¡¾·ì϶¹«¸æ¡¿DrupalĿ¼±éÀú·ì϶£¨CVE-2020-36193£©

°ä²¼¹¦·ò 2021-01-22

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-36193

ʱ   ¼ä

2021-01-22

Àà  ÐÍ

Ŀ¼±éÀú

µÈ   ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

 

DrupalÊÇPHP±àдµÄ¿ªÔ´ÄÚÈÝÖÎÀí¿ò¼Ü£¨CMF£©£¬ËüÓÉÄÚÈÝÖÎÀíϵͳ£¨CMS£©ºÍPHP¿ª·¢¿ò¼Ü£¨Framework£©¹²Í¬×é³É ¡£PEARÈ«³ÆÎªPHPÀ©´óÓëÀûÓÿ⣬ËüÊÇÒ»¸öPHPÀ©´ó¼°ÀûÓõÄÒ»¸ö´úÂë²Ö¿â ¡£

2021Äê1ÔÂ20ÈÕ,Drupal°ä²¼°²È«²¼¸æ£¬DrupalÖдæÔÚÒ»¸öĿ¼±éÀú·ì϶£¨CVE-2020-36193£©£¬¹Ù·½ÆÀ¼¶ÎªÑϳÁ ¡£ÏêÇéÈçÏ£º

DurpalʹÓõÄPEAR Archive_TarÊÇÒ»¿îÓÃÓÚÔÚPHPÖд´½¨¡¢ÌáÈ¡ºÍÁгötarÎļþµÄ¹¤¾ßÀà ¡£ÓÉÓÚArchive_TarÔÚ´¦ÖÃÈç.tar¡¢.tar.gz¡¢.bz2»ò.tlzµÈÌåʽµÄѹËõ°üʱ¹ýÂ˲»ÑÏ£¨·ì϶׷×ÙΪCVE-2020-28948£©£¬ÇÒArchive_TarÖеÄTar.php¶Ô·ûºÅÁ´½Ó²é³­²»³ä·Ö£¬¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«Ô̺¬·ûºÅÁ´½ÓµÄѹËõ°üÀ´ÀûÓô˷ì϶£¬×îÖÕµ¼ÖÂĿ¼±éÀú»òÔ¶³Ì´úÂëÖ´ÐÐ ¡£

Ó°ÏìÁìÓò

Drupal < 9.1.3

Drupal < 9.0.11

Drupal < 8.9.13

Drupal < 7.78

 

 

0x02 ´ëÖý¨Òé

Ŀǰ£¬DrupalÍŶÓÒѾ­½¨¸´ÁË´Ë·ì϶£¬½¨ÒéʵʱÉý¼¶ÖÁÈçϰ汾£º

ÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾

ÏÂÔØÁ´½Ó

Drupal<

9.1.3

Drupal 9.1.3

https://ftp.drupal.org/files/projects/drupal-9.1.3.tar.gz

https://ftp.drupal.org/files/projects/drupal-9.1.3.zip

Drupal<

9.0.11

Drupal 9.0.11

https://ftp.drupal.org/files/projects/drupal-9.0.11.tar.gz

https://ftp.drupal.org/files/projects/drupal-9.0.11.zip

Drupal<

8.9.13

Drupal 8.9.13

https://ftp.drupal.org/files/projects/drupal-8.9.13.tar.gz

https://ftp.drupal.org/files/projects/drupal-8.9.13.zip

Drupal< 7.78

Drupal 7.78

https://ftp.drupal.org/files/projects/drupal-7.78.tar.gz

https://ftp.drupal.org/files/projects/drupal-7.78.zip

 

 

0x03 ²Î¿¼Á´½Ó

https://www.drupal.org/sa-core-2021-001

/new_type/aqtg/20201126/22124.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36193

0x04 ¹¦·òÏß

2021-01-20  Drupal°ä²¼°²È«²¼¸æ

2021-01-22  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png