Apache Struts ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡ ¾÷µ¥ÀÌÆ® ±Ç°í
°ü¸®ÀÚ ( se@hhosting.co.kr ) 2017-03-10 10:48:29
Á¶È¸¼ö 50,576
¡à °³¿ä
o Apache Struts¿¡¼ ÀÓÀÇ ÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ® ¹ßÇ¥ [1]
o Ãë¾àÇÑ ¹öÀüÀ» »ç¿ë ÁßÀÎ ¼¹öÀÇ ´ã´çÀÚ´Â ÇØ°á¹æ¾È¿¡ µû¶ó ÃֽŠ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ±Ç°í
¡à ³»¿ë
o Jakarta Multipart Æļ¸¦ ±â¹ÝÀ¸·Î ÇÑ ÆÄÀÏ ¾÷·Îµå¸¦ ¼öÇàÇÒ ¶§ HTTP Request Çì´õÀÇ Content-TypeÀ» º¯Á¶ÇÏ¿©
¿ø°Ý ÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2017-5638)
¡à ¿µÇâÀ» ¹Þ´Â Á¦Ç° ¹× ¹öÀü
o Apache Struts 2.3.5~2.3.31 ¹öÀü
o Apache Struts 2.5~2.5.10 ¹öÀü
¡Ø ¹öÀü È®ÀÎ ¹æ¹ý : webÇÏÀ§ÀÇ /WEB-INF/lib/struts-core.x.x.jar ÆÄÀÏ ¹öÀü È®ÀÎ
¡à ÇØ°á ¹æ¾È
o Ãë¾àÁ¡ÀÌ ÇØ°áµÈ ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ¼öÇà
- Apache Struts 2.3.32 ¹öÀü [2]
- Apache Struts 2.5.10.1 ¹öÀü [3]
o Content-Type¿¡ ¾ö°ÝÇÑ ÇÊÅ͸µ Àû¿ë ¹× ognl Ç¥Çö½Ä°ú »ç¿ë ±ÝÁö
o commons-fileupload-x.x.x.jar ÆÄÀÏ »èÁ¦
¡Ø ÇØ´ç ÆÄÀÏ »èÁ¦ ½Ã ¾÷·Îµå ±â´É »ç¿ë ºÒ°¡
¡à ±âŸ ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
[Âü°í»çÀÌÆ®]
[1] https://cwiki.apache.org/confluence/display/WW/S2-045
[2] https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.3.32
[3] https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.5.10.1