• ȸ¿ø°¡ÀÔ




Ŭ¶ó¿ìµåÄܼÖ
1:1 ¹®ÀÇÇϱâ
ÄÁ¼³Æà ½Åû
¹«»óÁ¦°ø ½Åû
ÀÚÁÖÇÏ´Â Áú¹®
°øÁö»çÇ×
´º½º·¹ÅÍ
º¸µµÀÚ·á
Àü½Ã/¼¼¹Ì³ª
À̺¥Æ®
ÀÚ·á½Ç
 
 

°øÁö»çÇ×

[JAVA] Spring Framework Ãë¾àÁ¡ ¹ß°ß / CVE-2022-22965
ÀÛ¼ºÀÚ    | admin ÀÛ¼ºÀÏ   | 2022-04-01 Á¶È¸¼ö  | 2980

¹ß»ý ¹öÀü / ¿µÇâ ¹öÀü

1) JDK 9 À̻󿡼­ Spring Framework¸¦ »ç¿ëÇÏ´Â °æ¿ì

- Spring Framework 5.3.0 ~ 5.3.17, 5.2.0 ~ 5.2.19 ¹× ÀÌÀü ¹öÀü

¡Ø JDK 8 ÀÌÇϸ¦ »ç¿ëÇÏ´Â °æ¿ì Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù.

 

¹ß»ý ¹è°æ

Spring º¸¾È ÆÀ¿¡¼­ Spring Framework ¹× Spring Cloud Function °ü·Ã ¿ø°Ý ÄÚµå Ãë¾àÁ¡À» ¹ß°ßÇÏ¿´½À´Ï´Ù.

 

ƯÁ¤ Á¶°Ç(JDK9↑) ÀÌ ¸¸Á·ÇÏ´Â »óȲ°ú ȯ°æ¿¡¼­ ¿ø°Ý °ø°ÝÀÚ°¡ FrameworkÀÇ ¸Å°³º¯¼ö ¹ÙÀÎµå ±â´ÉÀ» ÀÌ¿ëÇÏ¿©

AccessLogValve °´Ã¼ ¹× ¾Ç¼º ÇÊµå °ªµéÀ» ȹµæÇÏ°í À̸¦ ÀÌ¿ëÇÏ¿© PipeLine ¸ÅÄ¿´ÏÁòÀ» Æ®¸®°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù.

 

ÀÌ¿Í °°ÀÌ Æ®¸®°Å¸¦ ÁøÇàÇÑ ÀÌÈÄ ÀÓÀÇ °æ·Î ÇÏÀ§¿¡ ÆÄÀÏÀ» ¾²´Â ¹æ½ÄÀÌ °¡´ÉÇÑ °ÍÀ¸·Î È®ÀεǾú½À´Ï´Ù.

 

Âü°í ÀÚ·á

Spring Blog: https://spring.io/blog/2022/03/31/spring-work-rce-early-announcement

ESTSecurity: https://blog.alyac.co.kr/4600?category=750247

KISA: https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=66592

 


À̽´ ¹öÀü È®ÀÎ ¹æ¹ý

1) JDK ¹öÀü È®ÀÎ

 

$ java -version

 

 

2) Spring Framework »ç¿ë À¯¹« È®ÀÎ

- ÇÁ·ÎÁ§Æ® ³» jar, war ÆÐÅ°Áö¸¦ zip È®ÀåÀÚ·Î º¯°æÇÏ¿© ¾ÐÃà ÇØÁ¦ ÈÄ ´ë»ó µð·ºÅ丮¿¡¼­ ¾Æ·¡¿Í °°ÀÌ ¸í·É¾î ½ÇÇà

 

$ find . -name spring-beans*.jar

$ find . -name spring*.jar

$ find . -name CachedIntrospectionResuLts.class

 
 
 

 

ÇØ°á ¹æ¾È

»ç¿ëÇÏ´Â JDK ¹öÀü°ú Spring Framework »ç¿ë À¯¹«¸¦ È®ÀÎÇÑ µÚ ÃֽŠ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ëÀÌ ÇÊ¿äÇÕ´Ï´Ù.

Á¦Á¶»ç ȨÆäÀÌÁö¿¡¼­ Áö¼Ó ½Å±Ô ¹öÀüÀÌ ¾÷µ¥ÀÌÆ® µÇ°í ÀÖ´Â »óÅ·ΠȮÀÎ ÈÄ ¾÷µ¥ÀÌÆ® Àû¿ëÀÌ ÇÊ¿äÇÕ´Ï´Ù.

 

- CVE-2022-22965(Spring4Shell)

· Spring Framework 5.3.18, 5.2.20 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®

 

- CVE-2022-22963

· Spring Cloud Function 3.1.7, 3.2.3 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®

 

½Å±Ô ¹öÀüÀÇ ÇÁ·Î±×·¥ ´Ù¿î·Îµå °æ·Î

https://repo.maven.apache.org/maven2/org/springwork/cloud/spring-cloud-function-context/

 

Àӽà Á¶Ä¡ ¹æ¾È (¾÷µ¥ÀÌÆ®°¡ ºÒ°¡ÇÑ °æ¿ì) - CVE-2022-22965

ÇÁ·ÎÁ§Æ® ÆÐÅ°Áö ¾Æ·¡ ÇØ´ç Àü¿ª Ŭ·¡½º¸¦ »ý¼ºÇÑ µÚ ÀçÄÄÆÄÀÏÀ» ÁøÇà ÈÄ Àû¿ëÇÕ´Ï´Ù.

