高危 Spring Framework反射型文件下载漏洞(CVE-2020-5421)

CVE编号

CVE-2020-5421

利用情况

EXP 已公开

补丁情况

官方补丁

披露时间

2020-09-19
该漏洞EXP已公开传播,漏洞利用成本极低,建议您立即关注并修复。
漏洞描述
在Spring Framework版本5.2.0-5.2.8、5.1.0-5.1.17、5.0.0-5.0.18、4.3.0-4.3.28和更旧的不受支持版本中,可能会绕过CVE-2015-5211对RFD攻击的保护,具体取决于通过使用jsessionid路径参数使用的浏览器。

解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b3...
https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b3...
https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678...
https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678...
https://lists.apache.org/thread.html/r3589ed0d18edeb79028615080d5a0e887885643...
https://lists.apache.org/thread.html/r3589ed0d18edeb79028615080d5a0e887885643...
https://lists.apache.org/thread.html/r503e64b43a57fd68229cac4a869d1a9a2eac9e7...
https://lists.apache.org/thread.html/r503e64b43a57fd68229cac4a869d1a9a2eac9e7...
https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1...
https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1...
https://lists.apache.org/thread.html/r7e6a213eea7f04fc6d9e3bd6eb8d68c4df92a22...
https://lists.apache.org/thread.html/r7e6a213eea7f04fc6d9e3bd6eb8d68c4df92a22...
https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b...
https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b...
https://lists.apache.org/thread.html/r918caad55dcc640a16753b00d8d6acb90b4e36d...
https://lists.apache.org/thread.html/r918caad55dcc640a16753b00d8d6acb90b4e36d...
https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219...
https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219...
https://lists.apache.org/thread.html/ra889d95141059c6cbe77dd80249bb488ae53b27...
https://lists.apache.org/thread.html/ra889d95141059c6cbe77dd80249bb488ae53b27...
https://lists.apache.org/thread.html/raf7ca57033e537e4f9d7df7f192fa6968c1e494...
https://lists.apache.org/thread.html/raf7ca57033e537e4f9d7df7f192fa6968c1e494...
https://lists.apache.org/thread.html/rb18ed999153ef0f0cb7af03efe0046c42c7242f...
https://lists.apache.org/thread.html/rb18ed999153ef0f0cb7af03efe0046c42c7242f...
https://lists.apache.org/thread.html/rc9efaf6db98bee19db1bc911d0fa442287dac5c...
https://lists.apache.org/thread.html/rc9efaf6db98bee19db1bc911d0fa442287dac5c...
https://lists.apache.org/thread.html/rd462a8b0dfab4c15e67c0672cd3c211ecd0e4f0...
https://lists.apache.org/thread.html/rd462a8b0dfab4c15e67c0672cd3c211ecd0e4f0...
https://lists.apache.org/thread.html/re014a49d77f038ba70e5e9934d400af6653e8c9...
https://lists.apache.org/thread.html/rf00d8f4101a1c1ea4de6ea1e09ddf7472cfd306...
https://lists.apache.org/thread.html/rf00d8f4101a1c1ea4de6ea1e09ddf7472cfd306...
https://security.netapp.com/advisory/ntap-20210513-0009/
https://tanzu.vmware.com/security/cve-2020-5421
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 pivotal_software spring_framework * Up to
(including)
4.2.9
运行在以下环境
应用 pivotal_software spring_framework * From
(including)
4.3.0
Up to
(including)
4.3.28
运行在以下环境
应用 pivotal_software spring_framework * From
(including)
5.0.0
Up to
(including)
5.0.18
运行在以下环境
应用 pivotal_software spring_framework * From
(including)
5.1.0
Up to
(including)
5.1.17
运行在以下环境
应用 pivotal_software spring_framework * From
(including)
5.2.0
Up to
(including)
5.2.8
运行在以下环境
系统 debian_11 libspring-java * Up to
(excluding)
4.3.30-1
运行在以下环境
系统 debian_12 libspring-java * Up to
(excluding)
4.3.30-1
阿里云评分
8.3
  • 攻击路径
    远程
  • 攻击复杂度
    容易
  • 权限要求
    无需权限
  • 影响范围
    越权影响
  • EXP成熟度
    EXP 已公开
  • 补丁情况
    官方补丁
  • 数据保密性
    数据泄露
  • 数据完整性
    传输被破坏
  • 服务器危害
    服务器失陷
  • 全网数量
    100
CWE-ID 漏洞类型
NVD-CWE-noinfo
阿里云安全产品覆盖情况