¡¾Îó²îͨ¸æ¡¿Spring Framework·´ÉäÐÍÎļþÏÂÔØÎó²î (CVE-2020-5421)
2020-09-21
×ÛÊö
¿ËÈÕ£¬VMware TanzuÐû²¼Ç徲ͨ¸æ£¬Ðû²¼ÁËÒ»¸ö±£´æÓÚSpring FrameworkÖеķ´ÉäÐÍÎļþÏÂÔØ£¨Reflected File Download,RFD£©Îó²îCVE-2020-5421¡£CVE-2020-5421 ¿Éͨ¹ýjsessionid·¾¶²ÎÊý£¬Èƹý·ÀÓùRFD¹¥»÷µÄ±£»¤¡£ÏÈǰÕë¶ÔRFDµÄ·À»¤ÊÇΪӦ¶Ô CVE-2015-5211 Ìí¼ÓµÄ¡£
¹¥»÷Õßͨ¹ýÏòÓû§·¢ËÍ´øÓÐÅú´¦Öóͷ£¾ç±¾À©Õ¹ÃûµÄURL£¬Ê¹Óû§ÏÂÔØ²¢Ö´ÐÐÎļþ£¬´Ó¶øÎ£º¦Óû§ÏµÍ³¡£
¹Ù·½ÒÑÐû²¼ÐÞ¸´ÁËÎó²îµÄа汾¡£
Spring FrameworkÊÇ Java ƽ̨µÄÒ»¸ö¿ªÔ´È«Õ»Ó¦ÓóÌÐò¿ò¼ÜºÍ¿ØÖÆ·´×ªÈÝÆ÷ʵÏÖ£¬Ò»Ñùƽ³£±»Ö±½Ó³ÆÎª Spring¡£
²Î¿¼Á´½Ó£º
https://tanzu.vmware.com/security/cve-2020-5421
ÊÜÓ°Ïì²úÆ·°æ±¾
Spring Framework 5.2.0 - 5.2.8
Spring Framework 5.1.0 - 5.1.17
Spring Framework 5.0.0 - 5.0.18
Spring Framework 4.3.0 - 4.3.28
ÒÔ¼°ÆäËûÒѲ»ÊÜÖ§³ÖµÄ°æ±¾
²»ÊÜÓ°Ïì²úÆ·°æ±¾
Spring Framework 5.2.9
Spring Framework 5.1.18
Spring Framework 5.0.19
Spring Framework 4.3.29
½â¾ö¼Æ»®
¹Ù·½ÒÑÐû²¼ÐÞ¸´ÁËÎó²îµÄа汾£¬½¨ÒéÏà¹ØÓû§¾¡¿ìÉý¼¶¾ÙÐзÀ»¤¡£
ÏÂÔØÁ´½Ó£º
https://github.com/spring-projects/spring-framework/releases
ÁíÍ⣬Õë¶Ô RFD ¹¥»÷£¬¹Ù·½ÔøÔÚ CVE-2015-5211 µÄͨ¸æÖиø³öÈçϽ¨Òé(https://tanzu.vmware.com/security/cve-2015-5211)£º
1¡¢ ±àÂë¶ø²»ÊÇתÒåJSONÏìÓ¦¡£Ïêϸ²Ù×÷Ïê¼û https://github.com/rwinch/spring-jackson-owasp¡£
2¡¢ ½«ºó׺ģʽƥÅäÉèÖÃΪ¹Ø±Õ»ò½öÏÞÓÚÏÔʽע²áµÄºó׺¡£
3¡¢ ÉèÖÃÄÚÈÝÐÉÌʱ£¬½« "useJaf "ºÍ "ignoreUknownPathExtension "ÊôÐÔÉèÖÃΪfalse£¬Õ⽫µ¼ÖÂδ֪À©Õ¹ÃûµÄURL»ñµÃ406ÏìÓ¦¡£µ«Çë×¢ÖØ£¬ÈôÊÇURLÔÀ´»áÔÚ×îºó´¦ÓÐÒ»¸öµã£¬¾Í²»ÒªÊ¹ÓøÃÏî¡£
4¡¢ ÔÚÏìÓ¦ÖÐÌí¼Ó "X-Content-Type-Options: nosniff "Í·¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







