Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
spring-cloud__spring-cloud-config_CVE-2020-5405_2-1-6-RELEASE — 分布式系统的集中配置服务器,提供HTTP API、属性加密/解密,并支持Git、Vault、JDBC和本地文件系统后端。 | Kitploit
工具/GitHubGitHub/shoucheng3/spring-cloud__spring-cloud-config_cve-2020-5405_2-1-6-release
身份验证与授权加密/解密工具配置审计云安全DevSecOpsAPI 安全
GitHubshoucheng3/spring-cloud__spring-cloud-config_cve-2020-5405_2-1-6-release

spring-cloud__spring-cloud-config_CVE-2020-5405_2-1-6-RELEASE

分布式系统的集中配置服务器,提供HTTP API、属性加密/解密,并支持Git、Vault、JDBC和本地文件系统后端。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
271年前尚未审核

//// 请勿编辑此文件。此文件是自动生成的。 对此文件的手动更改将在重新生成时丢失。 请编辑 src/main/asciidoc/ 目录下的文件。 ////

image::https://circleci.com/gh/spring-cloud/spring-cloud-config/tree/master.svg?style=svg["CircleCI", link="https://circleci.com/gh/spring-cloud/spring-cloud-config/tree/master"] image::https://codecov.io/gh/spring-cloud/spring-cloud-config/branch/master/graph/badge.svg["Codecov", link="https://codecov.io/gh/spring-cloud/spring-cloud-config/branch/master"] image::https://api.codacy.com/project/badge/Grade/f064024a072c477e97dca6ed5a70fccd?branch=master["Codacy code quality", link="https://www.codacy.com/app/Spring-Cloud/spring-cloud-config?branch=master&utm_source=github.com&utm_medium=referral&utm_content=spring-cloud/spring-cloud-config&utm_campaign=Badge_Grade"]

Spring Cloud Config 在分布式系统中为外部化配置提供服务器端和客户端的支持。通过 Config Server,您可以集中管理所有环境中应用程序的外部属性。客户端和服务器的概念与 Spring 的 Environment 和 PropertySource 抽象完全一致,因此它们非常适合 Spring 应用程序,但也可以与任何语言编写的任何应用程序一起使用。当应用程序通过部署管道从开发环境到测试环境再到生产环境时,您可以管理这些环境之间的配置,并确保应用程序在迁移时拥有运行所需的一切。服务器存储后端的默认实现使用 git,因此它易于支持配置环境的标记版本,并且可以被广泛的工具用于管理内容。添加替代实现并通过 Spring 配置插入它们也很容易。

== 特性

=== Spring Cloud Config Server

Spring Cloud Config Server 提供以下好处:

  • 基于 HTTP 资源的外部配置 API(名称-值对或等效的 YAML 内容)
  • 加密和解密属性值(对称或非对称)
  • 可通过 @EnableConfigServer 轻松嵌入到 Spring Boot 应用程序中

=== Spring Cloud Config Client

特别针对 Spring 应用程序,Spring Cloud Config Client 让您可以:

  • 绑定到 Config Server 并使用远程属性源初始化 Spring Environment。
  • 加密和解密属性值(对称或非对称)。
  • 使用 @RefreshScope 注解 Spring @Bean,以便在配置更改时重新初始化。
  • 使用管理端点: ** /env 用于更新 Environment 并重新绑定 @ConfigurationProperties 和日志级别。 ** /refresh 用于刷新 @RefreshScope bean。 ** /restart 用于重启 Spring 上下文(默认禁用)。 ** /pause 和 /resume 用于调用 Lifecycle 方法(在 ApplicationContext 上调用 stop() 和 start())。
  • 引导应用程序上下文:主应用程序的父上下文,可被训练执行任何操作(默认情况下,它绑定到 Config Server 并解密属性值)。

== 快速开始

本快速开始将逐步演示如何使用 Spring Cloud Config Server 的服务器和客户端。

首先,启动服务器,如下所示:

$ cd spring-cloud-config-server
$ ../mvnw spring-boot:run

服务器是一个 Spring Boot 应用程序,因此您也可以从 IDE 中运行它(主类是 ConfigServerApplication)。

接下来,尝试一个客户端,如下所示:

