Facebook Google Plus Twitter LinkedIn YouTube RSS ๋ฉ”๋‰ด ๊ฒ€์ƒ‰ ๋ฆฌ์†Œ์Šค - ๋ธ”๋กœ๊ทธ๋ฆฌ์†Œ์Šค - ์›จ๋น„๋‚˜๋ฆฌ์†Œ์Šค - ๋ณด๊ณ ์„œ๋ฆฌ์†Œ์Šค - ์ด๋ฒคํŠธicons_066 icons_067icons_068icons_069icons_070

Tenable ๋ธ”๋กœ๊ทธ

๊ตฌ๋…

Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)

Apache Software Foundation announces a security update for Apache Struts to address a vulnerability in the Commons FileUpload library that could lead to remote code execution. We recommend updating now.

Background

On November 5, the Apache Software Foundation (ASF) published a security announcement to Apache Struts project administrators about CVE-2016-1000031, a vulnerability in the Commons FileUpload library originally reported by Tenableโ€™s Research team in 2016. This library ships as part of Apache Struts 2 and is used as the default mechanism for file uploads. The ASF reports that Apache Struts 2.3.36 and prior are vulnerable. A remote attacker could use this vulnerability to gain remote code execution on publicly accessible websites running a vulnerable version of Apache Struts.

Vulnerability details

For details about this vulnerability, please review the Tenable Research Advisory for the Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution (LOBSTER).

Urgently required actions

The ASF confirms that Apache Struts version 2.5.12 and above include the patched version of the commons-fileupload library, version 1.3.3. If possible, Apache Struts project administrators should upgrade to 2.5.12 and above. The ASF also notes that the patched version of the commons-fileupload library can be dropped into projects that have already been deployed by simply replacing the JAR file in the WEB-INF/lib path with the fixed version. Maven based Struts projects can address this vulnerability by adding in the following dependency:

<dependency>
ย ย <groupId>commons-fileupload</groupId>
ย ย <artifactId>commons-fileupload</artifactId>
ย ย <version>1.3.3</version>
</dependency>

Identifying affected systems

A list of Nessus plugins to identify this vulnerability can be found here.

Get more information:

Learn more about Tenable.io, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a free 60-day trial of Tenable.io Vulnerability Management.

๊ด€๋ จ ๊ธฐ์‚ฌ

Tenable Vulnerability Management

๋น„๊ตํ•  ์ˆ˜ ์—†๋Š” ์ •ํ™•๋„๋กœ ๋ชจ๋“  ์ž์‚ฐ์„ ํ™•์ธํ•˜๊ณ  ์ถ”์ ํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์‹  ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์„ฑ ๊ด€๋ฆฌ ํ”Œ๋žซํผ ์ „์ฒด์— ์•ก์„ธ์Šคํ•˜์‹ญ์‹œ์˜ค.

Tenable Vulnerability Management ํ‰๊ฐ€ํŒ์€ Tenable Lumin ๋ฐ Tenable Web App Scanning์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.

Tenable Vulnerability Management

๋น„๊ตํ•  ์ˆ˜ ์—†๋Š” ์ •ํ™•๋„๋กœ ๋ชจ๋“  ์ž์‚ฐ์„ ํ™•์ธํ•˜๊ณ  ์ถ”์ ํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์‹  ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์„ฑ ๊ด€๋ฆฌ ํ”Œ๋žซํผ ์ „์ฒด์— ์•ก์„ธ์Šคํ•˜์‹ญ์‹œ์˜ค. ์ง€๊ธˆ ์—ฐ๊ฐ„ ๊ตฌ๋…์„ ๊ตฌ๋งคํ•˜์‹ญ์‹œ์˜ค.

100 ์ž์‚ฐ

๊ตฌ๋… ์˜ต์…˜ ์„ ํƒ:

์ง€๊ธˆ ๊ตฌ๋งค

Tenable Vulnerability Management

๋น„๊ตํ•  ์ˆ˜ ์—†๋Š” ์ •ํ™•๋„๋กœ ๋ชจ๋“  ์ž์‚ฐ์„ ํ™•์ธํ•˜๊ณ  ์ถ”์ ํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์‹  ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์„ฑ ๊ด€๋ฆฌ ํ”Œ๋žซํผ ์ „์ฒด์— ์•ก์„ธ์Šคํ•˜์‹ญ์‹œ์˜ค.

