Drupal Symfony×é¼þÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-08-07

Îó²î±àºÅºÍ¼¶±ð

 

CVE-2018-14773 ¸ß CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

 

Ó°Ïì°æ±¾

 

Drupal < 8.5.6Symfony 2.7.0ÖÁ2.7.48 £¬£¬£¬£¬£¬£¬£¬£¬2.8.0ÖÁ2.8.43 £¬£¬£¬£¬£¬£¬£¬£¬3.3.0ÖÁ3.3.17 £¬£¬£¬£¬£¬£¬£¬£¬3.4.0ÖÁ3.4.13 £¬£¬£¬£¬£¬£¬£¬£¬4.0.0ÖÁ4.0.13 £¬£¬£¬£¬£¬£¬£¬£¬4.1.0ÖÁ4.1.2°æ±¾Symfony HttpFoundation×é¼þÊÜ´ËÇå¾²ÎÊÌâµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£

 

Îó²î¸ÅÊö

 

Symfony HttpFoundation×é¼þÊÇDrupal CoreÖÐʹÓõĵÚÈý·½¿â £¬£¬£¬£¬£¬£¬£¬£¬¸ÃȱÏÝ»áÓ°Ïì8.5.6֮ǰµÄDrupal 8.x°æ±¾¡£¡£¡£¡£¡£¡£¡£SymfonyÊÇÐí¶àÏîÄ¿ÕýÔÚʹÓõÄWebÓ¦ÓóÌÐò¿ò¼Ü £¬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅCVE-2018-14773Îó²î¿ÉÄÜ»áÓ°Ïì´ó×ÚWebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£

 

¸ÃȱÏÝÊÇÓÉÓÚSymfonyÖ§³ÖÒÅÁôºÍΣÏÕµÄHTTP±êÍ·¡£¡£¡£¡£¡£¡£¡£

 

Ô¶³Ì¹¥»÷¿ÉÒÔͨ¹ýʹÓÃÌØÖÆµÄ¡°X-Original-URL¡±»ò¡°X-Rewrite-URL¡±HTTP±êÍ·ÖµÀ´´¥·¢¸ÃȱÏÝ¡£¡£¡£¡£¡£¡£¡£

 

Drupalά»¤ÕßÒ²·¢Ã÷ÁËÒ»¸öÀàËÆµÄÎÊÌâ £¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËDrupal CoreÖÐʹÓõĠ Zend Feed  ºÍ Diactoros ¿â¡£¡£¡£¡£¡£¡£¡£ÕâЩ¿âÊܵ½¡°URLÖØÐ´Îó²î¡±µÄÓ°Ïì £¬£¬£¬£¬£¬£¬£¬£¬ÎÞÂÛÔõÑù £¬£¬£¬£¬£¬£¬£¬£¬DrupalÍŶÓÈ·ÈÏ  Drupal Core²»Ê¹ÓÃÒ×Êܹ¥»÷µÄ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

 

ʹÓÃZend Feed»òDiactorosµÄÍøÕ¾µÄÖÎÀíÔ±ÐèÒª¾¡¿ìÐÞ²¹ËüÃÇ¡£¡£¡£¡£¡£¡£¡£ÔÚºÚ¿Í×îÏÈʹÓÃCVE-2018-14773Îó²î֮ǰ £¬£¬£¬£¬£¬£¬£¬£¬DrupalÖÎÀíÔ±ÐèÒª½ôÆÈÐÞ²¹ËûÃǵÄ×°Öᣡ£¡£¡£¡£¡£¡£

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

 

ÐÞ¸´½¨Ò飺

 

Õâ¸öÎó²îÒÑÔÚSymfony°æ±¾2.7.49 £¬£¬£¬£¬£¬£¬£¬£¬2.8.44 £¬£¬£¬£¬£¬£¬£¬£¬3.3.18 £¬£¬£¬£¬£¬£¬£¬£¬3.4.14 £¬£¬£¬£¬£¬£¬£¬£¬4.0.14ºÍ4.1.3ÖÐÐÞ¸´ £¬£¬£¬£¬£¬£¬£¬£¬DrupalÒÑÔÚÆä×îа汾8.5.6ÖÐÐÞ²¹Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£

 

https://www.drupal.org/SA-CORE-2018-005

https://github.com/symfony/symfony/commit/e447e8b92148ddb3d1956b96638600ec95e08f6b

²Î¿¼Á´½Ó£º

https://www.securityfocus.com/bid/104943/references

https://www.drupal.org/SA-CORE-2018-005

https://www.drupalcenter.de/aggregator/categories/7

https://symfony.com/blog/cve-2018-14773-remove-support-for-legacy-and-risky-http-headers