如何在Spring Security 6.2.1中修复Maven依赖Guava的CVE-2023-2976漏洞?
解决Maven项目中Guava CVE-2023-2976漏洞问题
你遇到的CVE-2023-2976漏洞,是Guava 31.1-jre版本中Files.createTempDir()方法的临时目录权限配置不当导致的外部可访问风险,该漏洞在Guava 32.0.0-jre及后续版本已修复。你当前排除opensaml-core的方式无效,核心原因是项目中可能有多个依赖都引入了旧版本Guava,只排除其中一个无法完全清除旧依赖。
步骤1:定位所有引入旧版本Guava的依赖
先执行Maven命令,查看项目中所有引入Guava的依赖路径:
mvn dependency:tree -Dincludes=com.google.guava:guava
执行后会输出类似结果,能清楚看到哪些依赖带进来了Guava 31.1-jre:
[INFO] --- maven-dependency-plugin:3.6.1:tree (default-cli) @ your-project --- [INFO] com.your.group:your-project:jar:1.0.0 [INFO] +- org.springframework.security:spring-security-saml2-service-provider:jar:6.2.1:compile [INFO] | +- org.opensaml:opensaml-core:jar:4.1.1:compile [INFO] | | +- com.google.guava:guava:jar:31.1-jre:compile [INFO] +- other.dependency:some-lib:jar:1.0.0:compile [INFO] | +- com.google.guava:guava:jar:31.1-jre:compile
步骤2:彻底修复漏洞的两种方法
方法一:直接声明Guava安全版本(推荐)
Maven会优先使用直接在pom.xml中声明的依赖版本,无需逐个排查排除。直接添加以下依赖到你的pom.xml中:
<dependency> <groupId>com.google.guava</groupId> <artifactId>guava</artifactId> <version>32.0.0-jre</version> <!-- 或更高的稳定版本 --> </dependency>
添加后重新执行mvn dependency:tree验证,所有Guava的依赖版本都会被替换为32.0.0-jre及以上。
方法二:逐个排除所有旧版本Guava的引入
如果不想直接声明Guava版本,需要针对步骤1中找到的每个引入旧版本Guava的依赖,添加排除规则。比如假设除了opensaml-core,还有some-lib也引入了旧Guava,那么需要修改对应的依赖:
<!-- 排除spring-security-saml2-service-provider中的旧Guava --> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-saml2-service-provider</artifactId> <exclusions> <exclusion> <groupId>com.google.guava</groupId> <artifactId>guava</artifactId> </exclusion> </exclusions> </dependency> <!-- 排除其他依赖中的旧Guava --> <dependency> <groupId>other.dependency</groupId> <artifactId>some-lib</artifactId> <exclusions> <exclusion> <groupId>com.google.guava</groupId> <artifactId>guava</artifactId> </exclusion> </exclusions> </dependency>
注意:这种方法需要确保所有引入旧Guava的依赖都被排除,否则漏洞依然存在。
验证修复结果
执行以下命令确认项目中已无Guava 31.1-jre版本:
mvn dependency:tree -Dincludes=com.google.guava:guava | grep 31.1-jre
如果没有输出,说明旧版本已被替换或排除,漏洞修复完成。
内容的提问来源于stack exchange,提问作者Ah1996
相关产品推荐
相关产品推荐

