为何含分号的URL绕过Nginx的/actuator/路径访问限制?
问题原因分析
1. URI规范化导致location匹配失效
Nginx默认开启uri_normalization on,会对请求URI进行规范化处理,包括解析路径中的../、合并连续斜杠等。当请求/actuator/prometheus;%2f..%2f..//到达时:
- 首先被URL解码为
/actuator/prometheus;/../../; - Nginx将分号后的
/../../识别为路径的一部分,规范化后整个路径被简化为/; - 此时
location /actuator/的前缀匹配不再生效,请求转而匹配优先级更低的location /,绕过了IP限制规则。
2. 无错误日志的原因
因为请求最终匹配的是location /,该规则没有deny限制,直接代理到后端,所以不会触发403错误,自然也不会生成错误日志。
调试方法
开启调试日志追踪匹配过程
在Nginx的http块中添加以下配置,重启后重新发送请求,查看调试日志可明确URI处理和location匹配的每一步:debug_connection 你的客户端IP或IP段; error_log /var/log/nginx/debug.log debug;添加自定义响应头验证匹配结果
修改两个location块,分别添加唯一标识的响应头,发送请求后查看响应头即可确认请求匹配的是哪个location:location /actuator/ { add_header X-Matched-Location "actuator-restricted"; allow 10.1.1.0/24; deny all; proxy_pass http://10.1.1.1:8989; } location / { add_header X-Matched-Location "root-unrestricted"; proxy_pass http://10.1.1.1:8989; }临时关闭URI规范化验证猜想
在/actuator/的location块中临时添加uri_normalization off,重新发送请求,若此时触发403,则可确认是规范化导致的匹配失效:location /actuator/ { uri_normalization off; allow 10.1.1.0/24; deny all; proxy_pass http://10.1.1.1:8989; }
内容的提问来源于stack exchange,提问作者Doodle-loo
相关产品推荐
相关产品推荐