$ curl localhost:8888/foo/development
{"name":"foo","label":"master","propertySources":[
  {"name":"https://github.com/scratches/config-repo/foo-development.properties","source":{"bar":"spam"}},
  {"name":"https://github.com/scratches/config-repo/foo.properties","source":{"foo":"bar"}}
]}

定位属性源的默认策略是克隆一个 git 仓库(在 spring.cloud.config.server.git.uri 中指定),并用它来初始化一个迷你 SpringApplication。迷你应用程序的 Environment 用于枚举属性源,并在 JSON 端点上发布它们。

HTTP 服务具有以下形式的资源:

/{application}/{profile}[/{label}]
/{application}-{profile}.yml
/{label}/{application}-{profile}.yml
/{application}-{profile}.properties
/{label}/{application}-{profile}.properties

其中 application 被注入为 SpringApplication 中的 spring.config.name(在常规 Spring Boot 应用中通常是 application),profile 是一个激活的配置文件(或逗号分隔的属性列表),label 是可选的 git 标签(默认为 master)。

Spring Cloud Config Server 从各种源拉取远程客户端的配置。以下示例从一个 git 仓库(必须提供)获取配置,如下所示:

[source,yaml]

spring:
  cloud:
    config:
      server:
        git:
          uri: https://github.com/spring-cloud-samples/config-repo

其他源包括任何 JDBC 兼容的数据库、Subversion、Hashicorp Vault、Credhub 和本地文件系统。

=== 客户端使用

要在应用程序中使用这些功能,您可以将其构建为依赖 spring-cloud-config-client 的 Spring Boot 应用程序(例如,请参阅 config-client 的测试用例或示例应用程序)。添加依赖最方便的方式是使用 Spring Boot 启动器 org.springframework.cloud:spring-cloud-starter-config。此外,还有针对 Maven 用户的父 pom 和 BOM(spring-cloud-starter-parent),以及针对 Gradle 和 Spring CLI 用户的 Spring IO 版本管理属性文件。以下示例显示了一个典型的 Maven 配置:

[source,xml,indent=0] .pom.xml

    <parent>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-parent</artifactId>
        <version>{spring-boot-docs-version}</version>
        <relativePath /> <!-- 从仓库查找父级 -->
    </parent>

	<dependencyManagement>
		<dependencies>
			<dependency>
				<groupId>org.springframework.cloud</groupId>
				<artifactId>spring-cloud-dependencies</artifactId>
				<version>{spring-cloud-version}</version>
				<type>pom</type>
				<scope>import</scope>
			</dependency>
		</dependencies>
	</dependencyManagement>

	<dependencies>
		<dependency>
			<groupId>org.springframework.cloud</groupId>
			<artifactId>spring-cloud-starter-config</artifactId>
		</dependency>
		<dependency>
			<groupId>org.springframework.boot</groupId>
			<artifactId>spring-boot-starter-test</artifactId>
			<scope>test</scope>
		</dependency>
	</dependencies>

	<build>
		<plugins>
            <plugin>
                <groupId>org.springframework.boot</groupId>
                <artifactId>spring-boot-maven-plugin</artifactId>
            </plugin>
		</plugins>
	</build>

    <!-- 快照和里程碑也需要仓库 -->

现在您可以创建一个标准的 Spring Boot 应用程序,例如以下 HTTP 服务器:

@SpringBootApplication
@RestController
public class Application {

    @RequestMapping("/")
    public String home() {
        return "Hello World!";
    }

    public static void main(String[] args) {
        SpringApplication.run(Application.class, args);
    }

}

当此 HTTP 服务器运行时,它会从默认的本地配置服务器(如果正在运行)的 8888 端口获取外部配置。要修改启动行为,您可以通过 bootstrap.properties(类似于 application.properties,但用于应用程序上下文的引导阶段)更改配置服务器的位置,如下所示:

spring.cloud.config.uri: http://myconfigserver.com

默认情况下,如果未设置应用程序名称,将使用 application。要修改名称,可以在 bootstrap.properties 文件中添加以下属性:

spring.application.name: myapp

注意:当设置属性 ${spring.application.name} 时,请不要在应用程序名称前加上保留字 application-,以防止解决正确的属性源时出现问题。

引导属性在 /env 端点中作为高优先级属性源出现,如下例所示:

