CVE-2020-13957 | Apache Solr ConfigSet APIÎļþÉÏ´«Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-10-13

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-13957

ʱ   ¼ä

 2020-10-13

Àà  ÐÍ

ÎļþÉÏ´«

µÈ   ¼¶

 ¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache solr

6.6.0ÖÁ6.6.5

7.0.0ÖÁ7.7.3

8.0.0ÖÁ8.6.2

 

Apache SolrÊÇÓÉJavaÓïÑÔ¿ª·¢¡¢ÔËÐÐÓÚApache Tomcat»òJettyµÈServletÈÝÆ÷µÄÒ»¸ö×ÔÁ¦µÄÈ«ÎÄËÑË÷ЧÀÍÆ÷¡£¡£¡£¡£¡£ËüÖ÷Òª»ùÓÚHTTPºÍApache LuceneʵÏÖ¡£¡£¡£¡£¡£Ö÷Òª¹¦Ð§°üÀ¨È«ÎļìË÷¡¢ÖÀÖбêʾ¡¢·ÖÃæËÑË÷¡¢¶¯Ì¬¾ÛÀà¡¢Êý¾Ý¿â¼¯³É£¬£¬£¬£¬ÒÔ¼°¸»Îı¾µÄ´¦Öóͷ£¡£¡£¡£¡£¡£

0x01 Îó²îÏêÇé

image.png

 

2020Äê10ÔÂ12ÈÕ£¬£¬£¬£¬Apache SolrÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ConfigSet API±£´æÎļþÉÏ´«Îó²î£¬£¬£¬£¬Îó²î×·×ÙΪCVE-2020-13957¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÁ¬ÏµÊ¹ÓÃUPLOAD/CREATE²Ù×÷À´Èƹý¼ì²é£¬£¬£¬£¬ÒÔ»ñȡЧÀÍÆ÷ȨÏÞ¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£

0x02 ´¦Öóͷ£½¨Òé

1. ÈôÊÇδʹÓÃConfigSets API£¬£¬£¬£¬Ôò½«ÏµÍ³ÊôÐÔconfigset.upload.enabledÉèÖÃΪfalseÒÔ½ûÓÃUPLOADÏÂÁî¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó£º

https://lucene.apache.org/solr/guide/8_6/configsets-api.html

 

2. ʹÓÃÉí·ÝÑéÖ¤/ÊÚȨ£¬£¬£¬£¬²¢È·±£ÇëÇóÕýµ±¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó£º

https://lucene.apache.org/solr/guide/8_6/authentication-and-authorization-plugins.html

 

3. ½«SolrÉý¼¶µ½ 8.6.3»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ÈôÊÇÎÞ·¨Éý¼¶£¬£¬£¬£¬ÔòÓ¦ÓÃSOLR-14663ͨ¸æÖеIJ¹¶¡£¡£¡£¡£¡£º

²Î¿¼Á´½Ó£º

https://issues.apache.org/jira/browse/SOLR-14663

 

4. ²»½«Solr API£¨°üÀ¨Admin UI£©Ïò²»ÊÜÐÅÈεĵÚÈý·½¹ûÕæ¡£¡£¡£¡£¡£µ÷½â·À»ðǽսÂÔ£¬£¬£¬£¬È·±£Ö»ÓÐÊÜÐÅÈεÄÅÌËã»úºÍÓû§²Å»ª»á¼û¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.mail-archive.com/announce@apache.org/msg06149.html

https://issues.apache.org/jira/browse/SOLR-14925

0x04 ʱ¼äÏß

2020-10-12  ApacheÐû²¼Ç徲ͨ¸æ

2020-10-13  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

image.png