Tenable Vulnerability Management ํ‰๊ฐ€ํŒ์€ Tenable Lumin ๋ฐ Tenable Web App Scanning์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.

Tenable Vulnerability Management

๋น„๊ตํ•  ์ˆ˜ ์—†๋Š” ์ •ํ™•๋„๋กœ ๋ชจ๋“  ์ž์‚ฐ์„ ํ™•์ธํ•˜๊ณ  ์ถ”์ ํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์‹  ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์„ฑ ๊ด€๋ฆฌ ํ”Œ๋žซํผ ์ „์ฒด์— ์•ก์„ธ์Šคํ•˜์‹ญ์‹œ์˜ค. ์ง€๊ธˆ ์—ฐ๊ฐ„ ๊ตฌ๋…์„ ๊ตฌ๋งคํ•˜์‹ญ์‹œ์˜ค.

100 ์ž์‚ฐ

๊ตฌ๋… ์˜ต์…˜ ์„ ํƒ:

์ง€๊ธˆ ๊ตฌ๋งค

Tenable Vulnerability Management

๋น„๊ตํ•  ์ˆ˜ ์—†๋Š” ์ •ํ™•๋„๋กœ ๋ชจ๋“  ์ž์‚ฐ์„ ํ™•์ธํ•˜๊ณ  ์ถ”์ ํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์‹  ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์„ฑ ๊ด€๋ฆฌ ํ”Œ๋žซํผ ์ „์ฒด์— ์•ก์„ธ์Šคํ•˜์‹ญ์‹œ์˜ค.

Tenable Vulnerability Management ํ‰๊ฐ€ํŒ์€ Tenable Lumin ๋ฐ Tenable Web App Scanning์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.

Tenable Vulnerability Management

๋น„๊ตํ•  ์ˆ˜ ์—†๋Š” ์ •ํ™•๋„๋กœ ๋ชจ๋“  ์ž์‚ฐ์„ ํ™•์ธํ•˜๊ณ  ์ถ”์ ํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์‹  ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์„ฑ ๊ด€๋ฆฌ ํ”Œ๋žซํผ ์ „์ฒด์— ์•ก์„ธ์Šคํ•˜์‹ญ์‹œ์˜ค. ์ง€๊ธˆ ์—ฐ๊ฐ„ ๊ตฌ๋…์„ ๊ตฌ๋งคํ•˜์‹ญ์‹œ์˜ค.

100 ์ž์‚ฐ

๊ตฌ๋… ์˜ต์…˜ ์„ ํƒ:

์ง€๊ธˆ ๊ตฌ๋งค

Tenable Web App Scanning ์‚ฌ์šฉํ•ด๋ณด๊ธฐ

Tenable One - ์œ„ํ—˜ ๋…ธ์ถœ ๊ด€๋ฆฌ ํ”Œ๋žซํผ์˜ ์ผ๋ถ€๋ถ„์œผ๋กœ ์ตœ๊ทผ์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์œ„ํ•ด ์„ค๊ณ„ํ•œ ์ตœ์‹  ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ œ๊ณต ์ „์ฒด ๊ธฐ๋Šฅ์— ์•ก์„ธ์Šคํ•˜์‹ญ์‹œ์˜ค. ๋งŽ์€ ์ˆ˜์ž‘์—…์ด๋‚˜ ์ค‘์š”ํ•œ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ค‘๋‹จ ์—†์ด, ๋†’์€ ์ •ํ™•๋„๋กœ ์ „์ฒด ์˜จ๋ผ์ธ ํฌํŠธํด๋ฆฌ์˜ค์˜ ์ทจ์•ฝ์„ฑ์„ ์•ˆ์ „ํ•˜๊ฒŒ ์Šค์บ”ํ•ฉ๋‹ˆ๋‹ค. ์ง€๊ธˆ ๋“ฑ๋กํ•˜์‹ญ์‹œ์˜ค.

Tenable Tenable Web App Scanning ํ‰๊ฐ€ํŒ์€ Tenable Lumin ๋ฐ Tenable Web App Scanning์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.

