Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Any File Read #332

Open
nlrvana opened this issue Feb 20, 2025 · 17 comments
Open

Any File Read #332

nlrvana opened this issue Feb 20, 2025 · 17 comments
Assignees

Comments

@nlrvana
Copy link

nlrvana commented Feb 20, 2025

No Pwn!

@noear
Copy link
Member

noear commented Feb 20, 2025

谢谢反馈!

@nlrvana
Copy link
Author

nlrvana commented Feb 20, 2025

谢谢反馈!

可以申请一个CVE嘛🤔

@noear
Copy link
Member

noear commented Feb 21, 2025

@nlrvana 可以的:)

@nlrvana
Copy link
Author

nlrvana commented Feb 21, 2025

@nlrvana可以的:)

okk 这个要我自己去申请吗

@noear
Copy link
Member

noear commented Feb 21, 2025

我还不熟为块。。。得你自己来了:) @nlrvana

另外,我尝试了修复。。。帮忙试一下: 3.1.0-SNAPSHOT

这是快照版本的使用说明:https://solon.noear.org/article/640


目前的方案,是在静态处理这块做了过滤(动态的仍允许接收到这个请求);;;是不是对所有的请求进行过滤,更好?

@nlrvana
Copy link
Author

nlrvana commented Feb 21, 2025

我还不熟为块。。。得你自己来了:) @nlrvana

另外,我尝试了修复。。。帮忙试一下: 3.1.0-SNAPSHOT

这是快照版本的使用说明:https://solon.noear.org/article/640

目前的方案,是在静态处理这块做了过滤(动态的仍允许接收到这个请求);;;是不是对所有的请求进行过滤,更好?

我来试试 是这样的,这个漏洞主要产生在静态处理的地方,所以只需要过滤静态处理就可以。毕竟solon框架没有选择tomcat这种大型中间件所以并不会解析../,包括很多知名的大型框架springboot(在选择了如netty中间件等情况下)等 他们都是过滤了静态处理的请求

@noear
Copy link
Member

noear commented Feb 21, 2025

好,麻烦了!

@noear noear self-assigned this Feb 21, 2025
@nlrvana
Copy link
Author

nlrvana commented Feb 21, 2025

好,麻烦了!

啊? 我按照你给的方式进行了更新。但是版本仍然是3.0.8
Image

@noear
Copy link
Member

noear commented Feb 21, 2025

@nlrvana 可能需要多刷新一下。。。或者,你直接用 3.0.9-M2 测试(刚发的测试版)

@nlrvana
Copy link
Author

nlrvana commented Feb 21, 2025

你可以把他提交到github上面,我下载后再继续测试

@nlrvana 可能需要多刷新一下。。。或者,你直接用 3.0.9-M2 测试(刚发的测试版)

🤔 我只看到了M1

Image

@noear
Copy link
Member

noear commented Feb 21, 2025

创建项目后,直接改下就好了:)

@nlrvana
Copy link
Author

nlrvana commented Feb 21, 2025

创建项目后,直接改下就好了:)

你似乎只是修复了../,但是在Windows中也可以识别到..\,但是我不是Windows,而是Mac系统无法再帮你测试了,抱歉☹️

@noear
Copy link
Member

noear commented Feb 21, 2025

好,我再加个 "..\" 过滤

@noear
Copy link
Member

noear commented Feb 21, 2025

3.0.9 发了。试下

@nlrvana
Copy link
Author

nlrvana commented Feb 21, 2025

3.0.9 发了。试下

似乎已经没有漏洞了

@noear
Copy link
Member

noear commented Feb 21, 2025

去申请 CVE 吧

@nlrvana
Copy link
Author

nlrvana commented Feb 21, 2025

我已经申请了,但他们的效率似乎有点慢。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants