CVE-2020-5410 | VMware Spring Cloud ConfigĿ¼±éÀúÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-06-02

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-5410

ʱ    ¼ä

2020-06-02

Àà    ÐÍ

DT

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

VMware Spring Cloud Config

2.2.0-2.2.2¡¢2.1.0-2.1.8ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾


0x01 Îó²îÏêÇé


VMware Spring Cloud ConfigÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄÒ»Ì×ÂþÑÜʽϵͳµÄÉèÖÃÖÎÃ÷È·¾ö¼Æ»®¡£¡£¡£¡£¸Ã²úÆ·Ö÷ҪΪÂþÑÜʽϵͳÖеÄÍⲿÉèÖÃÌṩЧÀÍÆ÷ºÍ¿Í»§¶ËÖ§³Ö¡£¡£¡£¡£
¿ËÈÕVMware¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬ £¬ÐÞ¸´ÁËÒ»¸öVMware Spring Cloud ConfigÖеÄĿ¼±éÀúÎó²î£¨CVE-2020-5410£©¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚVMware Spring Cloud Config 2.2.0-2.2.2°æ±¾¡¢2.1.0-2.1.8°æ±¾ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾ÔÊÐíÓ¦ÓóÌÐòͨ¹ýspring-cloud-config-serverÄ £¿£¿£¿£¿£¿£¿éÌṩí§ÒâÉèÖÃÎļþ£¬£¬£¬£¬ £¬Ê¹¹¥»÷Õß¿ÉÒÔʹÓÃÈ«ÐĽṹµÄURL¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


¹Ù·½ÒÑÐû²¼×îа汾ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬ £¬Óû§Ó¦¾¡¿ìÉý¼¶µ½VMware Spring Cloud Config 2.2.3»ò2.1.9°æ±¾£¬£¬£¬£¬ £¬ÆäÖв»ÔÙÖ§³ÖµÄ¾É°æ±¾Ó¦¾¡¿ìÉý¼¶ÖÁ¿ÉÖ§³ÖµÄ²»ÊܸÃÎó²îÓ°ÏìµÄ°æ±¾¡£¡£¡£¡£ÏÂÔØµØµã£º
https://github.com/spring-cloud/spring-cloud-config/releases
ÔÝʱ²½·¥£º½«spring-cloud-config-server°²ÅÅÔÚÄÚÍøÖУ¬£¬£¬£¬ £¬²¢ÇÒʹÓÃSpring Security¶ÔÆä¾ÙÐб£»£»£»£»£»£»£»¤£¬£¬£¬£¬ £¬Ê¹µÃÖ»ÓÐÄÚ²¿ÍøÂç»á¼ûȨÏÞµÄÓû§ºÍ¾ßÓÐ׼ȷÉí·ÝÑéÖ¤µÄÓû§²Å»ª¾ÙÐлá¼û¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ

https://spring.io/blog/2020/06/01/spring-cloud-greenwich-sr6-hoxton-sr5-and-2020-0-0-m2-aka-ilford-are-available


0x04 ²Î¿¼Á´½Ó


https://tanzu.vmware.com/security/cve-2020-5410


0x05 ʱ¼äÏß


2020-06-01 VMware¹Ù·½Ðû²¼Í¨¸æ
2020-06-02 VSRCÐû²¼Îó²îͨ¸æ