¡¾Îó²îͨ¸æ¡¿CVE-2020-17518 Apache Flinkí§ÒâÎļþдÈëÎó²î

Ðû²¼Ê±¼ä 2021-01-06

0x00 Îó²î¸ÅÊö

²úÆ·Ãû³Æ

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Apache Flink

CVE-2020-17518

í§ÒâÎļþдÈë

¸ßΣ

ÊÇ

CVE-2020-17519

í§ÒâÎļþ¶ÁÈ¡

¸ßΣ

ÊÇ

0x01 Îó²îÏêÇé

 

image.png

 

Apache FlinkÊÇÓÉApacheÈí¼þ»ù½ð»á¿ª·¢µÄ¿ªÔ´Á÷´¦Öóͷ£¿ò¼Ü£¬£¬£¬£¬£¬£¬Æä½¹µãÊÇÓÃJavaºÍScala±àдµÄÂþÑÜʽÊý¾ÝÁ÷ÒýÇæ¡£¡£¡£¡£ ¡£¡£¡£

2021Äê01ÔÂ05ÈÕ£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬¹ûÕæÁËApache FlinkÖеÄÁ½¸öÇå¾²Îó²î£¨CVE-2020-17518ºÍCVE-2020-17519£©¡£¡£¡£¡£ ¡£¡£¡£

Apache Flinkí§ÒâÎļþдÈëÎó²î£¨CVE-2020-17518£©

Apache Flink 1.5.1ÒýÈëÁËREST´¦Öóͷ£³ÌÐò£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹¦Ð§Éϱ£´æÈ±ÏÝ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄHTTP HEADER½«¶ñÒâÎļþдÈëµ½ÍâµØÎļþϵͳÉϵÄí§ÒâλÖ㬣¬£¬£¬£¬£¬²¢¿Éͨ¹ýFlink »á¼û¡£¡£¡£¡£ ¡£¡£¡£

Ó°Ïì¹æÄ££º

Apache Flink 1.5.1-1.11.2

 

Apache Flinkí§ÒâÎļþ¶ÁÈ¡Îó²î£¨CVE-2020-17519£©

ÓÉÓÚApache Flink 1.11.0ÖÐÒýÈëÁËÒ»Ïî²»Çå¾²µÄ¸ü¸Ä£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õßͨ¹ýJobManagerÀú³ÌµÄREST½Ó¿Ú¶ÁÈ¡ÍâµØÎļþϵͳÉϵÄÈκÎÎļþ£¬£¬£¬£¬£¬£¬ µ«½öÏÞÓÚ»á¼ûJobManagerÀú³Ì¿É»á¼ûµÄÎļþ¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýREST APIʹÓÃ../ʵÏÖĿ¼±éÀú¡£¡£¡£¡£ ¡£¡£¡£

Ó°Ïì¹æÄ££º

Apache Flink 1.11.0¡¢1.11.1¡¢1.11.2

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚApacheÒѾ­ÐÞ¸´ÁËÏà¹ØÎó²î£¬£¬£¬£¬£¬£¬½¨Òé¸üÐÂÖÁFlink 1.11.3»ò1.12.0¡£¡£¡£¡£ ¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://flink.apache.org/zh/downloads.html


0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202101.mbox/%3CCAGr9p8Co+adXuNzmHmG+o0uE6TMFGQqGdq80o1icRRnkKAZpEA@mail.gmail.com%3E

http://mail-archives.apache.org/mod_mbox/www-announce/202101.mbox/%3CCAGr9p8BZ+sMtZTNaU569f+8398WJr4k64WMDdSVaysgPy=HY2g@mail.gmail.com%3E

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17518

 

0x04 ʱ¼äÏß

2021-01-05  ApacheÐû²¼Ç徲ͨ¸æ

2021-01-06  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png