You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Spring Security 6.2.1中修复Maven依赖Guava的CVE-2023-2976漏洞?

解决Maven项目中Guava CVE-2023-2976漏洞问题

你遇到的CVE-2023-2976漏洞,是Guava 31.1-jre版本中Files.createTempDir()方法的临时目录权限配置不当导致的外部可访问风险,该漏洞在Guava 32.0.0-jre及后续版本已修复。你当前排除opensaml-core的方式无效,核心原因是项目中可能有多个依赖都引入了旧版本Guava,只排除其中一个无法完全清除旧依赖。

步骤1:定位所有引入旧版本Guava的依赖

先执行Maven命令,查看项目中所有引入Guava的依赖路径:

mvn dependency:tree -Dincludes=com.google.guava:guava

执行后会输出类似结果,能清楚看到哪些依赖带进来了Guava 31.1-jre:

[INFO] --- maven-dependency-plugin:3.6.1:tree (default-cli) @ your-project ---
[INFO] com.your.group:your-project:jar:1.0.0
[INFO] +- org.springframework.security:spring-security-saml2-service-provider:jar:6.2.1:compile
[INFO] |  +- org.opensaml:opensaml-core:jar:4.1.1:compile
[INFO] |  |  +- com.google.guava:guava:jar:31.1-jre:compile
[INFO] +- other.dependency:some-lib:jar:1.0.0:compile
[INFO] |  +- com.google.guava:guava:jar:31.1-jre:compile

步骤2:彻底修复漏洞的两种方法

方法一:直接声明Guava安全版本(推荐)

Maven会优先使用直接在pom.xml中声明的依赖版本,无需逐个排查排除。直接添加以下依赖到你的pom.xml中:

<dependency>
    <groupId>com.google.guava</groupId>
    <artifactId>guava</artifactId>
    <version>32.0.0-jre</version> <!-- 或更高的稳定版本 -->
</dependency>

添加后重新执行mvn dependency:tree验证,所有Guava的依赖版本都会被替换为32.0.0-jre及以上。

方法二:逐个排除所有旧版本Guava的引入

如果不想直接声明Guava版本,需要针对步骤1中找到的每个引入旧版本Guava的依赖,添加排除规则。比如假设除了opensaml-core,还有some-lib也引入了旧Guava,那么需要修改对应的依赖:

<!-- 排除spring-security-saml2-service-provider中的旧Guava -->
<dependency>
    <groupId>org.springframework.security</groupId>
    <artifactId>spring-security-saml2-service-provider</artifactId>
    <exclusions>
        <exclusion>
            <groupId>com.google.guava</groupId>
            <artifactId>guava</artifactId>
        </exclusion>
    </exclusions>
</dependency>

<!-- 排除其他依赖中的旧Guava -->
<dependency>
    <groupId>other.dependency</groupId>
    <artifactId>some-lib</artifactId>
    <exclusions>
        <exclusion>
            <groupId>com.google.guava</groupId>
            <artifactId>guava</artifactId>
        </exclusion>
    </exclusions>
</dependency>

注意:这种方法需要确保所有引入旧Guava的依赖都被排除,否则漏洞依然存在。

验证修复结果

执行以下命令确认项目中已无Guava 31.1-jre版本:

mvn dependency:tree -Dincludes=com.google.guava:guava | grep 31.1-jre

如果没有输出,说明旧版本已被替换或排除,漏洞修复完成。

内容的提问来源于stack exchange,提问作者Ah1996

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 10:04:59