安全公告编号:CNTA-2020-0026
2020nian12yue8ri,guojiaxinxianquanloudonggongxiangpingtai(cnvd)shoululeapache struts2 yuanchengdaimazhixingloudong(cnvd-2020-69833,duiyingcve-2020-17530)。gongjizheliyonggailoudong,kezaiweishouquandeqingkuangxiayuanchengzhixingdaima。muqian,loudongxijieyigongkai,changshangyifabushengjibanbenxiufuciloudong。
一、漏洞情况分析
struts2shidierdaijiyumodel-view-controller(mvc)moxingdejavaqiyejiwebyingyongkuangjia,chengweiguoneiwaijiaoweiliuxingderongqiruanjianzhongjianjian。
2020nian12yue8ri,apache strust2fabuzuixinanquangonggao,apache struts2cunzaiyuanchengdaimazhixingdegaoweiloudong(cve-2020-17530)。youyustruts2huiduiyixiebiaoqianshuxingdeshuxingzhijinxingercijiexi,dangzheixiebiaoqianshuxingshiyongle `%{x}` qie `x` dezhiyonghukekongshi,gongjizheliyonggailoudong,ketongguogouzaotedingcanshu,huodemubiaofuwuqidequanxian,shixianyuanchengdaimazhixinggongji。
亚博APPcnvdduigailoudongdezonghepingjiwei“gaowei”。
二、漏洞影响范围
亚博APPloudongyingxiangdechanpinbanbenbaokuo:
亚博APPstruts 2.0.0-2.5.25
三、漏洞处置建议
亚博APPjingzonghejishuyanpan,gailoudongdeliyongtiaojianjiaogao,nanyijinxingdaguimoliyong。apachegongsiyifabulexinbanben(2.5.26)xiufulegailoudong,cnvdjianyiyonghujishishengjizhizuixinbanben:
fu:cankaolianjie:
ganxiecnvdjishuzuzhichengdanwei——beijingzhidaochuangyuxinxijishugufenyouxiangongsi、qianxinkejijituangufenyouxiangongsiweibenbaogaotigongdejishuzhichi。
(编辑:CNVD)