CVE-2020-11995 | Apache Dubbo·´ÐòÁл¯Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-17

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-11995

ʱ    ¼ä

2020-08-17

Àà    ÐÍ


µÈ    ¼¶

ÖÐΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Dubbo 2.7.0 - 2.7.7

Dubbo 2.6.0 - 2.6.8

Dubbo 2.5.x £¨¹Ù·½²»ÔÙά»¤£©



0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



2020Äê8ÔÂ16ÈÕApache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache Dubbo·´ÐòÁл¯Îó²î£¨CVE-2020-11995£©¡£ ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚApache Dubbo Hessian2ЭÒé±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬µ¼ÖÂͨ¹ý¹¹½¨¶ñÒâÇëÇó¿ÉÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£

DubboĬÈÏʹÓÃHessaian2×÷ΪÐòÁл¯/·´ÐòÁл¯Ð­Ò飬£¬£¬£¬£¬µ±Ê¹ÓÃHessaian2·´ÐòÁл¯HashMap¹¤¾ßʱ£¬£¬£¬£¬£¬Ò»Ð©´æ´¢ÔÚÀàHashMapÖеĺ¯Êý½«±»Ö´ÐУ¬£¬£¬£¬£¬µ«Õâ¿ÉÄܻᵼÖÂÔ¶³ÌÏÂÁîÖ´ÐС£ ¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬rome-1.7.0.jarÖÐEqualsBeanÀàµÄhashCode£¨£©º¯Êý»áµ¼Ö¹¹½¨Ò»¸öÔ¶³Ì¼ÓÔØ¶ñÒâÀಢִÐжñÒâ´úÂëµÄ¶ñÒâÇëÇó¡£ ¡£¡£¡£¡£¡£¡£

Dubbo Êǰ¢Àï°Í°Í¹«Ë¾¿ªÔ´µÄÒ»¿î¸ßÐÔÄÜ¡¢ÇáÁ¿¼¶Java RPC¿ò¼Ü£¬£¬£¬£¬£¬ËüÌṩÁËÈý´ó½¹µãÄÜÁ¦:ÃæÏò½Ó¿ÚµÄÔ¶³ÌÒªÁìŲÓá¢ÖÇÄÜÈÝ´íºÍ¸ºÔØÆ½ºâ,ÒÔ¼°×Ô¶¯×¢²áЧÀÍ¡£ ¡£¡£¡£¡£¡£¡£ÏÖÔÚÒѱ»¶à¼Ò´óÐÍÆóÒµÍøÂç½ÓÄÉ£¬£¬£¬£¬£¬Éæ¼°°¢Àï°Í°Í¼¯ÍÅ¡¢ÖйúÈËÊÙ¡¢ÖйúµçÐÅ¡¢µ±µ±Íø¡¢µÎµÎ³öÐС¢º£¶ûºÍÖйú¹¤ÉÌÒøÐеȣ¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìʹÓÃ2.5.x£¬£¬£¬£¬£¬2.6.xºÍ2.7.xµÄËùÓÐDubboÓû§£¬£¬£¬£¬£¬ÇëÏà¹ØÓû§¾¡¿ìÉý¼¶¡£ ¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


¹Ù·½ÒÑÐû²¼Ð°汾£¬£¬£¬£¬£¬ÇëÉý¼¶µ½2.6.9»ò2.7.8°æ±¾£¬£¬£¬£¬£¬ÏÂÔØµØµã£º

https://github.com/apache/dubbo/releases/tag/dubbo-2.6.9

https://github.com/apache/dubbo/releases/tag/dubbo-2.7.8

ÔÝʱ²½·¥£º

ÔÚHessian2 3.2.9ÖÐÉèÖÃÖ§³Ö°×Ãûµ¥£¬£¬£¬£¬£¬²Î¿¼Á´½Ó£º

https://github.com/apache/dubbo-hessian-lite/releases/tag/v3.2.9


0x03 Ïà¹ØÐÂÎÅ


https://www.mail-archive.com/dev@dubbo.apache.org/msg06676.html


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r5b2df4ef479209dc4ced457b3d58a887763b60b9354c3dc148b2eb5b%40%3Cdev.dubbo.apache.org%3E


0x05 ʱ¼äÏß


2020-08-16 Apache¹Ù·½Ðû²¼Í¨¸æ

2020-08-17 VSRCÐû²¼Îó²îͨ¸æ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