Apache Software Foundation (ASF) Struts ‘org.apache.struts.taglib.html.Constants.CANCEL’ 参数安全绕过漏洞

漏洞信息详情

Apache Software Foundation (ASF) Struts ‘org.apache.struts.taglib.html.Constants.CANCEL’ 参数安全绕过漏洞

漏洞简介

Apache Software Foundation (ASF) Struts 1.2.9之前版本可让远程攻击者通过以下途径绕过身份验证程序:用一条带\’\’org.apache.struts.taglib.html.Constants.CANCEL\’\’ 参数的请求,从而引起操作被取消,但不会被未使用isCancelled检查的应用程序检测到。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Apache Software Foundation Struts 1.1

Apache Software Foundation struts-1.2.9-src.tar.gz

http://apache.mirrors.northco.net/struts/source/struts-1.2.9-src.tar.g z

Apache Software Foundation Struts 1.1

Apache Software Foundation struts-1.2.9-src.tar.gz

http://apache.mirrors.northco.net/struts/source/struts-1.2.9-src.tar.g z

Apache Software Foundation Struts 1.2.7

Apache Software Foundation struts-1.2.9-src.tar.gz

http://apache.mirrors.northco.net/struts/source/struts-1.2.9-src.tar.g z

Apache Software Foundation Struts 1.2.8

Apache Software Foundation struts-1.2.9-src.tar.gz

http://apache.mirrors.northco.net/struts/source/struts-1.2.9-src.tar.g z

参考网址

来源: struts.apache.org

链接:http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html

来源: MLIST

名称: [struts-user] 20060121 Validation Security Hole?

链接:http://mail-archives.apache.org/mod_mbox/struts-user/200601.mbox/%3c20060121221800.15814.qmail@web32607.mail.mud.yahoo.com%3e

来源: MLIST

名称: [struts-devel] 20060122 Re: Validation Security Hole?

链接:http://mail-archives.apache.org/mod_mbox/struts-dev/200601.mbox/%3cdr169r$623$2@sea.gmane.org%3e

来源: issues.apache.org

链接:http://issues.apache.org/bugzilla/show_bug.cgi?id=38374

来源: XF

名称: struts-iscancelled-security-bypass(25612)

链接:http://xforce.iss.net/xforce/xfdb/25612

来源: BID

名称: 17342

链接:http://www.securityfocus.com/bid/17342

来源: VUPEN

名称: ADV-2006-1205

链接:http://www.frsirt.com/english/advisories/2006/1205

来源: SECTRACK

名称: 1015856

链接:http://securitytracker.com/id?1015856

来源: SECUNIA

名称: 20117

链接:http://secunia.com/advisories/20117

来源: SECUNIA

名称: 19493

链接:http://secunia.com/advisories/19493

来源: SUSE

名称: SUSE-SR:2006:010

链接:http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享