Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | RuoYi v4.7.9 ÈÏÖ¤Óû§SQL×¢ÈëÎó²î |
CVE ID | CVE-2024-57521 |
Îó²îÀàÐÍ | SQL×¢Èë | ·¢Ã÷ʱ¼ä | 2025-12-24 |
Îó²îÆÀ·Ö | 10 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
RuoYiÊÇÒ»¿î»ùÓÚJavaµÄ¿ìËÙ¿ª·¢¿ò¼Ü£¬£¬Ö÷ÒªÓÃÓÚ¹¹½¨ÆóÒµ¼¶ÖÎÀíϵͳ¡£¡£¡£Ëü½ÓÄÉSpring Boot¡¢MyBatisµÈÊÖÒÕ£¬£¬Ö§³Öǰºó¶ËÊèÉ¢£¬£¬¾ß±¸È¨ÏÞÖÎÀí¡¢´úÂëÌìÉú¡¢Êý¾Ýͳ¼ÆµÈ¹¦Ð§¡£¡£¡£RuoYiÌṩÁ˸»ºñµÄ»ù´¡¹¦Ð§ºÍ²å¼þ£¬£¬¿É¿ìËٴºǫ́ÖÎÀíϵͳ£¬£¬ÊÊÓÃÓÚÖÖÖÖÓªÒµ³¡¾°¡£¡£¡£¿£¿£¿£¿£¿ò¼ÜÄÚÖÃÍêÉÆµÄÇå¾²»úÖÆ£¬£¬ÈçȨÏÞ¿ØÖƺÍÈÕÖ¾ÖÎÀí£¬£¬ÊʺÏÖÐСÐÍÆóÒµºÍ¿ª·¢ÍŶӾÙÐж¨ÖÆ»¯¿ª·¢¡£¡£¡£RuoYi¾ßÓнϸߵĿÉÀ©Õ¹ÐÔºÍÎÞаÐÔ£¬£¬ÆÕ±éÓ¦ÓÃÓÚÆóÒµÐÅÏ¢»¯½¨ÉèÖС£¡£¡£
2025Äê12ÔÂ24ÈÕ£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½RuoYi¿ò¼Üv4.7.9±£´æSQL×¢ÈëÎó²î£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎó²îÖ´ÐÐí§ÒâSQLÏÂÁî¡£¡£¡£¸ÃÎó²î·ºÆðÔÚ¿ò¼ÜµÄcreateTable¹¦Ð§ÖУ¬£¬¹¥»÷ÕßʹÓÃSQL²ÎÊý·¢ËÍÌØÖÆÇëÇ󣬣¬´Ó¶ø´¥·¢×¢Èë¡£¡£¡£Îó²îµÄ»ù´¡Ôµ¹ÊÔÓÉÔÚÓÚSQL×¢Èë¹ýÂË»úÖÆ²»ÍêÉÆ£¬£¬filterKeywordÒªÁìÖеÄÕýÔò±í´ïʽδÄÜÓÐÓÃ×èµ²ÌØ¶¨µÄ×Ö·û£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»ÈƹýSQL×¢Èë¹ýÂË£¬£¬½á¹¹¶ñÒâµÄSQLÅÌÎÊ¡£¡£¡£Í¨¹ý¸ÃÎó²î£¬£¬¹¥»÷Õß¿ÉÒÔʹÓò¼¶ûäעÊÖÒÕ£¬£¬Öð²½Ð¹Â¶Êý¾Ý¿âÖеÄÃô¸ÐÐÅÏ¢»òÖ´ÐÐÆäËû¶ñÒâ²Ù×÷¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
RuoYi <= v4.7.9
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://gitee.com/y_project/RuoYi/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ïÔÌϵͳÎó²î£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://gitee.com/y_project/RuoYi/issues/IBC976/https://nvd.nist.gov/vuln/detail/CVE-2024-57521https://github.com/mrlihd/CVE-2024-57521-SQL-Injection-PoC/blob/main/README.md