CVE-2020-5410 | VMware Spring Cloud ConfigĿ¼±éÀú·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-02

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-5410

ʱ    ¼ä

2020-06-02

Àà    ÐÍ

DT

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

VMware Spring Cloud Config

2.2.0-2.2.2¡¢2.1.0-2.1.8ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾


0x01 ·ì϶ÏêÇé


VMware Spring Cloud ConfigÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄÒ»Ì×É¢²¼Ê½ÏµÍ³µÄÅäÖÃÖÎÀí½â¾ö¹æ»®¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã²úÆ·ÖØÒªÎªÉ¢²¼Ê½ÏµÍ³ÖÐµÄ±í²¿ÅäÖÃÌṩ·þÎñÆ÷ºÍ¿Í»§¶ËÖ§³Ö¡£¡£¡£¡£ ¡£¡£¡£¡£
½üÈÕVMware¹Ù·½°ä²¼¹«¸æ £¬ £¬£¬£¬£¬£¬£¬½¨¸´ÁËÒ»¸öVMware Spring Cloud ConfigÖеÄĿ¼±éÀú·ì϶£¨CVE-2020-5410£©¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã·ì϶ԴÓÚVMware Spring Cloud Config 2.2.0-2.2.2°æ±¾¡¢2.1.0-2.1.8°æ±¾ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾ÔÊÐíÀûÓ÷¨Ê½Í¨¹ýspring-cloud-config-serverÄ£¿£¿£¿£¿£¿éÌṩËÁÒâÅäÖÃÎļþ £¬ £¬£¬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»ÀûÓþ«ÐÄ»ú¹ØµÄURL½øÐÐËÁÒâÎļþ¶ÁÈ¡¡£¡£¡£¡£ ¡£¡£¡£¡£


0x02 ´ëÖý¨Òé


¹Ù·½ÒѰ䲼×îа汾½¨¸´ÁË´Ë·ì϶ £¬ £¬£¬£¬£¬£¬£¬Óû§Ó¦¾¡¿ìÉý¼¶µ½VMware Spring Cloud Config 2.2.3»ò2.1.9°æ±¾ £¬ £¬£¬£¬£¬£¬£¬ÆäÖв»ÔÙÖ§³ÖµÄ¾É°æ±¾Ó¦¾¡¿ìÉý¼¶ÖÁ¿ÉÖ§³ÖµÄ²»Êܸ÷ì϶ӰÏìµÄ°æ±¾¡£¡£¡£¡£ ¡£¡£¡£¡£ÏÂÔØµØÖ·£º
https://github.com/spring-cloud/spring-cloud-config/releases
һʱ´ëÊ©£º½«spring-cloud-config-server¸éÖÃÔÚÄÚÍøÖÐ £¬ £¬£¬£¬£¬£¬£¬²¢ÇÒʹÓÃSpring Security¶ÔÆä½øÐб£»£»£»£»£»£»£»£»¤ £¬ £¬£¬£¬£¬£¬£¬Ê¹µÃÖ»ÓÐÄÚ²¿ÍøÂç½Ó¼ûȨÏÞµÄÓû§ºÍÓµÓÐÕýÈ·Éí·ÝÑéÖ¤µÄÓû§ÄÜÁ¦½øÐнӼû¡£¡£¡£¡£ ¡£¡£¡£¡£


0x03 ÓйØÐÂÎÅ

https://spring.io/blog/2020/06/01/spring-cloud-greenwich-sr6-hoxton-sr5-and-2020-0-0-m2-aka-ilford-are-available


0x04 ²Î¿¼Á´½Ó


https://tanzu.vmware.com/security/cve-2020-5410


0x05 ¹¦·òÏß


2020-06-01 VMware¹Ù·½°ä²¼¹«¸æ
2020-06-02 VSRC°ä²¼·ì϶¹«¸æ