CVE-2020-13953 | Apache Tapestry WEB-INFÎļþÏÂÔØÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-09-27

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-13953

ʱ   ¼ä

2020-09-27

Àà   ÐÍ


µÈ   ¼¶

ÖÐΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Tapestry 5.4.0-5.5.0


Apache TapestryÊÇÒ»¸öʹÓÃJavaÓïÑÔ±àдµÄ¿ªÔ´¿ò¼Ü£¬£¬£¬£¬£¬ÓÃÓÚ½¨É趯̬µÄ¡¢½áʵµÄ¡¢¸ßÎÞаÐÔµÄwebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£Tapestry¿ò¼ÜÐÞ½¨ÔÚ±ê×¼µÄJava Servlet APIÖ®ÉÏ£¬£¬£¬£¬£¬Òò´ËËüÄܹ»ºÜºÃµØ¼æÈÝÈκÎservletÈÝÆ÷»òÕßÓ¦ÓÃЧÀÍ¡£¡£¡£¡£¡£Tapestry¾ßÓÐÐí¶àÇå¾²¹¦Ð§£¬£¬£¬£¬£¬Ö¼ÔÚÔöǿӦÓóÌÐòÃâÊܲ»ÐëÒªµÄÈëÇֺ;ܾøÐ§À͵ÄË𺦡£¡£¡£¡£¡£

0x01 Îó²îÏêÇé

ͼƬ.png

 

2020Äê09ÔÂ26ÈÕ£¬£¬£¬£¬£¬Apache TapestryÖб»Ì»Â¶³ö±£´æÒ»¸öÎļþÏÂÔØÎó²î¡£¡£¡£¡£¡£Îó²î×·×ÙΪCVE-2020-13953£¬£¬£¬£¬£¬ÆäÎó²îÆ·¼¶ÎªÖÐΣ¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý¶ñÒâµÄURLÏÂÔØWEB-INFÖеÄÎļþ¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé

½«Apache TapestryÉý¼¶µ½ 5.6.0»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://tapestry.apache.org/download.html

0x03 ²Î¿¼Á´½Ó

https://www.mail-archive.com/users@tapestry.apache.org/msg77276.html

https://seclists.org/oss-sec/2020/q3/197

https://tapestry.apache.org/security.html

0x04 ʱ¼äÏß

2020-09-26  ApacheÐû²¼Ç徲ͨ¸æ

2020-09-27  VSRCÐû²¼Ç徲ͨ¸æ

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



ͼƬ.png