2023๋…„ 4์›” 21์ผยท1๋ถ„ ์ฝ๊ธฐ

Code Intelligence, CVSS ์ ์ˆ˜๊ฐ€ ๋” ๋†’์€ Spring ํ”„๋ ˆ์ž„์›Œํฌ์˜ ๋‘ ๋ฒˆ์งธ DoS ์ทจ์•ฝ์  ๊ณต๊ฐœ

Code Intelligence๋Š” Spring Framework์—์„œ ์ƒˆ๋กœ์šด DoS ์ทจ์•ฝ์ (CVE-2023-20863)์„ ๋ฐœ๊ฒฌํ–ˆ์œผ๋ฉฐ, ์ด๋Š” ํšŒ์‚ฌ์—์„œ ์ตœ๊ทผ ๋ฐœ๊ฒฌํ•œ ๋‘ ๋ฒˆ์งธ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. CVSS ์ ์ˆ˜ 7.5๋กœ ์ด์ „ ์ทจ์•ฝ์ (CVE-2023-20861)๋ณด๋‹ค ๋” ์‹ฌ๊ฐํ•œ ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค.

Code Intelligence, CVSS ์ ์ˆ˜๊ฐ€ ๋” ๋†’์€ Spring ํ”„๋ ˆ์ž„์›Œํฌ์˜ ๋‘ ๋ฒˆ์งธ DoS ์ทจ์•ฝ์  ๊ณต๊ฐœ

์ž๋™ํ™”๋œ ์†Œํ”„ํŠธ์›จ์–ด ๋ณด์•ˆ ํšŒ์‚ฌ์ธ Code Intelligence ์ตœ๊ทผ ์ธ๊ธฐ ์žˆ๋Š” Spring Framework ์—์„œ ์‹ฌ๊ฐํ•œ ์„œ๋น„์Šค ๊ฑฐ๋ถ€(DoS) ์ทจ์•ฝ์ (CVE-2023-20863)์„ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค. ๋†€๋ž๊ฒŒ๋„ ์ด๊ฒƒ์€ ํšŒ์‚ฌ๊ฐ€ ๋ถˆ๊ณผ ๋ช‡ ์ฃผ ๋งŒ์— ํ”„๋ ˆ์ž„์›Œํฌ์—์„œ ๋ฐœ๊ฒฌํ•œ ๋‘ ๋ฒˆ์งธ DoS ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค.

Spring Framework์—์„œ ๋ฐœ๊ฒฌ๋œ ์ด์ „ ์ทจ์•ฝ์ ์ธ CVE-2023-20861์€ CVSS(Common Vulnerability Scoring System) ์ ์ˆ˜ 5.3์„ ๊ธฐ๋กํ–ˆ์Šต๋‹ˆ๋‹ค. ๋ฐ˜๋Œ€๋กœ ์ƒˆ๋กœ ๋ฐœ๊ฒฌ๋œ ์ทจ์•ฝ์ ์€ CVSS ์ ์ˆ˜๊ฐ€ 7.5๋กœ ๋” ๋†’์•„ ๋ณด์•ˆ ๋ฌธ์ œ๊ฐ€ ๋” ์‹ฌ๊ฐํ•จ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.

์˜คํ”ˆ ์†Œ์Šค ์†Œํ”„ํŠธ์›จ์–ด์˜ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๊ธฐ ์œ„ํ•œ ๋…ธ๋ ฅ์˜ ์ผํ™˜์œผ๋กœ Code Intelligence Google OSS-Fuzz ํ”„๋กœ๊ทธ๋žจ์—์„œ JVM ํผ์ง• ์—”์ง„์ธ Jazzer๋กœ ํ”„๋กœ์ ํŠธ๋ฅผ ํ…Œ์ŠคํŠธํ•˜์—ฌ ์ทจ์•ฝ์ ์„ ๋ฐœ๊ฒฌํ–ˆ์Šต๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด ์ทจ์•ฝํ•œ Spring Framework ๋ฒ„์ „์— ์˜์กดํ•˜๋Š” ๋‹ค์–‘ํ•œ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์ด ์„œ๋ฒ„ ๊ฐ€์šฉ์„ฑ ๋ฌธ์ œ๋ฅผ ์ผ์œผํ‚ฌ ์œ„ํ—˜์ด ํฝ๋‹ˆ๋‹ค. ์˜ํ–ฅ์„ ๋ฐ›๋Š” ๋ฒ„์ „์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  • 6.0.0 ~ 6.0.7
  • 5.3.0 ~ 5.3.26
  • 5.2.0 ~ 5.2.23.๋ฆด๋ฆฌ์Šค

