Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Spring Boot ÈÏÖ¤ÈÆ¹ýÎó²î |
CVE ID | CVE-2026-22733 |
Îó²îÀàÐÍ | ÈÏÖ¤ÈÆ¹ý | ·¢Ã÷ʱ¼ä | 2026-3-20 |
Îó²îÆÀ·Ö | 8.2 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Spring BootÊÇÓÉSpring¹Ù·½ÌṩµÄ¿ªÔ´JavaÓ¦Óÿª·¢¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¿ìËÙ¹¹½¨×ÔÁ¦¡¢Éú²ú¼¶µÄSpringÓ¦Óᣡ£¡£¡£¡£ÆäÄÚÖÃActuator×é¼þÓÃÓÚ¼à¿ØºÍÖÎÀíÓ¦ÓÃÔËÐÐ״̬£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¿µ½¡¼ì²é¡¢Ö¸±êÊÕÂÞ¼°ÔËά½Ó¿ÚÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ΢ЧÀͼܹ¹ºÍÔÆÔÉúÇéÐΡ£¡£¡£¡£¡£
2026Äê3ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬°ÙÀÖ²©Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Spring Boot ÈÏÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£µ±Ó¦Óý«ÐèÒªÉí·ÝÈÏÖ¤µÄÓªÒµ¶Ëµã¹ýʧµØÓ³Éäµ½CloudFoundry Actuator·¾¶ÏÂʱ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚActuatorÓëSpring SecurityµÄ·¾¶´¦Öóͷ£»úÖÆ±£´æ³åÍ»£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö»á¼û¿ØÖÆÊ§Ð§¡£¡£¡£¡£¡£¹¥»÷ÕßÎÞÐèÉí·ÝÈÏÖ¤¼´¿É»á¼ûÔ±¾Êܱ£»£»£»£»£»¤µÄ½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐδÊÚȨ²Ù×÷¡£¡£¡£¡£¡£¸ÃÎó²îͨ³£·ºÆðÔÚͬʱÒýÈëActuatorÓëSpring SecurityÒÀÀµÇÒ±£´æ²»¹æ·¶Â·¾¶ÉèÖõÄWebÓ¦ÓÃÖС£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢È¨ÏÞÌáÉýÉõÖÁÓªÒµÂß¼ÀÄÓ㬣¬£¬£¬£¬£¬£¬½ø¶øÎ¥·´Êý¾ÝÇå¾²¼°Òþ˽±£»£»£»£»£»¤Ïà¹ØºÏ¹æÒªÇ󣬣¬£¬£¬£¬£¬£¬¶ÔÆóҵϵͳÇå¾²Ôì³É½Ï´óΣº¦¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
2.7.0 <= Spring Boot < 2.7.323.3.0 <= Spring Boot < 3.3.183.4.0 <= Spring Boot < 3.4.153.5.0 <= Spring Boot < 3.5.124.0.0 <= Spring Boot < 4.0.4
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/spring-projects/spring-boot/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://spring.io/security/cve-2026-22733/https://nvd.nist.gov/vuln/detail/CVE-2026-22733