CVE-2020-11995 | Apache Dubbo·´ÐòÁл¯·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-08-17

0x00 ·ì϶¸ÅÊö



CVE   ID

CVE-2020-11995

ʱ    ¼ä

2020-08-17

Àà    ÐÍ


µÈ    ¼¶

ÖÐΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Dubbo 2.7.0 - 2.7.7

Dubbo 2.6.0 - 2.6.8

Dubbo 2.5.x £¨¹Ù·½²»ÔÙÊØ»¤£©



0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



2020Äê8ÔÂ16ÈÕApache¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öApache Dubbo·´ÐòÁл¯·ì϶£¨CVE-2020-11995£©¡£¸Ã·ì϶ԴÓÚApache Dubbo Hessian2ºÍ̸´æÔÚ·´ÐòÁл¯·ì϶£¬µ¼ÖÂͨ¹ý¹¹½¨¶ñÒâÒªÇó¿ÉÖ´ÐÐËÁÒâ´úÂë¡£

DubboĬÈÏʹÓÃHessaian2×÷ΪÐòÁл¯/·´ÐòÁл¯ºÍ̸£¬µ±Ê¹ÓÃHessaian2·´ÐòÁл¯HashMap¶ÔÏóʱ£¬Ò»Ð©´æ´¢ÔÚÀàHashMapÖеĺ¯Êý½«±»Ö´ÐУ¬µ«Õâ¿ÉÄܻᵼÖÂÔ¶³ÌºÅÁîÖ´ÐС£ÀýÈ磬rome-1.7.0.jarÖÐEqualsBeanÀàµÄhashCode£¨£©º¯Êý»áµ¼Ö¹¹½¨Ò»¸öÔ¶³Ì¼ÓÔØ¶ñÒâÀಢִÐжñÒâ´úÂëµÄ¶ñÒâÒªÇó¡£

Dubbo Êǰ¢Àï°Í°Í¹«Ë¾¿ªÔ´µÄÒ»¿î¸ß»úÄÜ¡¢ÇáÁ¿¼¶Java RPC¿ò¼Ü£¬ËüÌṩÁËÈý´óÖ÷ÌâÄÜÁ¦:ÃæÏò½Ó¿ÚµÄÔ¶³Ì²½ÖèŲÓá¢ÖÇÄÜÈÝ´íºÍ¸ºÔØÆ½ºâ,ÒÔ¼°×Ô¶¯×¢²á·þÎñ¡£Ä¿Ç°Òѱ»¶à¼Ò´óÐÍÆóÒµÍøÂçѡȡ£¬Éæ¼°°¢Àï°Í°Í¼¯ÍÅ¡¢ÖйúÈËÊÙ¡¢ÖйúµçÐÅ¡¢µ±µ±Íø¡¢µÎµÎ³öÐÓ×¢º£¶ûºÍÖйú¹¤ÉÌÒøÐеÈ£¬¸Ã·ì϶ӰÏìʹÓÃ2.5.x£¬2.6.xºÍ2.7.xµÄËùÓÐDubboÓû§£¬ÇëÓйØÓû§¾¡¿ìÉý¼¶¡£


0x02 ´ëÖý¨Òé


¹Ù·½ÒѰ䲼а汾£¬ÇëÉý¼¶µ½2.6.9»ò2.7.8°æ±¾£¬ÏÂÔØµØÖ·£º

https://github.com/apache/dubbo/releases/tag/dubbo-2.6.9

https://github.com/apache/dubbo/releases/tag/dubbo-2.7.8

һʱ´ëÊ©£º

ÔÚHessian2 3.2.9ÖÐÉèÖÃÖ§³Ö°×Ãûµ¥£¬²Î¿¼Á´½Ó£º

https://github.com/apache/dubbo-hessian-lite/releases/tag/v3.2.9


0x03 ÓйØÐÂÎÅ


https://www.mail-archive.com/dev@dubbo.apache.org/msg06676.html


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r5b2df4ef479209dc4ced457b3d58a887763b60b9354c3dc148b2eb5b%40%3Cdev.dubbo.apache.org%3E


0x05 ¹¦·òÏß


2020-08-16 Apache¹Ù·½°ä²¼¹«¸æ

2020-08-17 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