Ãë¾àÁ¡ID |
22933 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
WordPress ¹öÀü 5.3.0 ÀÌÇÏ´Â ´ÙÀ½ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.
-»ç¿ëÀÚ°¡ Á¦°øÈù ÀÔ·ÂÀÇ ºÎÀûÀýÇÑ À¯È¿¼º °Ë»ç·Î ÀÎÇØ µÎ °³ÀÇ »çÀÌÆ® °£ ½ºÅ©¸³Æà (XSS) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ÀÎÁõµÇÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ´Â »ç¿ëÀÚ°¡ Ư¼öÇÏ°Ô Á¶ÀÛ µÈ URLÀ» Ŭ¸¯Çϵµ·Ï ÇÏ¿© »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú ¼¼¼Ç¿¡¼ ÀÓÀÇÀÇ ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇϵµ·Ï À¯µµÇÔÀ¸·Î½á ÀÌ·¯ÇÑ Ãë¾àÁ¡À» ¾Ç¿ë ÇÒ ¼ö ÀÖ½À´Ï´Ù.
-ÀÎÁõ µÈ ±ÇÇÑÀÌ ¾ø´Â ¿ø°Ý »ç¿ëÀÚ°¡ REST API¸¦ ÅëÇØ °Ô½Ã¹°À» °íÁ¤½Ãų ¼ö ÀÖ½À´Ï´Ù.
-wp_kses_bad_protcol ()ÀÌ À̸§ ÁöÁ¤µÈ ÄÝ·Ð ¼Ó¼ºÀ» ÀνÄÇϵµ·Ï °ÈµÇ¾ú½À´Ï´Ù.
* Âü°í »çÀÌÆ®: https://wordpress.org/support/wordpress-version/version-5-3-1/
* ¿µÇâ¹Þ´Â Ç÷§Æû: WordPress prior to 5.3.1 Any operating system Any version |
ÇØ°áÃ¥ |
´ÙÀ½ WordPress ´Ù¿î·Îµå À¥ ÆäÀÌÁö http://wordpress.org/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» ÇØ°áÇÑ WordPress ¹öÀü(5.3.1 ¶Ç´Â ±× ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù |
°ü·Ã URL |
CVE-2019-20042 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|