CVE-2020-28948 | DrupalÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-11-260x00 ·ì϶¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | ·ì϶µÈ¼¶ | Ô¶³ÌÀûÓà |
Drupal core | CVE-2020-28948 | Ô¶³Ì´úÂëÖ´ÐÐ | ¸ßΣ | ÊÇ |
CVE-2020-28949 | Ô¶³Ì´úÂëÖ´ÐÐ | ¸ßΣ | ÊÇ |
0x01 ·ì϶ÏêÇé

DrupalÊÇPHP±àдµÄ¿ªÔ´ÄÚÈÝÖÎÀí¿ò¼Ü£¨CMF£©£¬ËüÓÉÄÚÈÝÖÎÀíϵͳ£¨CMS£©ºÍPHP¿ª·¢¿ò¼Ü£¨Framework£©¹²Í¬×é³É¡£PEARÈ«³ÆÎªPHPÀ©´óÓëÀûÓÿ⣬ËüÊÇÒ»¸öPHPÀ©´ó¼°ÀûÓõÄÒ»¸ö´úÂë²Ö¿â¡£
2020Äê11ÔÂ25ÈÕ,Drupal°ä²¼°²È«²¼¸æ£¬DrupalÖдæÔÚÁ½¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-28948ºÍCVE-2020-28949£©¡£ÏêÇéÈçÏ£º
DrupalÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-28948£©
DurpalʹÓõÄPEAR Archive_TarÊÇÒ»¿îÓÃÓÚÔÚPHPÖд´½¨¡¢ÌáÈ¡ºÍÁгötarÎļþµÄ¹¤¾ßÀà¡£ÓÉÓÚ1.4.10¼°Ö®Ç°µÄArchive_TarÀàÔÚ´¦ÖÃÈç.tar¡¢.tar.gz¡¢.bz2»ò.tlzµÈÌåʽµÄѹËõ°üʱ¹ýÂ˲»ÑÏ£¬¿ÉÄܵ¼Ö´æÔÚPHAR·´ÐòÁл¯·ì϶£¬´Ó¶øÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£
DrupalÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-28949£©
ÓÉÓÚ1.4.10¼°Ö®Ç°µÄArchive_TarÀàÓµÓУº//ÎļþÃû¶Ï¸ùÖ°ÄÜ£¬µ«¸ÃÖ°ÄܽöÄÜ·À»¤phar://αºÍ̸¹¥»÷£¬ÆäËüÈκÎÁ÷°ü×°Æ÷¹¥»÷£¨Èçfile£º//£©ÒÀÈ»Äܹ»±»¹¥»÷Õ߳ɹ¦ÀûÓá£
Ó°ÏìÁìÓò£º
Drupal 7
Drupal 8.8¼°Ö®Ç°°æ±¾
Drupal 8.9
Drupal 9.0
0x02 ´ëÖý¨Òé
ĿǰDrupalÍŶÓÒѾ°ä²¼Á˰²È«¸üУ¬½¨ÒéÉý¼¶ÖÁÈçϰ汾¡£
Ó°Ïì°æ±¾ | ½¨¸´°æ±¾ | ÏÂÔØÁ´½Ó |
Drupal 7 | Drupal 7.75 | https://www.drupal.org/project/drupal/releases/7.75 |
Drupal 8.8¼°Ö®Ç°°æ±¾ | Drupal 8.8.12 | https://www.drupal.org/project/drupal/releases/8.8.12 |
Drupal 8.9 | Drupal 8.9.10 | https://www.drupal.org/project/drupal/releases/8.9.10 |
Drupal 9.0 | Drupal 9.0.9 | https://www.drupal.org/project/drupal/releases/9.0.9 |
»º½â´ëÊ©£º
²»ÈÝÓû§ÉÏ´«.tar¡¢.tar.gz¡¢.bz2»ò.tlzÀàÐ͵ÄѹËõ°ü¡£
0x03 ²Î¿¼Á´½Ó
https://www.drupal.org/sa-core-2020-013
https://www.tenable.com/cve/CVE-2020-28948
https://nvd.nist.gov/vuln/detail/CVE-2020-28948
0x04 ¹¦·òÏß
2020-11-25 Drupal°ä²¼°²È«²¼¸æ
2020-11-26 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