Genian Insights Security Advisories ========================================================= Last Updated: 2020-09-25 Security Vulnerability ---------------------------------- .. csv-table:: :header: "Fixed Versions", "Key", "Components", "Description", "Affects Versions", "CVSS Score" :class: datatable :widths: 10 10 15 50 15 10 "2.0.21 (R)","`GS-6160 <https://ims.genians.com/jira/browse/GS-6160>`_","Backend","Tomcat version upgrade (8.5.57 -> 8.5.78)","", "2.0.21 (R)","`GS-6061 <https://ims.genians.com/jira/browse/GS-6061>`_","Backend","httpd 보안 취약ì 패치","", "2.0.20, 2.0.100","`GS-5551 <https://ims.genians.com/jira/browse/GS-5551>`_","Backend","Apache Log4j 보안패치 2.17.1","2.0.100, 2.0.20", "2.0.20, 2.0.100","`GS-5543 <https://ims.genians.com/jira/browse/GS-5543>`_","Backend","Apache 취약ì 조치를 위한 2.4.52 ë²„ì „ ì—…ê·¸ë ˆì´ë“œ","", "2.0.18, 2.0.100","`GS-5107 <https://ims.genians.com/jira/browse/GS-5107>`_","Backend","SQL Injection 처리방법 ê°œì„ ","", "2.0.16, 2.0.100","`GS-5143 <https://ims.genians.com/jira/browse/GS-5143>`_","Backend","openssl 1.1.1l 패치","", "2.0.13","`GS-4652 <https://ims.genians.com/jira/browse/GS-4652>`_","Kafka","Kafka JMX remote portê°€ 보안/ì¸ì¦ ì—†ì´ ì—´ë ¤ìžˆëŠ” ë¬¸ì œ","1.5.107", "2.0.122","`GS-8408 <https://ims.genians.com/jira/browse/GS-8408>`_","Backend","ë‚´ ì •ë³´ 변경 ì‹œ ID파ë¼ë¯¸í„°ë¥¼ 변경하는 경우 변경한 IDë¡œ ìœ ì €ì •ë³´ê°€ 변경ë˜ëŠ” ë¬¸ì œ","",2.4 "2.0.120","`GS-8355 <https://ims.genians.com/jira/browse/GS-8355>`_","Tomcat","Tomcat version upgrade (8.5.86 -> 8.5.96)","",7.5 "2.0.118","`GS-7945 <https://ims.genians.com/jira/browse/GS-7945>`_","Backend","세션 하ì´ìží‚¹ì„ 통해 로그ì¸ì—†ì´ ì¸ì¦API를 ì‚¬ìš©í• ìˆ˜ 있는 취약ì ","",3.9 "2.0.117","`GS-7530 <https://ims.genians.com/jira/browse/GS-7530>`_","Frontend","관리ìžì˜ API 키가 다른 관리ìžì—게 노출ë˜ëŠ” 취약ì ","",5.3 "2.0.113, 2.0.104 (GOV)","`GS-7501 <https://ims.genians.com/jira/browse/GS-7501>`_","Agent","GsView를 통해 ê´€ë¦¬ìž ê¶Œí•œìœ¼ë¡œ ìƒìŠ¹í• 수 있는 취약ì ê°œì„ ","2.0.111",4.6 "2.0.113","`GS-7266 <https://ims.genians.com/jira/browse/GS-7266>`_","Backend","불필요한 httpd FollowSymLink 옵션 ì œê±°","", "2.0.113","`GS-7156 <https://ims.genians.com/jira/browse/GS-7156>`_","Backend, Frontend","XSS 취약ì 존재 (HTML Injection)","",5.6 "2.0.112","`GS-7295 <https://ims.genians.com/jira/browse/GS-7295>`_","Tomcat","Tomcat version upgrade (8.5.78 -> 8.5.86)","2.0.105", "2.0.111","`GS-7227 <https://ims.genians.com/jira/browse/GS-7227>`_","Backend","서버 OpenSSL 1.1.1q -> OpenSSL 1.1.1t ì—…ê·¸ë ˆì´ë“œ","2.0.111", "2.0.111","`GS-7042 <https://ims.genians.com/jira/browse/GS-7042>`_","Agent","[버그바운티] GsView 권한ìƒìŠ¹ 취약ì ê°œì„ ","", "2.0.110","`GS-7157 <https://ims.genians.com/jira/browse/GS-7157>`_","Backend","Local File Inclusion 취약ì ","2.0.101",7 "2.0.108","`GS-6878 <https://ims.genians.com/jira/browse/GS-6878>`_","Agent","reddb.dll(SQLite) 모듈 패치(3.39.2)","", "2.0.107, 2.0.104 (GOV)","`GS-6593 <https://ims.genians.com/jira/browse/GS-6593>`_","Backend","íŒŒì¼ í™•ìž¥ìžë¥¼ í—ˆìš©ëœ íŒŒì¼ í™•ìž¥ìžë¡œ 변경하여 업로드시 파ì¼ì´ 업로드ë˜ëŠ” ë¬¸ì œ","", "2.0.107","`GS-5638 <https://ims.genians.com/jira/browse/GS-5638>`_","Backend, ThreatDetector, Tomcat","Tomcat Context.xml JNDI ì„¤ì • êµ¬ì¡°ê°œì„ ","", "2.0.106, 2.0.104 (GOV)","`GS-6772 <https://ims.genians.com/jira/browse/GS-6772>`_","Backend, Kafka","서버 kafka 2.13-3.1.0 -> 2.13-3.2.3 ì—…ê·¸ë ˆì´ë“œ","", "2.0.106, 2.0.104 (GOV)","`GS-6745 <https://ims.genians.com/jira/browse/GS-6745>`_","Backend","보안 취약성 ë¬¸ì œë¡œ ì¸í•œ _filelist.html íŒŒì¼ ì‚ì œ","", "2.0.104","`GS-6165 <https://ims.genians.com/jira/browse/GS-6165>`_","Agent","Agent OpenSSL 취약ì 패치(1.1.1n -> 1.1.1o)","2.0.104", "2.0.104 (GOV), 2.0.104, 2.0.21 (R)","`GS-6475 <https://ims.genians.com/jira/browse/GS-6475>`_","Backend","서버 Openssl 1.1.1o -> Openssl 1.1.1q ì—…ê·¸ë ˆì´ë“œ","", "2.0.104 (GOV), 2.0.104, 2.0.21 (R)","`GS-6163 <https://ims.genians.com/jira/browse/GS-6163>`_","Backend","OpenSSL version upgrade (1.1.1n -> 1.1.1o)","", "2.0.104 (GOV), 2.0.104","`GS-6474 <https://ims.genians.com/jira/browse/GS-6474>`_","Agent","ì—ì´ì „트 Openssl 1.1.1o -> Openssl 1.1.1q ì—…ê·¸ë ˆì´ë“œ","2.0.104 (GOV), 2.0.106", "2.0.102, 2.0.20","`GS-5881 <https://ims.genians.com/jira/browse/GS-5881>`_","Backend","OpenSSL 서비스거부 취약ì 패치 ","", "2.0.102","`GS-5896 <https://ims.genians.com/jira/browse/GS-5896>`_","Agent","OpenSSL 서비스거부 취약ì 패치 (Endpoint)","2.0.102", "2.0.101","`GS-5511 <https://ims.genians.com/jira/browse/GS-5511>`_","Elasticsearch, Logstash","elasticsearch, logstash ë²„ì „ ì—…ê·¸ë ˆì´ë“œ(7.14.1 -> 7.16.3)","", "2.0.100","`GS-5108 <https://ims.genians.com/jira/browse/GS-5108>`_","Backend","LD_LIBRARY_PATH 환경변수 ì œê±°","",