๋ฐœ๊ฒฌ ํ›„ Code Intelligence CVE๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ์ˆ˜์ • ์‚ฌํ•ญ์„ ๋ฐœํ‘œํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ํ•ด๊ฒฐ์ฑ…์—๋Š” ๋ฐ˜๋ณต๋˜๋Š” ํ…์ŠคํŠธ์˜ ํฌ๊ธฐ์— ๋Œ€ํ•œ ์ œํ•œ ๊ฒ€์‚ฌ ๊ตฌํ˜„๊ณผ ์ผ์น˜ ์—ฐ์‚ฐ์ž์—์„œ ์‚ฌ์šฉ๋˜๋Š” ์ •๊ทœ์‹์˜ ๊ธธ์ด ์ œ์–ด๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ ์˜ ์˜ํ–ฅ์„ ๋ฐ›๋Š” ์‚ฌ์šฉ์ž๋Š” ์ด๋Ÿฌํ•œ ์ˆ˜์ • ์‚ฌํ•ญ์ด ํฌํ•จ๋œ ์ตœ์‹  ๋ฒ„์ „์œผ๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•  ๊ฒƒ์„ ์ด‰๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํŠนํžˆ 6.0.x ๋ฒ„์ „์„ ์‚ฌ์šฉํ•˜๋Š” ์‚ฌ์šฉ์ž๋Š” 6.0.8 ์ด์ƒ์œผ๋กœ, 5.3.x ์‚ฌ์šฉ์ž๋Š” 5.3.27 ์ด์ƒ์œผ๋กœ, 5.2.x ์‚ฌ์šฉ์ž๋Š” 5.2.24.RELEASE+๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ฐœ๋ฐœ์—์„œ ๊ฐ€์žฅ ๋†’์€ ๋ณด์•ˆ ํ‘œ์ค€์„ ๋ณด์žฅํ•˜๋Š” ๊ฒƒ์€ ํŠนํžˆ ๋” ๊ฐ„์†Œํ™”๋œ ํ”„๋กœ์„ธ์Šค๋ฅผ ์ถ”๊ตฌํ•˜๋Š” ๋น„์ฆˆ๋‹ˆ์Šค์— ๋งค์šฐ ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค. AppMaster ์™€ ๊ฐ™์€ No-code ๋ฐ low-code ํ”Œ๋žซํผ์€ ๊ฐœ๋ฐœ์ž๊ฐ€ ๋ณด์•ˆ๊ณผ ํ™•์žฅ์„ฑ์„ ์œ ์ง€ํ•˜๋ฉด์„œ ์›น, ๋ชจ๋ฐ”์ผ ๋ฐ ๋ฐฑ์—”๋“œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์‹ ์†ํ•˜๊ฒŒ ๊ตฌ์ถ•ํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. [appmaster .io/blog/full-guide-on-no-code-low-code-app-development-for-2022" data-mce-href="https:// appmaster.io/blog/full-guide-on -no-code-low-code-app-development-for-2022"> No-code ๋ฐ ๋กœ์šฐ์ฝ”๋“œ low-code ์•ฑ ๊ฐœ๋ฐœ ๋„๊ตฌ๊ฐ€](https://<span class=) ๋„๋ฆฌ ๋ณด๊ธ‰๋˜์–ด ์กฐ์ง์—์„œ ํšจ์œจ์„ฑ์„ ๋†’์ด๊ณ  ์ทจ์•ฝ์„ฑ ์œ„ํ—˜์„ ์ค„์ธ ํฌ๊ด„์ ์ธ ์†Œํ”„ํŠธ์›จ์–ด ์†”๋ฃจ์…˜์„ ๋งŒ๋“ค ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Easy to start
Create something amazing

Experiment with AppMaster with free plan.
When you will be ready you can choose the proper subscription.

Get Started
Code Intelligence, CVSS ์ ์ˆ˜๊ฐ€ ๋” ๋†’์€ Spring ํ”„๋ ˆ์ž„์›Œํฌ์˜ ๋‘ ๋ฒˆ์งธ DoS ์ทจ์•ฝ์  ๊ณต๊ฐœ | AppMaster