CVE-2020-5410 | VMware Spring Cloud ConfigĿ¼±éÀú·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-02

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-5410

ʱ    ¼ä

2020-06-02

Àà    ÐÍ

DT

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

VMware Spring Cloud Config

2.2.0-2.2.2¡¢2.1.0-2.1.8ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾


0x01 ·ì϶ÏêÇé


VMware Spring Cloud ConfigÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄÒ»Ì×É¢²¼Ê½ÏµÍ³µÄÅäÖÃÖÎÀí½â¾ö¹æ»®¡£¸Ã²úÆ·ÖØÒªÎªÉ¢²¼Ê½ÏµÍ³ÖÐµÄ±í²¿ÅäÖÃÌṩ·þÎñÆ÷ºÍ¿Í»§¶ËÖ§³Ö¡£
½üÈÕVMware¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öVMware Spring Cloud ConfigÖеÄĿ¼±éÀú·ì϶£¨CVE-2020-5410£©¡£¸Ã·ì϶ԴÓÚVMware Spring Cloud Config 2.2.0-2.2.2°æ±¾¡¢2.1.0-2.1.8°æ±¾ºÍ²»ÔÙÊÜÖ§³ÖµÄ¾É°æ±¾ÔÊÐíÀûÓ÷¨Ê½Í¨¹ýspring-cloud-config-serverÄ£¿éÌṩËÁÒâÅäÖÃÎļþ£¬Ê¹¹¥»÷ÕßÄܹ»ÀûÓþ«ÐÄ»ú¹ØµÄURL½øÐÐËÁÒâÎļþ¶ÁÈ¡¡£


0x02 ´ëÖý¨Òé


¹Ù·½ÒѰ䲼×îа汾½¨¸´ÁË´Ë·ì϶£¬Óû§Ó¦¾¡¿ìÉý¼¶µ½VMware Spring Cloud Config 2.2.3»ò2.1.9°æ±¾£¬ÆäÖв»ÔÙÖ§³ÖµÄ¾É°æ±¾Ó¦¾¡¿ìÉý¼¶ÖÁ¿ÉÖ§³ÖµÄ²»Êܸ÷ì϶ӰÏìµÄ°æ±¾¡£ÏÂÔØµØÖ·£º
https://github.com/spring-cloud/spring-cloud-config/releases
һʱ´ëÊ©£º½«spring-cloud-config-server¸éÖÃÔÚÄÚÍøÖУ¬²¢ÇÒʹÓÃSpring Security¶ÔÆä½øÐб £»¤£¬Ê¹µÃÖ»ÓÐÄÚ²¿ÍøÂç½Ó¼ûȨÏÞµÄÓû§ºÍÓµÓÐÕýÈ·Éí·ÝÑéÖ¤µÄÓû§ÄÜÁ¦½øÐнӼû¡£


0x03 ÓйØÐÂÎÅ

https://spring.io/blog/2020/06/01/spring-cloud-greenwich-sr6-hoxton-sr5-and-2020-0-0-m2-aka-ilford-are-available


0x04 ²Î¿¼Á´½Ó


https://tanzu.vmware.com/security/cve-2020-5410


0x05 ¹¦·òÏß


2020-06-01 VMware¹Ù·½°ä²¼¹«¸æ
2020-06-02 VSRC°ä²¼·ì϶¹«¸æ