CVE-2020-13953 | Apache Tapestry WEB-INFÎļþÏÂÔØÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-09-27

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-13953

ʱ   ¼ä

2020-09-27

Àà   ÐÍ


µÈ   ¼¶

ÖÐΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Tapestry 5.4.0-5.5.0


Apache TapestryÊÇÒ»¸öʹÓÃJavaÓïÑÔ±àдµÄ¿ªÔ´¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ½¨É趯̬µÄ¡¢½áʵµÄ¡¢¸ßÎÞаÐÔµÄwebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£Tapestry¿ò¼ÜÐÞ½¨ÔÚ±ê×¼µÄJava Servlet APIÖ®ÉÏ£¬£¬£¬£¬£¬£¬£¬£¬Òò´ËËüÄܹ»ºÜºÃµØ¼æÈÝÈκÎservletÈÝÆ÷»òÕßÓ¦ÓÃЧÀÍ¡£¡£¡£¡£¡£¡£Tapestry¾ßÓÐÐí¶àÇå¾²¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÔöǿӦÓóÌÐòÃâÊܲ»ÐëÒªµÄÈëÇֺ;ܾøÐ§À͵ÄË𺦡£¡£¡£¡£¡£¡£

0x01 Îó²îÏêÇé

ͼƬ.png

 

2020Äê09ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Apache TapestryÖб»Ì»Â¶³ö±£´æÒ»¸öÎļþÏÂÔØÎó²î¡£¡£¡£¡£¡£¡£Îó²î×·×ÙΪCVE-2020-13953£¬£¬£¬£¬£¬£¬£¬£¬ÆäÎó²îÆ·¼¶ÎªÖÐΣ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý¶ñÒâµÄURLÏÂÔØWEB-INFÖеÄÎļþ¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé

½«Apache TapestryÉý¼¶µ½ 5.6.0»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://tapestry.apache.org/download.html

0x03 ²Î¿¼Á´½Ó

https://www.mail-archive.com/users@tapestry.apache.org/msg77276.html

https://seclists.org/oss-sec/2020/q3/197

https://tapestry.apache.org/security.html

0x04 ʱ¼äÏß

2020-09-26  ApacheÐû²¼Ç徲ͨ¸æ

2020-09-27  VSRCÐû²¼Ç徲ͨ¸æ

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



ͼƬ.png