Ãë¾àÁ¡ID |
22958 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ WordPress ´Â 5.5.2 ÀÌÀü ¹öÀüÀÌ¸ç ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù.
-wp-includes / Requests / Utility / FilteredIterator.php¿¡ deserialization Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ÀÎÁõµÇÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀڴ Ư¼öÇÏ°Ô Á¶ÀÛ µÈ Á÷·ÄÈ µÈ ÆäÀ̷ε带 ¿µÇâÀ» ¹Þ´Â ÀνºÅϽº¿¡ Àü¼ÛÇÏ¿© ´ë»ó È£½ºÆ®¿¡¼ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÔÀ¸·Î½á À̸¦ ¾Ç¿ë ÇÒ ¼ö ÀÖ½À´Ï´Ù (CVE-2020-28032).
-WordpressÀÇ XML-RPC ±¸¼º ¿ä¼Ò¿¡ ¿©·¯ ±ÇÇÑ »ó½Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ÀÎÁõµÇÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ´Â À̸¦ ¾Ç¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â È£½ºÆ®¿¡ ´ëÇÑ ±ÇÇÑ ÀÖ´Â ¾×¼¼½º ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ½À´Ï´Ù (CVE-2020-28035, CVE-2020-28036).
-wp-includes / functions.phpÀÇ is_blog_installed ÇÔ¼ö¿¡ ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ÀÎÁõµÇÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ´Â À̸¦ ¾Ç¿ëÇÏ¿© ÀÎÁõÀ» ¿ìȸÇÏ°í ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù (CVE-2020-28037).
* Âü°í »çÀÌÆ®: https://wordpress.org/news/2020/10/wordpress-5-5-2-security-and-maintenance-release/ https://wordpress.org/support/wordpress-version/version-5-5-2/
* ¿µÇâ¹Þ´Â Ç÷§Æû: WordPress prior to 5.5.2 Any operating system Any version |
ÇØ°áÃ¥ |
´ÙÀ½ WordPress ´Ù¿î·Îµå À¥ ÆäÀÌÁö http://wordpress.org/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» ÇØ°áÇÑ WordPress ¹öÀü(5.5.2 ¶Ç´Â ±× ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2020-28032,CVE-2020-28033,CVE-2020-28034,CVE-2020-28035,CVE-2020-28036,CVE-2020-28037,CVE-2020-28038,CVE-2020-28040 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|