$ curl localhost:8080/env
{
  "profiles":[],
  "configService:https://github.com/spring-cloud-samples/config-repo/bar.properties":{"foo":"bar"},
  "servletContextInitParams":{},
  "systemProperties":{...},
  ...
}

一个名为 configService:<远程仓库 URL>/<文件名> 的属性源包含值为 bar 的 foo 属性,并且具有最高优先级。

注意:属性源名称中的 URL 是 git 仓库,而不是配置服务器 URL。

=== 示例应用程序

您可以在此处找到示例应用程序:https://github.com/spring-cloud/spring-cloud-config/tree/master/spring-cloud-config-sample[链接]。它是一个 Spring Boot 应用程序,因此您可以使用常规机制(例如 mvn spring-boot:run)运行它。运行时,它会在 http://localhost:8888(一个可配置的默认值)上查找配置服务器,因此您也可以同时运行服务器以查看它们一起工作的情况。

示例中有一个测试用例,其中配置服务器也在同一个 JVM 中启动(使用不同的端口),并且测试断言来自 git 配置仓库的环境属性存在。要更改配置服务器的位置,您可以在 bootstrap.yml(或系统属性和其他位置)中设置 spring.cloud.config.uri。

测试用例有一个 main() 方法,它以相同的方式运行服务器(查看日志以了解其端口),因此您可以在一个进程中运行整个系统并进行试验(例如,您可以在 IDE 中运行 main() 方法)。main() 方法使用 target/config 作为 git 仓库的工作目录,因此您可以在那里进行本地更改,并看到这些更改反映在运行中的应用程序中。以下示例显示了调整测试用例的会话:

$ curl localhost:8080/env/sample
mytest
$ vi target/config/mytest.properties
.. 将 "sample" 的值改为新值,可以选择提交
$ curl localhost:8080/refresh
["sample"]
$ curl localhost:8080/env/sample
sampleValue

刷新端点报告 "sample" 属性已更改。

== 构建

:jdkversion: 1.7

=== 基本编译与测试

要构建源代码,您需要安装 JDK {jdkversion}。

Spring Cloud 使用 Maven 进行大多数构建相关活动,您应该能够通过克隆您感兴趣的项目并输入以下命令快速开始:

$ ./mvnw install

注意:您也可以自己安装 Maven (>=3.3.3) 并在以下示例中运行 mvn 命令代替 ./mvnw。如果这样做,您还可能需要添加 -P spring,如果您的本地 Maven 设置不包含 spring 预发布工件的仓库声明。

注意:请注意,您可能需要通过设置 MAVEN_OPTS 环境变量,值类似于 -Xmx512m -XX:MaxPermSize=128m,来增加 Maven 可用的内存量。我们尝试在 .mvn 配置中覆盖这一点,因此如果您发现必须这样做才能使构建成功,请提交票据以将设置添加到源代码控制。

关于如何构建项目的提示,请查看 .travis.yml(如果有)。应该有一个 "script" 命令,可能还有 "install" 命令。还要查看 "services" 部分,了解是否需要本地运行某些服务(例如 mongo 或 rabbit)。忽略您在 "before_install" 中可能找到的与 git 相关的内容,因为它们与设置 git 凭据有关,而您已经拥有这些凭据。

需要中间件的项目通常包含一个 docker-compose.yml,因此请考虑使用 https://docs.docker.com/compose/[Docker Compose] 在 Docker 容器中运行中间件服务器。请参阅 https://github.com/spring-cloud-samples/scripts[scripts 演示仓库] 中的 README,了解关于 mongo、rabbit 和 redis 常见情况的具体说明。

注意:如果其他方法都失败了,请使用 .travis.yml 中的命令构建(通常是 ./mvnw install)。

=== 文档

spring-cloud-build 模块有一个 "docs" 配置文件,如果启用它,它将尝试从 src/main/asciidoc 构建 asciidoc 源。作为该过程的一部分,它将查找 README.adoc 并通过加载所有包含项来处理它,但不会解析或渲染它,只是将其复制到 ${main.basedir}(默认为 ${basedir},即项目的根目录)。如果 README 有任何更改,那么在进行 Maven 构建后,它将以修改后的文件形式出现在正确的位置。只需提交并推送更改。

下载工具