You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wildfly上Java应用特定URL存在Host头攻击漏洞求助

解决Wildfly中不带尾斜杠URL的Host头攻击漏洞

问题根源

当请求URL(如/app)末尾不带斜杠时,Wildfly的Undertow容器会自动触发302重定向,将请求导向带斜杠的URL(/app/)。这个重定向的Location头直接使用请求中的Host字段生成,这一步发生在应用过滤器执行之前,导致你配置的AppFilter完全没机会拦截并修正恶意Host头,从而暴露漏洞。

解决方案

1. 禁用容器自动尾斜杠重定向

直接关闭Wildfly的自动重定向功能,让请求直接进入应用过滤器处理。在standalone.xml的undertow子系统中,修改servlet-container配置:

<subsystem xmlns="urn:jboss:domain:undertow:12.0" default-server="default-server" default-virtual-host="default-host" default-servlet-container="default" default-security-domain="other">
    <server name="default-server">
        <http-listener name="default" socket-binding="http" redirect-socket="https" enable-http2="true"/>
        <host name="default-host" alias="localhost">
            <location name="/" handler="welcome-content"/>
            <filter-ref name="server-header"/>
            <filter-ref name="x-powered-by-header"/>
        </host>
    </server>
    <servlet-container name="default" redirect-servlet-path="false"> <!-- 添加此属性 -->
        <jsp-config/>
        <websockets/>
    </servlet-container>
    <!-- 其他配置... -->
</subsystem>

添加redirect-servlet-path="false"后,容器不再自动重定向不带斜杠的URL,请求会直接进入你的AppFilter,由过滤器处理Host头校验逻辑。

2. 在容器层面配置Host头校验

如果不想禁用重定向,可以在Undertow层面添加Host头过滤,确保所有请求(包括容器重定向的请求)都使用合法的Host值。在standalone.xml中添加自定义过滤器:

<subsystem xmlns="urn:jboss:domain:undertow:12.0">
    <!-- 定义过滤器 -->
    <filters>
        <!-- 自定义Host校验过滤器 -->
        <filter name="valid-host-filter" class-name="com.foo.bar.ValidHostFilter" module="com.foo.bar"/>
        <!-- 或用内置重写过滤器强制替换Host头 -->
        <rewrite name="rewrite-host" redirect="true">
            <rule pattern="^.*$" substitution="http://your-valid-host:80%U" flags="R"/>
        </rewrite>
    </filters>
    <!-- 在host中引用过滤器(高优先级确保先执行) -->
    <server name="default-server">
        <host name="default-host" alias="localhost">
            <filter-ref name="valid-host-filter" priority="1"/>
            <!-- 若使用重写过滤器则替换为:<filter-ref name="rewrite-host"/> -->
        </host>
    </server>
    <!-- 其他配置... -->
</subsystem>

自定义的ValidHostFilter需要你实现Host头白名单校验逻辑,非法请求直接返回错误;重写过滤器则直接将Host替换为合法值,确保重定向的Location头安全。

3. 应用层面补充防护

作为额外防护,可以在web.xml中添加<security-constraint>限制非法Host的请求:

<security-constraint>
    <web-resource-collection>
        <web-resource-name>Valid Hosts Only</web-resource-name>
        <url-pattern>/*</url-pattern>
    </web-resource-collection>
    <auth-constraint/>
</security-constraint>
<security-constraint>
    <web-resource-collection>
        <web-resource-name>Allowed Hosts</web-resource-name>
        <url-pattern>/*</url-pattern>
    </web-resource-collection>
    <auth-constraint>
        <role-name>*</role-name>
    </auth-constraint>
    <host-name>localhost</host-name>
    <host-name>your-valid-domain.com</host-name>
</security-constraint>

该配置会拒绝来自非法Host的请求,需注意它依赖容器处理逻辑,要确保优先级设置正确。

为什么之前的修改无效

你修改root_path和添加url-pattern的操作无效,核心原因是容器的自动重定向发生在应用过滤器链执行之前——当请求/app时,Wildfly已经完成重定向响应,你的AppFilter根本没机会被调用,所以这些应用层面的配置无法影响这个过程。

内容的提问来源于stack exchange,提问作者ijm3

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 22:57:03