Ãë¾àÁ¡ID |
22990 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ WordPress ´Â 5.7.0 ÀÌÀü ¹öÀüÀÌ¸ç ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù.
- ÆÄÀÏÀ» ¾÷·ÎµåÇÒ ¼ö ÀÖ´Â »ç¿ëÀÚ(¿¹: ÀÛ¼ºÀÚ)´Â XXE °ø°ÝÀ¸·Î À̾îÁö´Â ¹Ìµð¾î ¶óÀ̺귯¸®ÀÇ XML ±¸¹® ºÐ¼® ¹®Á¦¸¦ ¾Ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. PHP 8À» »ç¿ëÇÏ´Â WordPress ¼³Ä¡°¡ ÇÊ¿äÇÕ´Ï´Ù. XXE °ø°ÝÀÌ ¼º°øÇÏ¸é ³»ºÎ ÆÄÀÏ¿¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº ºÎ ¸±¸®½º¸¦ ÅëÇØ ¿µÇâÀ» ¹Þ´Â ÀÌÀü ¹öÀü°ú ÇÔ²² WordPress ¹öÀü 5.7.1¿¡¼ ÆÐÄ¡µÇ¾ú½À´Ï´Ù. ÀÚµ¿ ¾÷µ¥ÀÌÆ®¸¦ È°¼ºÈµÈ »óÅ·ΠÀ¯ÁöÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. (CVE-2021-29447)
- ¿öµåÇÁ·¹½º ¿¡µðÅÍÀÇ ºí·Ï Áß Çϳª´Â ºñ¹Ð¹øÈ£·Î º¸È£µÈ °Ô½Ã¹°°ú ÆäÀÌÁö¸¦ ³ëÃâ½ÃÅ°´Â ¹æ½ÄÀ¸·Î ¾Ç¿ëµÉ ¼ö ÀÖ½À´Ï´Ù. À̸¦ À§Çؼ´Â ÃÖ¼ÒÇÑ ±â¿©ÀÚ ±ÇÇÑÀÌ ÇÊ¿äÇÕ´Ï´Ù. ÀÌ°ÍÀº ºÎ ¸±¸®½º¸¦ ÅëÇØ ¿µÇâÀ» ¹Þ´Â ÀÌÀü ¹öÀü°ú ÇÔ²² WordPress 5.7.1¿¡¼ ÆÐÄ¡µÇ¾ú½À´Ï´Ù. (CVE-2021-29450)
* Âü°í »çÀÌÆ®: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-pmmh-2f36-wvhq https://lists.debian.org/debian-lts-announce/2021/04/msg00017.html https://wordpress.org/news/category/security/ Vendor Advisory https://www.debian.org/security/2021/dsa-4896 http://packetstormsecurity.com/files/163148/XML-External-Entity-Via-MP3-File-Upload-On-WordPress.html http://packetstormsecurity.com/files/164198/WordPress-5.7-Media-Library-XML-Injection.html https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-rv47-pc52-qrhh https://lists.debian.org/debian-lts-announce/2021/04/msg00017.html https://wordpress.org/news/category/security/ https://www.debian.org/security/2021/dsa-4896
* ¿µÇâ¹Þ´Â Ç÷§Æû: WordPress 5.7.0 ÀÌÀü ¹öÀü Any operating system Any version |
ÇØ°áÃ¥ |
´ÙÀ½ WordPress ´Ù¿î·Îµå À¥ ÆäÀÌÁö http://wordpress.org/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» ÇØ°áÇÑ WordPress ¹öÀü(5.7.0 ¶Ç´Â ±× ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù |
°ü·Ã URL |
CVE-2021-29447,CVE-2021-29450 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|