You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
åä½ JPCERT-AT-2017-0025 JPCERT/CC 2017-07-10(æ°è¦) 2017-07-11(æ´æ°) <<< JPCERT/CC Alert 2017-07-10 >>> Apache Struts 2 ã®èå¼±æ§ (S2-048) ã«é¢ããæ³¨æåèµ· https://www.jpcert.or.jp/at/2017/at170025.html I. æ¦è¦ Apache Software Foundation ã¯ã2017å¹´7æ7æ¥ (ç±³å½æé) ã« Apache Struts 2 ã®èå¼±æ§ (CVE-2017-9791) ã«é¢ããæ å ± (S2-048) ãå ¬éãã¾ããã 2.3 系㮠Apache Struts 2 ã«å«ã¾ãã Struts 1 Plugin ãç¨ãã¦ãã Struts ã¢ããªã±ã¼ã·ã§ã³ã«ããã¦ãå ¥åå¤ãé©åã«å¦çããªãã£ãå ´åã«ã æ¬èå¼±æ§ã®å½±é¿ãå
NICTã¦ããã¼ãµã«ã³ãã¥ãã±ã¼ã·ã§ã³ç ç©¶æã§ã¯ãApache Struts2ã®èå¼±æ§ã®å ¬è¡¨ãè¸ã¾ãã¦ã3æ13æ¥ï¼æï¼ä»¥éãNICTã使ããé³å£°å¯¾è©±ç ç©¶ç¨ã®ã½ããã¦ã§ã¢éçºãããï¼MCMLé³å£°ã¤ã³ã¿ã©ã¯ã·ã§ã³SDKï¼ãå¤é¨ã®ç ç©¶è çã«æä¾ããå ¬éãµã¼ãã®éç¨ã忢ãã¦ãã¾ãã ãã®å¾ã®å é¨èª¿æ»ã«ãããå½è©²ãµã¼ãã¯å¤é¨ããéå¸¸ã«æ©ã段éã«ä¸æ£ã«ã¢ã¯ã»ã¹ãåãã¦ããããµã¼ãã®ä¸ã«ãå©ç¨è ã®IDãã¡ã¼ã«ã¢ãã¬ã¹ãæå·åããããã¹ã¯ã¼ãã®æ å ±ãå«ã¾ãã¦ãããã¨ãã5æ1æ¥ï¼æï¼ä»ãã§å¤æãã¾ããã
ã´ãã¯å社ãéå¶åè¨ãã¦ãããããã¹ã±ãããã¼ã«ãªã¼ã°ãB.LEAGUEãé¢é£ã®Webãµã¤ãã䏿£ã¢ã¯ã»ã¹ãåããåé¡ã§ãåå ã¨ãªã£ããApache Struts2ãã®èå¼±æ§ã®èå¥åãã3æ9æ¥ã«å ¬éããããS2-045ãã§ããã¨æ¬èªåæã«åçããã 䏿£ã¢ã¯ã»ã¹ãåããã®ã¯ãB.LEAGUEãã±ãããµã¤ãã¨ãã¡ã³ã¯ã©ãåä»ãµã¤ãã®ãµã¼ãã¼ã ãB.LEAGUEãã±ãããµã¤ãã¯ããããã¡ã¯ããªã¼ããã¡ã³ã¯ã©ãåä»ãµã¤ãã¯ããããå±ã½ããããã´ãã®çºæ³¨ãåãã¦æ§ç¯ããã両ãµã¤ãã§ã¯Struts2ã使ç¨ãã¦ãããä»»æã®ã³ã¼ããå®è¡ã§ããS2-045ã¨ããèå¼±æ§ãæªç¨ãããã ã´ãã¯3æ25æ¥ã«ä¸¡ãµã¤ãã«ãããå ¨ã¦ã®ã¯ã¬ã¸ããã«ã¼ãæ±ºæ¸æ©è½ã忢ãã調æ»ä¼ç¤¾ã®Payment Card Forensicsï¼PCFï¼ã«è©³ç´°ãªèª¿æ»ãä¾é ¼ããã4æ10æ¥ã®PCFããã®ä¸éå ±åã§ã䏿£ã¢ã¯ã»ã¹ãåãã¦ããã
ãã¬ã³ããã¤ã¯ãã®è å¨ãªãµã¼ãé¨éã§ãããã©ã¯ã¼ãã«ããã³ã°ã¹ã¬ãããªãµã¼ãã§ã¯ããApache Strutsï¼ã¢ãããã»ã¹ãã©ããï¼ããæ±ããä¸é£ã®èå¼±æ§ã«å¯¾ãã¦æ»æã仿ãããããã³ã°ãã¼ã«ãæµéãã¦ãããã¨ã確èªãã¾ããã Apache Struts ã¨ã¯ãApacheã½ããã¦ã§ã¢è²¡å£ã® Apache Strutsããã¸ã§ã¯ãã«ã¦éçºããã¦ãããªã¼ãã³ã½ã¼ã¹ã® Java Webã¢ããªã±ã¼ã·ã§ã³ãã¬ã¼ã ã¯ã¼ã¯ã§ãã2013å¹´7æ16æ¥ã«ãæ·±å»ãªèå¼±æ§ãä¿®æ£ããã¢ãããã¼ããStruts 2.3.15.1ãããªãªã¼ã¹ããã¦ãã¾ãã ããã§ããæ·±å»ãªèå¼±æ§ã¨ã¯ãã¢ããªã±ã¼ã·ã§ã³ãµã¼ãã®å®è¡æ¨©éã§ä»»æã® OS ã³ãã³ããå®è¡å¯è½ã¨ãªããã®ã§ããä¸è¬ã«ãããã³ã°è¡çºã¯ 6ã¤ã®æ®µéãçµã¦è¡ãããã¨ããã¦ãã¾ããããã§ã¼ãº1ï¼åµå¯ããããã§ã¼ãº2ï¼ã¹ãã£ã³ããããã§ã¼ãº3ï¼ã¢ã¯ã»ã¹æ¨©ã®ç²å¾ãããã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}