Zip Slipí§ÒâÎļþÁýÕÖÎó²î Çå¾²Íþвͨ¸æ
2018-06-06
×ÛÊö
ÍâµØÊ±¼ä6ÔÂ5ÈÕ£¬SnykµÄÑо¿Ô±Ðû²¼ÁËÒ»¸öÃûΪZip SlipµÄÎó²î¡£Í¨¹ý¸ÃÎó²î£¬¹¥»÷Õß¿ÉÒÔʹÓÃÒ»¸öÌØÖÆµÄZIPѹËõÎļþ£¬Í¨¹ý·¾¶±éÀúÁýÕÖí§ÒâÎļþ£¬´Ó¶øµ¼ÖÂDZÔÚµÄÏÂÁîÖ´ÐС£
ÏêϸÐÅÏ¢¿É²Î¿¼£º
https://snyk.io/research/zip-slip-vulnerability
Îó²î¸ÅÊö
¹¥»÷Õß¿ÉÒÔʹÓÃÉúÑÄĿ¼±éÀúÎļþÃûµÄÌØÖÆµµ°¸Îļþ£¨ÀýÈç../../evil.sh£©´¥·¢Zip SlipÎó²î¡£ Ò»µ©Ò×Êܹ¥»÷µÄ´úÂë¿âÌáÈ¡Á˹鵵ÎļþµÄÄÚÈÝ£¬¹¥»÷Õ߾ͿÉÒÔ½«ËüÓ¦¸ÃפÁôµÄÎļþ¼ÐÖ®ÍâµÄ¶ñÒâÎļþ½âѹËõ¡£ Ñо¿Ö°Ô±Ö¸³ö£º¡°Ä¿Â¼±éÀúÎó²îµÄÌõ¼þÊǹ¥»÷Õß¿ÉÒÔ»á¼ûÎļþϵͳÖÐÓ¦¸ÃפÁôµÄÄ¿µÄÎļþ¼ÐÖ®ÍâµÄ²¿·ÖÎļþϵͳ¡±¡£È»ºó£¬¹¥»÷Õß¿ÉÒÔÁýÕÖ¿ÉÖ´ÐÐÎļþ²¢Ô¶³ÌŲÓÃËüÃÇ£¬»òÕßÆÚ´ýϵͳ»òÓû§Å²ÓÃËüÃÇ£¬´Ó¶øÔÚÊܺ¦ÕߵĻúеÉÏʵÏÖÔ¶³ÌÏÂÁîÖ´ÐС£
ÊÜÓ°ÏìÇéÐÎ
¸ÃÎó²îÓ°ÏìÁËÊýǧ¸öÏîÄ¿£¬°üÀ¨AWS Toolkit for Eclipse£¬Spring£¬LinkedInµÄPinot OLAPÊý¾Ý¿â£¬Apache / Twitter Heron£¬Alibaba JStorm£¬JenkinsºÍGradle¡£ÆäËûÔÆÌṩÉÌÒ²·¢Ã÷ÁËһЩÎÊÌ⣬²¢ÇÒËæ×Ÿü¶àÐÅÏ¢¹ûÕæ£¬Javaȱ·¦°üÀ¨¸ß¼¶¹éµµÎļþ´¦Öóͷ£µÄÖÐÑë¿âÒâζ×ÅJavaÉúÌ¬ÏµÍ³ÌØÊâųÈõ£¬ÊÜÓ°ÏìµÄJava¿â°üÀ¨Java java.util.zip¡£ Apache commons-compres£¬Apache Ant£¬ZeroTurnaround zt-zipºÍzip4j¡£
ÏêϸµÄÓ°ÏìÁбíÒÔ¼°CVEÇéÐÎÇë²Î¿¼£º
https://github.com/snyk/zip-slip-vulnerability
½â¾ö¼Æ»®
Óû§Ê×ÏÈÐèÒªÔÚ¹¤³ÌÏîÄ¿ÖÐËÑË÷±£´æÎó²îµÄ´úÂëÆ¬¶Ï£¬È·ÈÏÊÇ·ñÊܸÃÎó²îÓ°Ï죬ͬʱȷ±£Ïà¹ØµÄ¿âÒѾÔÚÐÞ¸´ÁÐ±íµ±ÖС£
ÏêϸÄÚÈÝÇë²Î¿¼£º
https://github.com/snyk/zip-slip-vulnerability
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ





