¡¾Ç徲ͨ¸æ¡¿Apache Solrí§ÒâÎļþ¶ÁÈ¡ÓëSSRFÎó²îͨ¸æ
2021-03-18
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½ÍøÉÏÅû¶ÁËApache SolrµÄÎļþ¶ÁÈ¡ÓëSSRFÎó²î£¬ÓÉÓÚApache SolrĬÈÏ×°ÖÃʱ먦ÆôÉí·ÝÑéÖ¤£¬µ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓÃConfig API·¿ªrequestDispatcher.requestParsers.enableRemoteStreaming¿ª¹Ø£¬´Ó¶øÊ¹ÓÃÎó²î¾ÙÐÐÎļþ¶ÁÈ¡¡£ÏÖÔÚÎó²îPoCÒѹûÕæ£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
Apache SolrÊÇ Apache Lucene ÏîÄ¿µÄ¿ªÔ´ÆóÒµËÑË÷ƽ̨£¬ÓÉJava¿ª·¢£¬ÔËÐÐÓÚServletÈÝÆ÷£¨ÈçApache Tomcat»òJetty£©µÄÒ»¸ö×ÔÁ¦µÄÈ«ÎÄËÑË÷·þÎñÆ÷£¬Ö÷Òª¹¦Ð§°üÀ¨È«ÎļìË÷¡¢ÖÀÖбêʾ¡¢·ÖÃæËÑË÷¡¢¶¯Ì¬¾ÛÀà¡¢Êý¾Ý¿â¼¯³É£¬ÒÔ¼°¸»Îı¾µÄ´¦Öóͷ£¡£
²Î¿¼Á´½Ó£º
https://issues.apache.org/jira/browse/SOLR?spm=a2c4g.11174386.n2.4.4fda1051uA9TBw
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
Apache Solr <= 8.8.1£¨È«°æ±¾£©
Èý. Îó²î·À»¤
ÓÉÓÚÏÖÔÚ¹Ù·½²»ÓèÐÞ¸´¸ÃÎó²î£¬ÔÝÎÞÇå¾²°æ±¾¡£
3.1 ·À»¤²½·¥
1. ¿ªÆôÉí·ÝÑéÖ¤/ÊÚȨ£¬²Î¿¼¹Ù·½Îĵµ£ºhttps://lucene.apache.org/solr/guide/8_6/authentication-and-authorization-plugins.html
2. ÉèÖ÷À»ðǽսÂÔ£¬È·±£Solr API£¨°üÀ¨Admin UI£©Ö»ÓÐÊÜÐÅÍеÄIPºÍÓû§²Å»ª»á¼û¡£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







