CVE-2020-5421 | Spring Framework·´ÉäÐÍÎļþÏÂÔØ·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-09-22

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2020-5421

ʱ    ¼ä

2020-09-22

Àà    ÐÍ

RFD

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Spring Framework

5.2.0 - 5.2.8

5.1.0 - 5.1.17

5.0.0 - 5.0.18

4.3.0 - 4.3.28

ÒÔ¼°¸üÔçÆÚµÄ°æ±¾

 

Spring FrameworkÊÇÒ»¸öJava/Java EE/.NETµÄ·Ö²ãÀûÓ÷¨Ê½¿ò¼Ü¡£¡£¡£¡£ ¡£¡£¸Ã¿ò¼Ü»ùÓÚExpert One-on-One Java EE Design and Development£¨ISBN 0-7645-4385-7£©Ò»ÎÄÖеĴúÂë £¬ £¬£¬£¬£¬£¬£¬²¢×î³õÓÉRod Johnson¿ª·¢¡£¡£¡£¡£ ¡£¡£Spring FrameworkÌṩÁËÒ»¸ö¼òÒ׵Ŀª·¢·½Ê½ £¬ £¬£¬£¬£¬£¬£¬ÕâÖÖ¿ª·¢·½Ê½½«Ô¤·ÀÄÇЩ¿ÉÄÜÒÔÖÁµ×²ã´úÂë±äµÃ·±Îß»ìÂҵĴóÁ¿ÊôÐÔÎļþºÍÔ®ÊÖÀà¡£¡£¡£¡£ ¡£¡£

0x01 ·ì϶ÏêÇé

image.png 

 

2020Äê09ÔÂ17ÈÕ £¬ £¬£¬£¬£¬£¬£¬VMware°ä²¼°²È«²¼¸æ £¬ £¬£¬£¬£¬£¬£¬Spring Framework°æ±¾5.2.0-5.2.8¡¢5.1.0-5.1.17¡¢5.0.0-5.0.18¡¢4.3.0-4.3.28¼°¸üÔçÆÚµÄ°æ±¾ÖдæÔÚÒ»¸ö·´ÉäÐÍÎļþÏÂÔØ·ì϶ £¬ £¬£¬£¬£¬£¬£¬·ì϶¸ú×ÙΪCVE-2020-5421¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶¿Éͨ¹ýʹÓÃjsessionidõè¾¶²ÎÊýÈÆ¹ýRFD°²È«·À»¤Õ½Êõ¡£¡£¡£¡£ ¡£¡£

´Ë±í £¬ £¬£¬£¬£¬£¬£¬Õë¶ÔRFD¹¥»÷ £¬ £¬£¬£¬£¬£¬£¬»¹Äܹ»²ÉȡһЩÆäËûµÄ²½Ö裺

    • ±àÂë¶ø²»ÊÇתÒåJSONÏìÓ¦¡£¡£¡£¡£ ¡£¡£ÕâÊÇOWASP XSSµÄ½¨Òé¡£¡£¡£¡£ ¡£¡£ÓйØÈôºÎʹÓÃSpring½øÐвÙ×÷µÄʾÀý £¬ £¬£¬£¬£¬£¬£¬Çë°Ý¼ûhttps://github.com/rwinch/spring-jackson-owasp¡£¡£¡£¡£ ¡£¡£

    • ½«ºó׺ģʽƥÅäÅäÖÃΪ¹Ø¹Ø»ò½öÏÞÓÚÏÔʽע²áµÄºó׺¡£¡£¡£¡£ ¡£¡£

    • ʹÓÃÄÚÈÝÊôÐÔ¡°useJaf¡±ºÍ¡°ignoreUknownPathExtension¡°ÉèÖÃΪfalseÀ´ÅäÖÃÄÚÈÝЭÉÌ £¬ £¬£¬£¬£¬£¬£¬Õ⽫µ¼ÖÂÀ©´óÃûδ֪µÄURL²úÉú406ÏìÓ¦¡£¡£¡£¡£ ¡£¡£µ«ÊÇÈôÊÇÌìÈ»µ«Ô¸URLµÄĩβÓÐÒ»¸öµã £¬ £¬£¬£¬£¬£¬£¬½«²»ÄÜѡȡ´ËÖÖ²½Öè¡£¡£¡£¡£ ¡£¡£

    • ÔÚÏìÓ¦ÖÐÔö³¤¡° X-Content-Type-Options£ºnosniff¡±±êÍ·¡£¡£¡£¡£ ¡£¡£Spring Security 4ĬÈÏÇé¿ö²ÉÈ¡´ËÖÖ·½Ê½¡£¡£¡£¡£ ¡£¡£

0x02 ´ëÖý¨Òé

ĿǰVMware¹Ù·½ÒѰ䲼°²È«¸üР£¬ £¬£¬£¬£¬£¬£¬½¨Ò齫Spring FrameworkÉý¼¶µ½Ðµİ汾£º

5.2.9

5.1.18

5.0.19

4.3.29

ÏÂÔØÁ´½Ó£º

https://github.com/spring-projects/spring-framework/releases

0x03 ÓйØÐÂÎÅ

https://spring.io/blog/2015/10/15/spring-framework-4-2-2-4-1-8-and-3-2-15-available-now

0x04 ²Î¿¼Á´½Ó

https://tanzu.vmware.com/security/cve-2020-5421

https://tanzu.vmware.com/security/cve-2015-5211

https://www.security-database.com/detail.php?alert=CVE-2015-5211

0x05 ¹¦·òÏß

2020-09-17  VMware°ä²¼°²È«²¼¸æ

2020-09-22  VSRC°ä²¼°²È«¹«¸æ

 

image.png