** ÀçÄÄÆÄÀÏÀ» ÁøÇàÇÑ ÀÌÈÄ¿¡´Â ÇÁ·Î±×·¥ÀÌ Á¤»óÀûÀ¸·Î µ¿ÀÛÇÏ´ÂÁö º°µµ Å×½ºÆ®°¡ ÇÊ¿äÇÕ´Ï´Ù.

 

import org.springwork.core.Ordered;

import org.springwork.core.annotation.Order;

import org.springwork.web.bind.WebDataBinder;

import org.springwork.web.bind.annotation.ControllerAdvice;

import org.springwork.web.bind.annotation.InitBinder;

 

@ControllerAdvice

@Order(10000)

public class BinderControllerAdvice {

@InitBinder

public setAllowedFields(WebDataBinder dataBinder) {

String[] denylist = new String[]{"class.*", "Class.*", "*.class.*", "*.Class.*"};

dataBinder.setDisallowedFields(denylist);

}

}

 
 

°¨»çÇÕ´Ï´Ù.

¸ñ·Ï
kt cloud NAVER Cloud È£½ºÆà ¼Ö·ç¼Ç °í°´¼¾ÅÍ ¸¶ÀÌÆäÀÌÁö
Ŭ¶ó¿ìµå ¼­¹ö
µ¥ÀÌÅͺ£À̽º
½ºÅ丮Áö/CDN
¿£ÅÍÇÁ¶óÀÌÁî
º¸¾È
³×Æ®¿öÅ©
¸Å´ÏÁö¸ÕÆ®
¸¶ÄÏÇ÷¹À̽º
¼­ºñ½ºº° Á¦ÇÑ»çÇ×
Ŭ¶ó¿ìµå ¼Ò°³
Ŭ¶ó¿ìµå ¼­¹ö
Ŭ¶ó¿ìµå ¼Ò°³



Amazon AWS
¿£Å¬¶ó¿ìµå24ÀÇ AWS
Ŭ¶ó¿ìµå ¼Ò°³
¸Å´ÏÁöµå ¼­ºñ½º
¼­¹ö/ÄÚ·ÎÄÉÀ̼Ç/IDC
Ŭ¶ó¿ìµå µðµµ½º ¹æ¾îÁ¸
µµ¸ÞÀμ¾ÅÍ
SSL º¸¾È¼­¹ö ÀÎÁõ¼­
À¥È£½ºÆÃ
ȨÆäÀÌÁö Á¦ÀÛ
±â¾÷ ¼Ö·ç¼Ç


1:1 ¹®ÀÇ Çϱâ
ÄÁ¼³Æà ½Åû
¹«»óÁ¦°ø ½Åû
ÀÚÁÖÇÏ´Â Áú¹®
°øÁö»çÇ×
´º½º·¹ÅÍ
º¸µµÀÚ·á
Àü½Ã/¼¼¹Ì³ª
À̺¥Æ®
ÀÚ·á½Ç

ȸ¿øÁ¤º¸ ¼öÁ¤
·Î±×ÀÎ ¹æ½Ä ¼±ÅÃ
Àå¹Ù±¸´Ï
ÀÚÁÖ¾²´Â µî·ÏÁ¤º¸ °ü¸®
¿ä±Ý ¹× ÀÌ¿ë³»¿ª
¼­ºñ½º »ç¿ëÇöȲ
Ŭ¶ó¿ìµå Á¦Ç°
È£½ºÆà ¼Ö·ç¼Ç
¹ßÇà¿äû
1:1 ¹®Àdz»¿ª


kt cloud
NAVER Cloud
Amazon AWS

(ÁÖ)À£µ¥ÀÌŸ½Ã½ºÅÛ ¿£Å¬¶ó¿ìµå24 | ´ëÇ¥ÀÌ»ç : ¸Í»ó¿µ | »ç¾÷ÀÚµî·Ï¹øÈ£ : 220-86-71461 | Åë½ÅÆǸž÷½Å°í : 2012-°æ±â¼º³²-0210
º»»ç : (13492) °æ±âµµ ¼º³²½Ã ºÐ´ç±¸ ´ë¿ÕÆDZ³·Î 644¹ø±æ 86 (»ïÆòµ¿ 730) 4Ãþ
ÀüÈ­ : 1544-9302 | Æѽº : 031-8016-8519 | ÀüÀÚ¿ìÆí : webmaster@ncloud24.com | °³ÀÎÁ¤º¸°ü¸®Ã¥ÀÓÀÚ : ÀÌÁ¾Áø ¸Å´ÏÀú
Copyright(c) 2011 www.ncloud24.com