Apache?DolphinScheduler¸ßΣÎó²î£¨CVE-2020-11974¡¢CVE-2020-13922£©´¦Öóͷ£ÊÖ²á
2020-09-17
Ò». Îó²î¸ÅÊö
9ÔÂ11ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½ApacheÈí¼þ»ù½ð»áÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËApache DolphinSchedulerȨÏÞÁýÕÖÎó²î£¨CVE-2020-13922£©ÓëApache DolphinSchedulerÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-11974£©£¬CVE-2020-11974Óëmysql connectorjÔ¶³ÌÖ´ÐдúÂëÎó²îÓйأ¬ÔÚÑ¡Ôñmysql×÷ΪÊý¾Ý¿âʱ£¬¹¥»÷Õß¿Éͨ¹ýjdbc connect²ÎÊýÊäÈë{“detectCustomCollations”:true£¬“ autoDeserialize”:true} ÔÚDolphinScheduler ·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£CVE-2020-13922µ¼ÖÂͨË×Óû§¿Éͨ¹ýapi interfaceÔÚDolphinScheduler ϵͳÖÐÁýÕÖÆäËûÓû§µÄÃÜÂ룺api interface /dolphinscheduler/users/update£¬ÇëÏà¹ØÓû§ÊµÊ±Éý¼¶¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
https://www.mail-archive.com/announce@apache.org/msg06076.html
https://www.mail-archive.com/announce@apache.org/msg06077.html
¶þ. Ó°Ïì¹æÄ£
Apache DolphinSchedulerȨÏÞÁýÕÖÎó²î£¨CVE-2020-13922£©
ÊÜÓ°Ïì°æ±¾
Apache DolphinScheduler = 1.2.0¡¢1.2.1¡¢1.3.1
²»ÊÜÓ°Ïì°æ±¾
Apache DolphinScheduler >= 1.3.2
Apache DolphinSchedulerÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-11974£©
ÊÜÓ°Ïì°æ±¾
Apache DolphinScheduler = 1.2.0 1.2.1
²»ÊÜÓ°Ïì°æ±¾
Apache DolphinScheduler >= 1.3.1
Èý. Îó²î¼ì²â
3.1 ²úÆ·¼ì²â
AG¹«Ë¾¿Æ¼¼Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÓëWEBