The Power of Taint Analysis: Uncovering Critical Code Vulnerability in OpenAPI Generator
2025-07-11 11:01:00

涓婂鏃訛紝鍙跺瓙濯氬彂鑲插緱寰堝ソ锛岃涔︿笉鎬庝箞鐢ㄥ姛锛屽ぇ閮ㄥ垎鏃墮棿閮借姳鍦ㄧ┛鐫€鎵撴壆涓娿€?

鑰屾矇瀵備簡榪欎箞涔呯殑鏅敎锛屽嚟浠€涔堥潬銆婂徃鈃ゃ€嬩竴涓嬪氨鐏簡銆?瑕佺煡閬撱€婂徃鈃ゃ€嬪紑鎾墠锛屽悇鏂瑰0闊抽兘涓嶇湅濂借繖閮ㄥ墽锛岃€屼笖鐢峰コ涓昏鏅敎寮犲漿褰兘鏄€滄崸涓嶇孩浣撹川鈥濄€?

The Power of Taint Analysis: Uncovering Critical Code Vulnerability in OpenAPI Generator

閭d負浣曡繖鏍蜂竴閮ㄥ紑鎾墠琚ぇ澶氭暟浜轟笉鐪嬪ソ鐨勩€婂徃鈃ゃ€嬶紝寮€鎾悗鍗磋兘榪呴€熷湪鍚勫ぇ紺句氦騫衝彴寮曡搗騫挎硾璁ㄨ锛岀儹搴︾敋鑷寵刀瓚呫€婂北娌充護銆嬶紝鑰屽コ涓繪櫙鐢滀篃棰戜笂鐑悳鍛紵銆婂徃鈃ゃ€嬫湰韜繖涓」鐩畾浣嶅氨涓嶆槸寰堥珮锛岃祫婧愭湁闄愶紝鎵€浠ュ婕斿拰鍓х粍寰堝浜嬮兘浜插姏浜蹭負锛屽氨榪炲婕旀潕鏈ㄦ垐閮戒翰鑷笂闀滀負鍓х粍鐪侀挶銆?銆婂徃鈃ゃ€嬩箣鍓嶆洿鏄鐖嗘枡鍓т腑鐨勭兢婕旈兘鏄紑鎷嶅墠鈥滈殢鏈烘姄浜衡€濓紝鍍忔槸寮犲漿褰姪鐞嗘紨榪囧徃鏈猴紝鍓婕旂殑濡誨瓙鍎垮瓙婕旇繃鍓т腑鐨勮礬浜虹敳姣嶄翰鍜屽効瀛愶紝鐢氳嚦鎺㈢彮璁拌€呬篃琚€滄姄鈥濆幓褰撲簡涓€嬈$兢婕旓紝鐪熸槸鑳界渷鍒欑渷銆?鍓т腑鏅敎鐨勮澶氭棗琚嶉€犲瀷锛屼護涓嶅皯瑙備紬鍗拌薄娣卞埢锛屾洿鏈変笉灝戠矇涓濇槸涓撻棬涓轟簡鐪嬫櫙鐢滅殑閫犲瀷鎵嶅靉鍧戠殑銆?

The Power of Taint Analysis: Uncovering Critical Code Vulnerability in OpenAPI Generator

鍓т腑锛屼粠鍙歌棨澶嶆椿寮€濮嬶紝鏅敎灝變竴鐩寸┛鐨勬槸鏃楄锛岃€屼笖閫犲瀷甯堣繕鏍規嵁鍓ф儏闇€瑕侊紝璁捐浜嗘皯鍥芥椂鏈熷拰鐜頒唬涓嶅悓椋庢牸鐨勫濂楅€犲瀷銆?鑰屼笖闄や簡鍦ㄥコ涓誨徃鈃ょ殑鏃楄涓婄敤蹇冧簡涔嬪锛屽墽涓櫙鐢滅殑鍖呭寘鍜岄楗幫紝浠ュ強濂充簩鍙鋒矆閾剁伅韜笂鐨勪紬澶氶摱楗頒篃寮曡搗浜嗚浼楃殑娉ㄦ剰銆?

The Power of Taint Analysis: Uncovering Critical Code Vulnerability in OpenAPI Generator

榪樻湁緗戝弸鍦ㄦ煇紺句氦騫衝彴鍙戞枃锛屽墽涓矆閾剁伅鍜屽ぎ娉㈢殑嫻瘋獡灞辯洘瀵規垝锛屽徃鈃ょ殑鍑犳鍖呭寘涔熸潵鑷繖瀹跺簵锛岀敋鑷蟲矆閾剁伅楠楀徃鈃よ鎵懼埌浜嗚丹浼炲發絀存椂瑁呰嬋′箣娉ョ殑鐩掑瓙閮芥潵鑷ぇ鐞嗗彜鍩庣殑涓€瀹跺簵銆?

銆婂徃鈃ゃ€嬫牴鎹笉鍚屽満鏅殑闇€瑕侊紝鎷嶆憚鍙栨櫙璧拌繃浜嗕竴涓囧鍏噷銆?1988騫存潕鑺告倓鐒墮€€闅愮編鍥界粨濠氱敓瀛愶紝1995騫撮噸榪斿獎瑙嗗湀锛屽伓灝旀媿鎴忋€?

鏋楄姵鍏墊渶钁楀悕鐨勮鑹叉槸鐢佃鍓с€婂攼鏄庣殗銆嬮噷鎵紨鐨勬潹璐靛锛屽ス澧炶偉30鏂ゅ悗婕斿嚭鐨勬潹璐靛鐝犲渾鐜夋鼎銆侀泹瀹瑰崕璐碉紝鏄綋涓嬮偅浜涚氦鑵板皷鑴哥殑濂蟲槑鏄熸墍姣旀嫙涓嶄簡鐨勶紝濂逛篃鍥犳鑾峰緱榪囬噾楣板瑙嗗悗妗傚啝銆?浣嗘灄鑺衝叺鐨勮韓浣撳嵈鍥犱負澧炶偉銆佸噺鑲ュ厓姘斿ぇ浼わ紝鍏勾澶氭棤娉曟媿鎴忥紝鐩村埌90騫翠唬鏈湡鎵嶅鍑恒€?

鑲栭泟姣曚笟浜庡寳浜數褰卞闄?5鏄庢槦鐝紝1983騫達紝濂瑰洜涓繪紨鐢佃鍓с€婅箟璺庡瞾鏈堛€嬭幏寰楃涓€灞婁腑鍥界數瑙嗛噾楣板鏈€浣衝コ涓昏銆?濂規槸褰撴椂灝戞暟娌℃湁鍚戝闂殑浜猴紝榪欎箞澶氬勾鏉ヤ竴鐩存椿璺冨湪褰辮浣滃搧閲岋紝鐜板湪緇忓父浼氬湪褰辮浣滃搧閲岀湅鍒板ス鎵紨鐨勭敺濂充富瑙掔殑濡堝銆?

(作者:歐倩怡)