CVE-2020-28948 | DrupalÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-11-26

0x00 ·ì϶¸ÅÊö

²úÆ·Ãû³Æ

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Drupal core

CVE-2020-28948

Ô¶³Ì´úÂëÖ´ÐÐ

¸ßΣ

ÊÇ

CVE-2020-28949

Ô¶³Ì´úÂëÖ´ÐÐ

¸ßΣ

ÊÇ

 

0x01 ·ì϶ÏêÇé

 

image.png

 

DrupalÊÇPHP±àдµÄ¿ªÔ´ÄÚÈÝÖÎÀí¿ò¼Ü£¨CMF£©£¬ËüÓÉÄÚÈÝÖÎÀíϵͳ£¨CMS£©ºÍPHP¿ª·¢¿ò¼Ü£¨Framework£©¹²Í¬×é³É¡£PEARÈ«³ÆÎªPHPÀ©´óÓëÀûÓÿ⣬ËüÊÇÒ»¸öPHPÀ©´ó¼°ÀûÓõÄÒ»¸ö´úÂë²Ö¿â¡£

2020Äê11ÔÂ25ÈÕ,Drupal°ä²¼°²È«²¼¸æ£¬DrupalÖдæÔÚÁ½¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-28948ºÍCVE-2020-28949£©¡£ÏêÇéÈçÏ£º

DrupalÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-28948£©

DurpalʹÓõÄPEAR Archive_TarÊÇÒ»¿îÓÃÓÚÔÚPHPÖд´½¨¡¢ÌáÈ¡ºÍÁгötarÎļþµÄ¹¤¾ßÀà¡£ÓÉÓÚ1.4.10¼°Ö®Ç°µÄArchive_TarÀàÔÚ´¦ÖÃÈç.tar¡¢.tar.gz¡¢.bz2»ò.tlzµÈÌåʽµÄѹËõ°üʱ¹ýÂ˲»ÑÏ£¬¿ÉÄܵ¼Ö´æÔÚPHAR·´ÐòÁл¯·ì϶£¬´Ó¶øÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£

 

DrupalÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-28949£©

ÓÉÓÚ1.4.10¼°Ö®Ç°µÄArchive_TarÀàÓµÓУº//ÎļþÃû¶Ï¸ùÖ°ÄÜ£¬µ«¸ÃÖ°ÄܽöÄÜ·À»¤phar://αºÍ̸¹¥»÷£¬ÆäËüÈκÎÁ÷°ü×°Æ÷¹¥»÷£¨Èçfile£º//£©ÒÀÈ»Äܹ»±»¹¥»÷Õ߳ɹ¦ÀûÓá£

 

Ó°ÏìÁìÓò£º

Drupal 7

Drupal 8.8¼°Ö®Ç°°æ±¾

Drupal 8.9

Drupal 9.0

 

0x02 ´ëÖý¨Òé

ĿǰDrupalÍŶÓÒѾ­°ä²¼Á˰²È«¸üУ¬½¨ÒéÉý¼¶ÖÁÈçϰ汾¡£

Ó°Ïì°æ±¾

½¨¸´°æ±¾

ÏÂÔØÁ´½Ó

Drupal 7

Drupal   7.75

https://www.drupal.org/project/drupal/releases/7.75

Drupal   8.8¼°Ö®Ç°°æ±¾

Drupal   8.8.12

https://www.drupal.org/project/drupal/releases/8.8.12

Drupal   8.9

Drupal   8.9.10

https://www.drupal.org/project/drupal/releases/8.9.10

Drupal   9.0

Drupal   9.0.9

https://www.drupal.org/project/drupal/releases/9.0.9

 

»º½â´ëÊ©£º

²»ÈÝÓû§ÉÏ´«.tar¡¢.tar.gz¡¢.bz2»ò.tlzÀàÐ͵ÄѹËõ°ü¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.drupal.org/sa-core-2020-013

https://www.tenable.com/cve/CVE-2020-28948

https://nvd.nist.gov/vuln/detail/CVE-2020-28948

 

0x04 ¹¦·òÏß

2020-11-25  Drupal°ä²¼°²È«²¼¸æ

2020-11-26  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



image.png