CVE-2020-5410 | VMware Spring Cloud ConfigĿ¼±éÀú·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-06-020x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-5410 |
ʱ ¼ä |
2020-06-02 |
|
Àà ÐÍ |
DT |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
VMware Spring Cloud Config 2.2.0-2.2.2¡¢2.1.0-2.1.8ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾ |
0x01 ·ì϶ÏêÇé
½üÈÕVMware¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öVMware Spring Cloud ConfigÖеÄĿ¼±éÀú·ì϶£¨CVE-2020-5410£©¡£¸Ã·ì϶ԴÓÚVMware Spring Cloud Config 2.2.0-2.2.2°æ±¾¡¢2.1.0-2.1.8°æ±¾ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾ÔÊÐíÀûÓ÷¨Ê½Í¨¹ýspring-cloud-config-serverÄ£¿éÌṩËÁÒâÅäÖÃÎļþ£¬Ê¹¹¥»÷ÕßÄܹ»ÀûÓþ«ÐÄ»ú¹ØµÄURL½øÐÐËÁÒâÎļþ¶ÁÈ¡¡£
0x02 ´ëÖý¨Òé
¹Ù·½ÒѰ䲼×îа汾½¨¸´ÁË´Ë·ì϶£¬Óû§Ó¦¾¡¿ìÉý¼¶µ½VMware Spring Cloud Config 2.2.3»ò2.1.9°æ±¾£¬ÆäÖв»ÔÙÖ§³ÖµÄ¾É°æ±¾Ó¦¾¡¿ìÉý¼¶ÖÁ¿ÉÖ§³ÖµÄ²»Êܸ÷ì϶ӰÏìµÄ°æ±¾¡£ÏÂÔØµØÖ·£º
https://github.com/spring-cloud/spring-cloud-config/releases
һʱ´ëÊ©£º½«spring-cloud-config-server¸éÖÃÔÚÄÚÍøÖУ¬²¢ÇÒʹÓÃSpring Security¶ÔÆä½øÐб£»¤£¬Ê¹µÃÖ»ÓÐÄÚ²¿ÍøÂç½Ó¼ûȨÏÞµÄÓû§ºÍÓµÓÐÕýÈ·Éí·ÝÑéÖ¤µÄÓû§ÄÜÁ¦½øÐнӼû¡£
0x03 ÓйØÐÂÎÅ
https://spring.io/blog/2020/06/01/spring-cloud-greenwich-sr6-hoxton-sr5-and-2020-0-0-m2-aka-ilford-are-available
0x04 ²Î¿¼Á´½Ó
https://tanzu.vmware.com/security/cve-2020-5410
0x05 ¹¦·òÏß
2020-06-01 VMware¹Ù·½°ä²¼¹«¸æ
2020-06-02 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