เวิร์กโฟลว์ SharePoint หยุดทํางานหลังจากที่คุณติดตั้งการอัปเดตความปลอดภัย .NET สําหรับ CVE-2018-8421

นำไปใช้กับ
SharePoint Server

อาการ

หลังจากที่คุณติดตั้งการอัปเดตความปลอดภัย.NET Framework เดือนกันยายน 2018 เพื่อแก้ไข CVE-2018-8421 (.NET Framework ช่องโหว่การดําเนินการโค้ดจากระยะไกล) เวิร์กโฟลว์ทันทีของ SharePoint จะหยุดทํางาน เมื่อปัญหานี้เกิดขึ้น จะมีรายการข้อผิดพลาดที่คล้ายกับข้อมูลต่อไปนี้ถูกบันทึกไว้:

<Date> <Time> w3wp.exe (0x1868) 0x22FC SharePoint Foundation Workflow Infrastructure 72fs Unexpected RunWorkflow: Microsoft.SharePoint.SPException: <Error><CompilerError Line="-1" Column="-1" Text="Type System.CodeDom.CodeBinaryOperatorExpression is not marked as authorized in the application configuration file." /><CompilerError Line="-1" Column="-1" Text="Type System.CodeDom.CodeBinaryOperatorExpression is not marked as authorized in the application configuration file." /><CompilerError Line="-1" Column="-1" Text="Type System.CodeDom.CodeBinaryOperatorExpression is not marked as authorized in the application configuration file." /><CompilerError Line="-1" Column="-1" Text="Type System.CodeDom.CodeBinaryOperatorExpression is not marked as authorized in the application configuration file." /><CompilerError Line="-1" Column="-1" Text="Type System.CodeDom.CodeBinaryOperatorExpression is not marked as authorized in the application configuration file." /><CompilerError Line="-1" Column="-1" Text="Type System.CodeDom.CodeBinaryOperatorExpression is not marked as authorized in the application configuration file." /><CompilerError Line="-1" Column="-1" Text="Type System.CodeDom.CodeBinaryOperatorExpression is not marked as authorized in the application configuration file." /><CompilerError Line="-1" Column="-1"…

รายการข้อผิดพลาดแนะนําว่า System.CodeDom.CodeBinaryOperatorExpression ไม่รวมอยู่ในชนิดที่ได้รับอนุญาต

สําหรับข้อมูลเพิ่มเติมเกี่ยวกับการอัปเดตความปลอดภัยสําหรับ .NET เดือนกันยายน ให้ไปที่หน้า Microsoft .NET Blog นี้

สาเหตุ

Workflow Foundation (WF) จะเรียกใช้เวิร์กโฟลว์เฉพาะเมื่อชนิดที่อ้างถึงและแอสเซมบลีทั้งหมดได้รับอนุญาตในไฟล์การกําหนดค่า .NET (หรือเพิ่มอย่างชัดเจนผ่านโค้ด) ในทรีต่อไปนี้:

<configuration>

<System.Workflow.ComponentModel.WorkflowCompiler>

<authorizedTypes>

<targetFx>

อย่างไรก็ตาม หลังจากการอัปเดต เวิร์กโฟลว์พร้อมใช้งานทันทีบางชนิดที่ใช้โดย SharePoint ที่ไม่ต้องการก่อนหน้านี้เป็นสิ่งจําเป็น

การแก้ปัญหา

เมื่อต้องการแก้ไขปัญหานี้ ให้ใช้โปรแกรมปรับปรุงความปลอดภัยและที่ไม่เกี่ยวกับความปลอดภัยที่เหมาะสมจากบทความใน Knowledge Base ต่อไปนี้

4461501 คําอธิบายของการอัปเดตความปลอดภัยสําหรับ SharePoint Enterprise Server 2016: 13 พฤศจิกายน 2018

4461508 13 พฤศจิกายน 2018 การอัปเดตสะสมสําหรับ SharePoint Foundation 2013 (KB4461508)

4461510 13 พฤศจิกายน 2018 การอัปเดตสะสมสําหรับ SharePoint Enterprise Server 2013 (KB4461510)
 
4011713 13 พฤศจิกายน 2018 อัปเดตสําหรับ SharePoint Foundation 2010 (KB4011713)

4461528 13 พฤศจิกายน 2018 การอัปเดตสะสมสําหรับ SharePoint Server 2010 (KB4461528)

หมายเหตุ

  • หลังจากติดตั้งการอัปเดต ตัวช่วยสร้างการกําหนดค่าผลิตภัณฑ์ SharePoint จะต้องทํางานเพื่อให้การแก้ไขถูกนําไปใช้อย่างสมบูรณ์
  • การกระทําของเวิร์กโฟลว์ของบริษัทอื่นหรือเวิร์กโฟลว์แบบกําหนดเองบางอย่างอาจมีการอ้างอิงเพิ่มเติม ถ้าคุณพบลักษณะการทํางานที่คล้ายกับปัญหานี้ แต่ไม่ได้กล่าวถึงในบทความนี้ โปรดปรึกษานักพัฒนาการดําเนินการเวิร์กโฟลว์เพื่อขอความช่วยเหลือ

