Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Spring Boot ÈÏÖ¤ÈÆ¹ýÎó²î |
CVE ID | CVE-2026-22733 |
Îó²îÀàÐÍ | ÈÏÖ¤ÈÆ¹ý | ·¢Ã÷ʱ¼ä | 2026-3-20 |
Îó²îÆÀ·Ö | 8.2 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Spring BootÊÇÓÉSpring¹Ù·½ÌṩµÄ¿ªÔ´JavaÓ¦Óÿª·¢¿ò¼Ü£¬£¬£¬£¬ÓÃÓÚ¿ìËÙ¹¹½¨×ÔÁ¦¡¢Éú²ú¼¶µÄSpringÓ¦Óᣡ£¡£ÆäÄÚÖÃActuator×é¼þÓÃÓÚ¼à¿ØºÍÖÎÀíÓ¦ÓÃÔËÐÐ״̬£¬£¬£¬£¬Ö§³Ö¿µ½¡¼ì²é¡¢Ö¸±êÊÕÂÞ¼°ÔËά½Ó¿ÚÖÎÀí£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ΢ЧÀͼܹ¹ºÍÔÆÔÉúÇéÐΡ£¡£¡£
2026Äê3ÔÂ20ÈÕ£¬£¬£¬£¬¿Ê±K66Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Spring Boot ÈÏÖ¤ÈÆ¹ýÎó²î¡£¡£¡£µ±Ó¦Óý«ÐèÒªÉí·ÝÈÏÖ¤µÄÓªÒµ¶Ëµã¹ýʧµØÓ³Éäµ½CloudFoundry Actuator·¾¶ÏÂʱ£¬£¬£¬£¬ÓÉÓÚActuatorÓëSpring SecurityµÄ·¾¶´¦Öóͷ£»úÖÆ±£´æ³åÍ»£¬£¬£¬£¬¿ÉÄܵ¼Ö»á¼û¿ØÖÆÊ§Ð§¡£¡£¡£¹¥»÷ÕßÎÞÐèÉí·ÝÈÏÖ¤¼´¿É»á¼ûÔ±¾Êܱ£»£»£»¤µÄ½Ó¿Ú£¬£¬£¬£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐδÊÚȨ²Ù×÷¡£¡£¡£¸ÃÎó²îͨ³£·ºÆðÔÚͬʱÒýÈëActuatorÓëSpring SecurityÒÀÀµÇÒ±£´æ²»¹æ·¶Â·¾¶ÉèÖõÄWebÓ¦ÓÃÖС£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢È¨ÏÞÌáÉýÉõÖÁÓªÒµÂß¼ÀÄÓ㬣¬£¬£¬½ø¶øÎ¥·´Êý¾ÝÇå¾²¼°Òþ˽±£»£»£»¤Ïà¹ØºÏ¹æÒªÇ󣬣¬£¬£¬¶ÔÆóҵϵͳÇå¾²Ôì³É½Ï´óΣº¦¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
2.7.0 <= Spring Boot < 2.7.323.3.0 <= Spring Boot < 3.3.183.4.0 <= Spring Boot < 3.4.153.5.0 <= Spring Boot < 3.5.124.0.0 <= Spring Boot < 4.0.4
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¡£¡£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/spring-projects/spring-boot/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://spring.io/security/cve-2026-22733/https://nvd.nist.gov/vuln/detail/CVE-2026-22733