Tenable Web App Scanning ๊ตฌ์ž…

๋น„๊ตํ•  ์ˆ˜ ์—†๋Š” ์ •ํ™•๋„๋กœ ๋ชจ๋“  ์ž์‚ฐ์„ ํ™•์ธํ•˜๊ณ  ์ถ”์ ํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์‹  ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์„ฑ ๊ด€๋ฆฌ ํ”Œ๋žซํผ ์ „์ฒด์— ์•ก์„ธ์Šคํ•˜์‹ญ์‹œ์˜ค. ์ง€๊ธˆ ์—ฐ๊ฐ„ ๊ตฌ๋…์„ ๊ตฌ๋งคํ•˜์‹ญ์‹œ์˜ค.

5 FQDN

Tenable Lumin ์‚ฌ์šฉํ•ด ๋ณด๊ธฐ

Tenable Lumin์œผ๋กœ ์œ„ํ—˜ ๋…ธ์ถœ ๊ด€๋ฆฌ๋ฅผ ์‹œ๊ฐํ™”ํ•˜์—ฌ ํŒŒ์•…ํ•˜๊ณ  ์‹œ๊ฐ„์— ๊ฑธ์ณ ์œ„ํ—˜ ๊ฐ์†Œ๋ฅผ ์ถ”์ ํ•˜๊ณ  ์œ ์‚ฌํ•œ ์กฐ์ง๊ณผ ๋Œ€๋น„ํ•˜์—ฌ ๋ฒค์น˜๋งˆํ‚นํ•˜์‹ญ์‹œ์˜ค.

Tenable Lumin ํ‰๊ฐ€ํŒ์€ Tenable Lumin ๋ฐ Tenable Web App Scanning์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.

Tenable Lumin ๊ตฌ๋งค

์˜์—… ๋‹ด๋‹น์ž์—๊ฒŒ ๋ฌธ์˜ํ•˜์—ฌ ์–ด๋–ป๊ฒŒ Tenable Lumin์ด ์ „์ฒด ์กฐ์ง์— ๋Œ€ํ•œ ํ†ต์ฐฐ์„ ์–ป๊ณ  ์‚ฌ์ด๋ฒ„ ์œ„ํ—˜์„ ๊ด€๋ฆฌํ•˜๋Š” ๋„์›€์ด ๋˜๋Š”์ง€ ์•Œ์•„๋ณด์‹ญ์‹œ์˜ค.

๋ฌด๋ฃŒ๋กœ Tenable Nessus Professional ์‚ฌ์šฉํ•ด๋ณด๊ธฐ

7์ผ ๋™์•ˆ ๋ฌด๋ฃŒ

Tenable Nessus๋Š” ํ˜„์žฌ ๊ตฌ์ž… ๊ฐ€๋Šฅํ•œ ๊ฐ€์žฅ ์ข…ํ•ฉ์ ์ธ ์ทจ์•ฝ์„ฑ ์Šค์บ๋„ˆ์ž…๋‹ˆ๋‹ค.

์‹ ๊ทœ - Tenable Nessus Expert
์ง€๊ธˆ ์‚ฌ์šฉ ๊ฐ€๋Šฅ

Nessus Expert๋Š” ์™ธ๋ถ€ ๊ณต๊ฒฉ ํ‘œ๋ฉด ์Šค์บ”๋‹๊ณผ ๊ฐ™์€ ๋” ๋งŽ์€ ๊ธฐ๋Šฅ ๋ฐ ๋„๋ฉ”์ธ์„ ์ถ”๊ฐ€ํ•˜๊ณ  ํด๋ผ์šฐ๋“œ ์ธํ”„๋ผ๋ฅผ ์Šค์บ”ํ•˜๋Š” ๊ธฐ๋Šฅ์„ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ๋ฅผ ํด๋ฆญํ•˜์—ฌ Nessus Expert๋ฅผ ์‚ฌ์šฉํ•ด๋ณด์‹ญ์‹œ์˜ค.

์•„๋ž˜ ์–‘์‹์„ ์ž‘์„ฑํ•˜์—ฌ Nessus Pro ํ‰๊ฐ€ํŒ์„ ์‚ฌ์šฉํ•ด๋ณด์‹ญ์‹œ์˜ค.

