CVE-2020-5410 | VMware Spring Cloud ConfigĿ¼±éÀúÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-06-020x00 Îó²î¸ÅÊö
CVE ID |
CVE-2020-5410 |
ʱ ¼ä |
2020-06-02 |
Àà ÐÍ |
DT |
µÈ ¼¶ |
¸ßΣ |
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
VMware Spring Cloud Config 2.2.0-2.2.2¡¢2.1.0-2.1.8ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾ |
0x01 Îó²îÏêÇé
¿ËÈÕVMware¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öVMware Spring Cloud ConfigÖеÄĿ¼±éÀúÎó²î£¨CVE-2020-5410£©¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚVMware Spring Cloud Config 2.2.0-2.2.2°æ±¾¡¢2.1.0-2.1.8°æ±¾ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾ÔÊÐíÓ¦ÓóÌÐòͨ¹ýspring-cloud-config-serverÄ£¿£¿£¿£¿£¿£¿éÌṩí§ÒâÉèÖÃÎļþ£¬£¬£¬£¬£¬Ê¹¹¥»÷Õß¿ÉÒÔʹÓÃÈ«ÐĽṹµÄURL¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
¹Ù·½ÒÑÐû²¼×îа汾ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬Óû§Ó¦¾¡¿ìÉý¼¶µ½VMware Spring Cloud Config 2.2.3»ò2.1.9°æ±¾£¬£¬£¬£¬£¬ÆäÖв»ÔÙÖ§³ÖµÄ¾É°æ±¾Ó¦¾¡¿ìÉý¼¶ÖÁ¿ÉÖ§³ÖµÄ²»ÊܸÃÎó²îÓ°ÏìµÄ°æ±¾¡£¡£¡£¡£ÏÂÔØµØµã£º
https://github.com/spring-cloud/spring-cloud-config/releases
ÔÝʱ²½·¥£º½«spring-cloud-config-server°²ÅÅÔÚÄÚÍøÖУ¬£¬£¬£¬£¬²¢ÇÒʹÓÃSpring Security¶ÔÆä¾ÙÐб£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬Ê¹µÃÖ»ÓÐÄÚ²¿ÍøÂç»á¼ûȨÏÞµÄÓû§ºÍ¾ßÓÐ׼ȷÉí·ÝÑéÖ¤µÄÓû§²Å»ª¾ÙÐлá¼û¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://spring.io/blog/2020/06/01/spring-cloud-greenwich-sr6-hoxton-sr5-and-2020-0-0-m2-aka-ilford-are-available
0x04 ²Î¿¼Á´½Ó
https://tanzu.vmware.com/security/cve-2020-5410
0x05 ʱ¼äÏß
2020-06-01 VMware¹Ù·½Ðû²¼Í¨¸æ
2020-06-02 VSRCÐû²¼Îó²îͨ¸æ