วิธีแก้ไขปัญหาชั่วคราว

เมื่อต้องการแก้ไขปัญหานี้ ให้เพิ่มชนิดที่จําเป็นลงในไฟล์ Web.config ของแอปพลิเคชันทั้งหมดอย่างชัดเจน แม้ว่าจะมีขั้นตอนด้วยตนเอง เราขอแนะนําให้คุณใช้วิธีการสคริปต์

เพิ่มชนิดด้วยตนเอง

เมื่อต้องการแก้ไขปัญหานี้ ให้เพิ่มชนิดที่จําเป็นลงในไฟล์ web.config ของแอปพลิเคชันทั้งหมดอย่างชัดเจน

สําหรับ SharePoint 2013 และเวอร์ชันที่ใหม่กว่า

สําหรับ SharePoint 2013 และเวอร์ชันที่ใหม่กว่า ให้เพิ่มบรรทัดต่อไปนี้:

<authorizedType Assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeBinaryOperatorExpression" Authorized="True" />

<authorizedType Assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodePrimitiveExpression" Authorized="True" />

<authorizedType Assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeMethodInvokeExpression" Authorized="True" />

<authorizedType Assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeMethodReferenceExpression" Authorized="True" />

<authorizedType Assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeFieldReferenceExpression" Authorized="True" />

<authorizedType Assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeThisReferenceExpression" Authorized="True" />

<authorizedType Assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodePropertyReferenceExpression" Authorized="True" />
 

สําหรับ SharePoint เวอร์ชันก่อนหน้า SharePoint 2013

สําหรับ SharePoint เวอร์ชันก่อนหน้า 2013 ให้เพิ่มบรรทัดต่อไปนี้แทน:

<authorizedType Assembly="System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeBinaryOperatorExpression" Authorized="True" />

<authorizedType Assembly="System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodePrimitiveExpression" Authorized="True" />

<authorizedType Assembly="System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeMethodInvokeExpression" Authorized="True" />

<authorizedType Assembly="System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeMethodReferenceExpression" Authorized="True" />

<authorizedType Assembly="System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeFieldReferenceExpression" Authorized="True" />

<authorizedType Assembly="System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodeThisReferenceExpression" Authorized="True" />

<authorizedType Assembly="System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" NameSpace="System.CodeDom" TypeName="CodePropertyReferenceExpression" Authorized="True" />

เพิ่มชนิดผ่านสคริปต์

เราขอแนะนําให้คุณเรียกใช้สคริปต์ต่อไปนี้แทนการปรับเปลี่ยนไฟล์ที่มีอยู่โดยตรง

หมาย เหตุ กลไกเวิร์กโฟลว์ของบริษัทอื่นบางโปรแกรมอาจจําเป็นต้องเพิ่มชนิดเพิ่มเติม ถ้าเป็นกรณีนี้ ให้ติดต่อผู้จําหน่ายของคุณสําหรับข้อมูลเกี่ยวกับชนิดที่จําเป็น แล้วปรับสคริปต์ให้สอดคล้องกัน

สคริปต์ต่อไปนี้เปลี่ยนแปลง Web.config สําหรับแอปพลิเคชันบนเว็บทั้งหมดเพื่อเพิ่มรายการที่จําเป็น สคริปต์นี้จะเพิ่มชนิดเหล่านี้สําหรับแอปพลิเคชันบนเว็บที่มีอยู่และสําหรับแอปพลิเคชันที่สร้างขึ้นหลังจากเรียกใช้สคริปต์ สคริปต์ควรถูกเรียกใช้เพียงครั้งเดียวบนเซิร์ฟเวอร์ Front-End ของเว็บในฟาร์ม (ซึ่งจะปรับปรุงเซิร์ฟเวอร์ทั้งหมด)

<#

 This script adds the entries to all web.config files for all web applications in the farm.

 Run this script as Farm Administrator in one of the WFEs.

 This script has to run only one time.

SUMMARY:

This script uses the native SharePoint SPWebConfigModification API to deploy new updates to the web.config file for each web application on each server in the farm.  Servers that are added at a later date will also get the updates applied because the API configuration is persisted in the config database.  This API does not update the web.config for the central administration web application.

If you are running workflows on the central admin web application, you will have to manually update the web.config by using the steps in the referenced blog.