Tenable Nessus Professional ๊ตฌ์ž…

Tenable Nessus๋Š” ํ˜„์žฌ ๊ตฌ์ž… ๊ฐ€๋Šฅํ•œ ๊ฐ€์žฅ ์ข…ํ•ฉ์ ์ธ ์ทจ์•ฝ์„ฑ ์Šค์บ๋„ˆ์ž…๋‹ˆ๋‹ค. Tenable Nessus Professional์€ ์ทจ์•ฝ์„ฑ ์Šค์บ” ์ ˆ์ฐจ๋ฅผ ์ž๋™ํ™”ํ•˜๊ณ  ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ฃผ๊ธฐ์˜ ์‹œ๊ฐ„์„ ์ ˆ๊ฐํ•˜๊ณ  IT ํŒ€๊ณผ ์ฐธ์—ฌํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.

์—ฌ๋Ÿฌ ํ•ด ๋ผ์ด์„ ์Šค๋ฅผ ๊ตฌ๋งคํ•˜์—ฌ ์ ˆ๊ฐํ•˜์‹ญ์‹œ์˜ค. ์—ฐ์ค‘๋ฌดํœด ์ „ํ™”, ์ปค๋ฎค๋‹ˆํ‹ฐ ๋ฐ ์ฑ„ํŒ… ์ง€์›์— ์•ก์„ธ์Šคํ•˜๋ ค๋ฉด Advanced ์ง€์›์„ ์ถ”๊ฐ€ํ•˜์‹ญ์‹œ์˜ค.

๋ผ์ด์„ ์Šค ์„ ํƒ

์—ฌ๋Ÿฌ ํ•ด ๋ผ์ด์„ ์Šค๋ฅผ ๊ตฌ๋งคํ•˜์—ฌ ์ ˆ๊ฐํ•˜์‹ญ์‹œ์˜ค.

์ง€์› ๋ฐ ๊ต์œก ์ถ”๊ฐ€

๋ฌด๋ฃŒ๋กœ Tenable Nessus Expert ์‚ฌ์šฉํ•ด๋ณด๊ธฐ

7์ผ๊ฐ„ ๋ฌด๋ฃŒ

์ตœ์‹  ๊ณต๊ฒฉ ํ‘œ๋ฉด์„ ๋ฐฉ์–ดํ•˜๊ธฐ ์œ„ํ•ด ๊ตฌ์ถ•๋œ Nessus Expert๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด IT๋ถ€ํ„ฐ ํด๋ผ์šฐ๋“œ๊นŒ์ง€, ๋” ๋งŽ์€ ๊ฒƒ์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ณ  ์กฐ์ง์„ ์ทจ์•ฝ์„ฑ์œผ๋กœ๋ถ€ํ„ฐ ๋ณดํ˜ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด๋ฏธ Tenable Nessus Professional์„ ๋ณด์œ ํ•˜๊ณ  ๊ณ„์‹ญ๋‹ˆ๊นŒ?
7์ผ๊ฐ„ Nessus Expert๋กœ ๋ฌด๋ฃŒ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜์‹ญ์‹œ์˜ค.

Tenable Nessus Expert ๊ตฌ์ž…

์ตœ์‹  ๊ณต๊ฒฉ ํ‘œ๋ฉด์„ ๋ฐฉ์–ดํ•˜๊ธฐ ์œ„ํ•ด ๊ตฌ์ถ•๋œ Nessus Expert๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด IT๋ถ€ํ„ฐ ํด๋ผ์šฐ๋“œ๊นŒ์ง€, ๋” ๋งŽ์€ ๊ฒƒ์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ณ  ์กฐ์ง์„ ์ทจ์•ฝ์„ฑ์œผ๋กœ๋ถ€ํ„ฐ ๋ณดํ˜ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ผ์ด์„ ์Šค ์„ ํƒ

์—ฌ๋Ÿฌ ํ•ด ๋ผ์ด์„ ์Šค๋ฅผ ๊ตฌ๋งคํ•˜์—ฌ ๋น„์šฉ์„ ๋” ์ ˆ๊ฐํ•˜์‹ญ์‹œ์˜ค.

์ง€์› ๋ฐ ๊ต์œก ์ถ”๊ฐ€