diff --git a/s/spring/1/Dockerfile b/s/spring/1/Dockerfile index 2a556e4..72737b6 100644 --- a/s/spring/1/Dockerfile +++ b/s/spring/1/Dockerfile @@ -1,7 +1,7 @@ FROM openjdk:8-jdk MAINTAINER Medici.Yan@Gmail.com -ENV JAR_URL http://vulapps.poetn.cc/s/spring/spring-data-rest/spring-data-rest-cve-2017-8046.jar +ENV JAR_URL http://vulapps.poetn.cc/s/spring/spring-data-rest/spring-data-rest-cve-2017-8046_v2.jar COPY src/start.sh /start.sh diff --git a/s/spring/1/README.md b/s/spring/1/README.md index 3d8b290..adc77ae 100644 --- a/s/spring/1/README.md +++ b/s/spring/1/README.md @@ -28,8 +28,6 @@ $ docker run -d -p 8080:8080 medicean/vulapps:s_spring_1 1. 访问 `http://127.0.0.1:8080/`,测试服务是否启动成功 - > 第一次启动时会下载 mongodb,网速慢的可能要多等一会儿 - ![](https://github.com/Medicean/VulApps/raw/master/s/spring/1/poc-1.png) 2. 利用 POST 请求添加一个数据 @@ -66,3 +64,7 @@ Content-Length: 228 ### 参考链接 * [这个Spring高危漏洞,你修补了吗?-- 其河@美团点评技术团队](https://mp.weixin.qq.com/s/uTiWDsPKEjTkN6z9QNLtSA) + +### 改动日志 + +* 2017/09/29 删除原 jar 包中 mongodb 依赖 diff --git a/s/spring/1/poc-1.png b/s/spring/1/poc-1.png index 4fc2e03..0b25b6d 100644 Binary files a/s/spring/1/poc-1.png and b/s/spring/1/poc-1.png differ