CVE-2020-13953 | Apache Tapestry WEB-INFÎļþÏÂÔØ·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-09-270x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-13953 | ʱ ¼ä | 2020-09-27 |
Àà ÐÍ | µÈ ¼¶ | ÖÐΣ | |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Tapestry 5.4.0-5.5.0 |
Apache TapestryÊÇÒ»¸öʹÓÃJava˵»°±àдµÄ¿ªÔ´¿ò¼Ü£¬ÓÃÓÚ´´½¨¶¯Ì¬µÄ¡¢×³ÊµµÄ¡¢¸ß½Ã½ÝÐÔµÄwebÀûÓ÷¨Ê½¡£Tapestry¿ò¼Ü¹¹ÖþÔڳ߶ȵÄJava Servlet APIÖ®ÉÏ£¬Òò¶øËü¿ÉÄܺܺõؼæÈÝÈκÎservletÈÝÆ÷»òÕßÀûÓ÷þÎñ¡£TapestryÓµÓкܶలȫְÄÜ£¬Ö¼ÔÚ¼ÓÇ¿ÀûÓ÷¨Ê½ÃâÊܲ»ÓÃÒªµÄÈëÇֺͻؾø·þÎñµÄÇÖº¦¡£
0x01 ·ì϶ÏêÇé

2020Äê09ÔÂ26ÈÕ£¬Apache TapestryÖб»Â¶³ö³ö´æÔÚÒ»¸öÎļþÏÂÔØ·ì϶¡£·ì϶׷×ÙΪCVE-2020-13953£¬Æä·ì϶µÈ¼¶ÎªÖÐΣ¡£¹¥»÷Õß¿Éͨ¹ý¶ñÒâµÄURLÏÂÔØWEB-INFÖеÄÎļþ¡£
0x02 ´ëÖý¨Òé
½«Apache TapestryÉý¼¶µ½ 5.6.0»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://tapestry.apache.org/download.html
0x03 ²Î¿¼Á´½Ó
https://www.mail-archive.com/users@tapestry.apache.org/msg77276.html
https://seclists.org/oss-sec/2020/q3/197
https://tapestry.apache.org/security.html
0x04 ¹¦·òÏß
2020-09-26 Apache°ä²¼°²È«²¼¸æ
2020-09-27 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/


¾©¹«Íø°²±¸11010802024551ºÅ