==============================================================

#>

Add-PSSnapin Microsoft.SharePoint.PowerShell -ErrorAction SilentlyContinue | Out-Null

function Add-CodeDomAuthorizedType

{

    <#

    .Synopsis

       Adds the necessary authorizedType elements to all web.config files for all non-central admin web applications

    .DESCRIPTION

       Adds the necessary authorizedType elements to all web.config files for all non-central admin web applications

    .EXAMPLE

       Add-CodeDomAuthorizedType

    #>

    [CmdletBinding()]

    param

    (

    )

    begin

    {

        $farmMajorVersion = (Get-SPFarm -Verbose:$false ).BuildVersion.Major

        $contentService = [Microsoft.SharePoint.Administration.SPWebService]::ContentService

        $typeNames = @( "CodeBinaryOperatorExpression", "CodePrimitiveExpression", "CodeMethodInvokeExpression", "CodeMethodReferenceExpression", "CodeFieldReferenceExpression","CodeThisReferenceExpression", "CodePropertyReferenceExpression")

    }

    process

    {

        if( @($contentService.WebConfigModifications | ? { $_.Name -eq "NetFrameworkAuthorizedTypeUpdate" }).Count -gt 0 )

        {

            Write-Warning "Existing NetFrameworkAuthorizedTypeUpdate entries found, this script has to be run only one time per farm."

            return

        }

        if( $farmMajorVersion -le 14 ) # 2010, 2007

        {

            foreach( $typeName in $typeNames )

            {

                # System, Version=2.0.0.0

                $netFrameworkConfig = New-Object Microsoft.SharePoint.Administration.SPWebConfigModification

                $netFrameworkConfig.Path     = "configuration/System.Workflow.ComponentModel.WorkflowCompiler/authorizedTypes"

                $netFrameworkConfig.Name     = "authorizedType[@Assembly='System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089'][@Namespace='System.CodeDom'][@TypeName='{0}'][@Authorized='True']" -f $typeName

                $netFrameworkConfig.Owner    = "NetFrameworkAuthorizedTypeUpdate"

                $netFrameworkConfig.Sequence = 0

                $netFrameworkConfig.Type     = [Microsoft.SharePoint.Administration.SPWebConfigModification+SPWebConfigModificationType]::EnsureChildNode

                $netFrameworkConfig.Value    = '<authorizedType Assembly="System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" Namespace="System.CodeDom" TypeName="{0}" Authorized="True"/>' -f $typeName

                $contentService.WebConfigModifications.Add($netFrameworkConfig);

            }

        }

        else # 2013+

        {

            foreach( $typeName in $typeNames )

            {

                # System, Version=4.0.0.0

                $netFrameworkConfig = New-Object Microsoft.SharePoint.Administration.SPWebConfigModification

                $netFrameworkConfig.Path     = "configuration/System.Workflow.ComponentModel.WorkflowCompiler/authorizedTypes/targetFx"

                $netFrameworkConfig.Name     = "authorizedType[@Assembly='System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089'][@Namespace='System.CodeDom'][@TypeName='{0}'][@Authorized='True']" -f $typeName

                $netFrameworkConfig.Owner    = "NetFrameworkAuthorizedTypeUpdate"

                $netFrameworkConfig.Sequence = 0

                $netFrameworkConfig.Type     = [Microsoft.SharePoint.Administration.SPWebConfigModification+SPWebConfigModificationType]::EnsureChildNode

                $netFrameworkConfig.Value    = '<authorizedType Assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" Namespace="System.CodeDom" TypeName="{0}" Authorized="True"/>' -f $typeName

                $contentService.WebConfigModifications.Add($netFrameworkConfig);

            }

        }

        Write-Verbose "Updating web.configs"

        $contentService.Update()

        $contentService.ApplyWebConfigModifications();

    }

    end

    {

    }   

}

function Remove-CodeDomAuthorizedType

{

    <#

    .Synopsis

       Removes any web configuration entries owned by "NetFrameworkAuthorizedTypeUpdate"

    .DESCRIPTION

       Removes any web configuration entries owned by "NetFrameworkAuthorizedTypeUpdate"

    .EXAMPLE

        Remove-CodeDomAuthorizedType

    #>

    [CmdletBinding()]

    param()

    begin

    {

        $contentService = [Microsoft.SharePoint.Administration.SPWebService]::ContentService

    }

    process

    {

        $webConfigModifications = @($contentService.WebConfigModifications | ? { $_.Owner -eq "NetFrameworkAuthorizedTypeUpdate" })

        foreach ( $webConfigModification in $webConfigModifications )

        {

            Write-Verbose "Found instance owned by NetFrameworkAuthorizedTypeUpdate"

            $contentService.WebConfigModifications.Remove( $webConfigModification ) | Out-Null

        }

        if( $webConfigModifications.Count -gt 0 )

        {

            $contentService.Update()

            $contentService.ApplyWebConfigModifications()

        }

    }

    end

    {

    }   

}

# The following command will get the timerjob responsible for the web.config change deployment

# Get-SPTimerJob | ? { $_.Name -eq "job-webconfig-modification" }

# The following command will make the appropriate changes

Add-CodeDomAuthorizedType

# Remove the following command if you have to remove the web.config updates, you can use this function to retract the changes

# Remove-CodeDomAuthorizedType