¡¾·ì϶¹«¸æ¡¿pgjdbc SQL ×¢Èë·ì϶£¨CVE-2024-1597£©

°ä²¼¹¦·ò 2024-02-21

Ò»¡¢·ì϶¸ÅÊö

·ìϼûû³Æ

  PgJDBC   SQL ×¢Èë·ì϶

CVE   ID

CVE-2024-1597

·ì϶ÀàÐÍ

SQL×¢Èë

·¢ÏÖ¹¦·ò

2024-02-21

·ì϶ÆÀ·Ö

10.0

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ֪

 

PostgreSQL JDBC Driver£¨¼ò³Æ PgJDBC£©ÔÊÐíJava ·¨Ê½Ê¹Óó߶ȵġ¢¶ÀÁ¢ÓÚÊý¾Ý¿âµÄ Java ´úÂëÏνӵ½ PostgreSQL Êý¾Ý¿â¡£¡£¡£¡£¡£¡£

2024Äê2ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅVSRC¼à²âµ½PgJDBCÖдæÔÚÒ»¸öSQL×¢Èë·ì϶£¨CVE-2024-1597£©£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ10.0¡£¡£¡£¡£¡£¡£

PgJDBCÊÜÓ°Ïì°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬£¬µ±Ê¹Óõ¥Ò»²éÎÊģʽ£¨PreferQueryMode=SIMPLE£¬£¬£¬£¬£¬£¬£¬£¬·ÇĬÈÏģʽ£©Ê±´æÔÚSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ±SQL°ó¶¨Õ¼Î»·û´øÓУ¨-£©Ç°×ºÊ±£¬£¬£¬£¬£¬£¬£¬£¬¸ºÖµµÄÖ±½Ó´úÌæ¿ÉÄܵ¼ÖÂÌìÉúµÄÏóÕ÷±»ÊÓΪÐÐ×¢½â£¨È磺SELECT -?, ?£©£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊǵÚÒ»¸öÊýֵռλ·ûµÄ²ÎÊýֵΪ¸ºÖµ£¨Èç -1£¬£¬£¬£¬£¬£¬£¬£¬-123µÈ£©ÇÒµÚ¶þ¸ö×Ö·û´®ÖµÕ¼Î»·ûµÄ²ÎÊýÖдøÓл»ÐзûµÄ¶ñÒâÎı¾¿ÉÄܵ¼ÖºÅÁîÖ´ÐÓ×£¡£¡£¡£¡£¡£ÍþвÕß¿ÉÀûÓø÷ì϶ִÐÐSQL×¢Èë¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼Ö»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐδÊÚȨ²Ù×÷µÈ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°ÏìÁìÓò

42.7.0<=PgJDBC°æ±¾< 42.7.2

42.6.0<=PgJDBC°æ±¾< 42.6.1

42.5.0<=PgJDBC°æ±¾< 42.5.5

42.4.0<=PgJDBC°æ±¾< 42.4.4

42.3.0<=PgJDBC°æ±¾< 42.3.9

PgJDBC°æ±¾< 42.2.8

 

Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ¹Ù·½ÒѾ­°ä²¼Á˸÷ì϶µÄ²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÀûÓò¹¶¡»ò´ý½¨¸´°æ±¾°ä²¼Ê±Éý¼¶µ½PgJDBC°æ±¾42.7.2¡¢42.6.1¡¢42.5.5¡¢42.4.4¡¢42.3.9 ºÍ 42.2.8¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://jdbc.postgresql.org/download/

3.2 һʱ´ëÊ©

ÔÝÎÞ¡£¡£¡£¡£¡£¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬£¬£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬£¬£¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬£¬£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://github.com/pgjdbc/pgjdbc/commit/93b0fcb2711d9c1e3a2a03134369738a02a58b40

https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56

https://nvd.nist.gov/vuln/detail/CVE-2024-1597

 


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-02-21

³õ´Î°ä²¼

 


Îå¡¢¸½Â¼

5.1 8827Ì«Ñô¼¯Íżò½é

8827Ì«Ñô¼¯ÍųÉÁ¢ÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°8827Ì«Ñô¼¯ÍÅ´óÏ㬣¬£¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÀö½­ÖÐÓ×°å¹ÒÅÆÉÏÊÓ×£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£¡£¡£¡£¡£

5.2 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png