£ºhttps://fusionauth.io/docs/v1/tech/installation-guide/upgrade¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://lab.mediaservice.net/advisory/2020-03-fusionauth.txt


¾©¹«Íø°²±¸11010802024551ºÅ