Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Spring Boot ÈÏÖ¤ÈÆ¹ýÎó²î |
CVE ID | CVE-2026-22733 |
Îó²îÀàÐÍ | ÈÏÖ¤ÈÆ¹ý | ·¢Ã÷ʱ¼ä | 2026-3-20 |
Îó²îÆÀ·Ö | 8.2 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Spring BootÊÇÓÉSpring¹Ù·½ÌṩµÄ¿ªÔ´JavaÓ¦Óÿª·¢¿ò¼Ü£¬£¬£¬£¬£¬£¬ÓÃÓÚ¿ìËÙ¹¹½¨×ÔÁ¦¡¢Éú²ú¼¶µÄSpringÓ¦Óᣡ£¡£¡£¡£¡£¡£ÆäÄÚÖÃActuator×é¼þÓÃÓÚ¼à¿ØºÍÖÎÀíÓ¦ÓÃÔËÐÐ״̬£¬£¬£¬£¬£¬£¬Ö§³Ö¿µ½¡¼ì²é¡¢Ö¸±êÊÕÂÞ¼°ÔËά½Ó¿ÚÖÎÀí£¬£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ΢ЧÀͼܹ¹ºÍÔÆÔÉúÇéÐΡ£¡£¡£¡£¡£¡£¡£
2026Äê3ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬Z6×ðÁú¿Ê±Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Spring Boot ÈÏÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£µ±Ó¦Óý«ÐèÒªÉí·ÝÈÏÖ¤µÄÓªÒµ¶Ëµã¹ýʧµØÓ³Éäµ½CloudFoundry Actuator·¾¶ÏÂʱ£¬£¬£¬£¬£¬£¬ÓÉÓÚActuatorÓëSpring SecurityµÄ·¾¶´¦Öóͷ£»úÖÆ±£´æ³åÍ»£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö»á¼û¿ØÖÆÊ§Ð§¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÎÞÐèÉí·ÝÈÏÖ¤¼´¿É»á¼ûÔ±¾Êܱ£»£»£»£»£»£»£»¤µÄ½Ó¿Ú£¬£¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐδÊÚȨ²Ù×÷¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îͨ³£·ºÆðÔÚͬʱÒýÈëActuatorÓëSpring SecurityÒÀÀµÇÒ±£´æ²»¹æ·¶Â·¾¶ÉèÖõÄWebÓ¦ÓÃÖС£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢È¨ÏÞÌáÉýÉõÖÁÓªÒµÂß¼ÀÄÓ㬣¬£¬£¬£¬£¬½ø¶øÎ¥·´Êý¾ÝÇå¾²¼°Òþ˽±£»£»£»£»£»£»£»¤Ïà¹ØºÏ¹æÒªÇ󣬣¬£¬£¬£¬£¬¶ÔÆóҵϵͳÇå¾²Ôì³É½Ï´óΣº¦¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
2.7.0 <= Spring Boot < 2.7.323.3.0 <= Spring Boot < 3.3.183.4.0 <= Spring Boot < 3.4.153.5.0 <= Spring Boot < 3.5.124.0.0 <= Spring Boot < 4.0.4
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/spring-projects/spring-boot/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://spring.io/security/cve-2026-22733/https://nvd.nist.gov/vuln/detail/CVE-2026-22733