CVE-2020-5421 | Spring Framework·´ÉäÐÍÎļþÏÂÔØÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-09-22

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2020-5421

ʱ    ¼ä

2020-09-22

Àà    ÐÍ

RFD

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Spring Framework

5.2.0 - 5.2.8

5.1.0 - 5.1.17

5.0.0 - 5.0.18

4.3.0 - 4.3.28

ÒÔ¼°¸üÔçÆÚµÄ°æ±¾

 

Spring FrameworkÊÇÒ»¸öJava/Java EE/.NETµÄ·Ö²ãÓ¦ÓóÌÐò¿ò¼Ü¡£¡£¡£¡£¡£¡£¸Ã¿ò¼Ü»ùÓÚExpert One-on-One Java EE Design and Development£¨ISBN 0-7645-4385-7£©Ò»ÎÄÖеĴúÂ룬£¬ £¬£¬£¬²¢×î³õÓÉRod Johnson¿ª·¢¡£¡£¡£¡£¡£¡£Spring FrameworkÌṩÁËÒ»¸ödzÒ׵Ŀª·¢·½·¨£¬£¬ £¬£¬£¬ÕâÖÖ¿ª·¢·½·¨½«×èÖ¹ÄÇЩ¿ÉÄÜÖÂʹµ×²ã´úÂë±äµÃ·±ÔÓÔÓÂҵĴó×ÚÊôÐÔÎļþºÍ×ÊÖúÀà¡£¡£¡£¡£¡£¡£

0x01 Îó²îÏêÇé

image.png 

 

2020Äê09ÔÂ17ÈÕ£¬£¬ £¬£¬£¬VMwareÐû²¼Ç徲ͨ¸æ£¬£¬ £¬£¬£¬Spring Framework°æ±¾5.2.0-5.2.8¡¢5.1.0-5.1.17¡¢5.0.0-5.0.18¡¢4.3.0-4.3.28¼°¸üÔçÆÚµÄ°æ±¾Öб£´æÒ»¸ö·´ÉäÐÍÎļþÏÂÔØÎó²î£¬£¬ £¬£¬£¬Îó²î¸ú×ÙΪCVE-2020-5421¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿Éͨ¹ýʹÓÃjsessionid·¾¶²ÎÊýÈÆ¹ýRFDÇå¾²·À»¤Õ½ÂÔ¡£¡£¡£¡£¡£¡£

±ðµÄ£¬£¬ £¬£¬£¬Õë¶ÔRFD¹¥»÷£¬£¬ £¬£¬£¬»¹¿ÉÒÔ½ÓÄÉһЩÆäËûµÄÒªÁ죺

    • ±àÂë¶ø²»ÊÇתÒåJSONÏìÓ¦¡£¡£¡£¡£¡£¡£ÕâÊÇOWASP XSSµÄ½¨Òé¡£¡£¡£¡£¡£¡£ÓйØÔõÑùʹÓÃSpring¾ÙÐвÙ×÷µÄʾÀý£¬£¬ £¬£¬£¬Çë°Ý¼ûhttps://github.com/rwinch/spring-jackson-owasp¡£¡£¡£¡£¡£¡£

    • ½«ºó׺ģʽƥÅäÉèÖÃΪ¹Ø±Õ»ò½öÏÞÓÚÏÔʽע²áµÄºó׺¡£¡£¡£¡£¡£¡£

    • ʹÓÃÄÚÈÝÊôÐÔ¡°useJaf¡±ºÍ¡°ignoreUknownPathExtension¡°ÉèÖÃΪfalseÀ´ÉèÖÃÄÚÈÝЭÉÌ£¬£¬ £¬£¬£¬Õ⽫µ¼ÖÂÀ©Õ¹Ãûδ֪µÄURL±¬·¢406ÏìÓ¦¡£¡£¡£¡£¡£¡£¿ÉÊÇÈôÊÇ×ÔȻϣÍûURLµÄĩβÓÐÒ»¸öµã£¬£¬ £¬£¬£¬½«²»¿É½ÓÄÉ´ËÖÖÒªÁì¡£¡£¡£¡£¡£¡£

    • ÔÚÏìÓ¦ÖÐÌí¼Ó¡° X-Content-Type-Options£ºnosniff¡±±êÍ·¡£¡£¡£¡£¡£¡£Spring Security 4ĬÈÏÇéÐνÓÄÉ´ËÖÖ·½·¨¡£¡£¡£¡£¡£¡£

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚVMware¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬½¨Ò齫Spring FrameworkÉý¼¶µ½Ðµİ汾£º

5.2.9

5.1.18

5.0.19

4.3.29

ÏÂÔØÁ´½Ó£º

https://github.com/spring-projects/spring-framework/releases

0x03 Ïà¹ØÐÂÎÅ

https://spring.io/blog/2015/10/15/spring-framework-4-2-2-4-1-8-and-3-2-15-available-now

0x04 ²Î¿¼Á´½Ó

https://tanzu.vmware.com/security/cve-2020-5421

https://tanzu.vmware.com/security/cve-2015-5211

https://www.security-database.com/detail.php?alert=CVE-2015-5211

0x05 ʱ¼äÏß

2020-09-17  VMwareÐû²¼Ç徲ͨ¸æ

2020-09-22  VSRCÐû²¼Ç徲ͨ¸æ

 

image.png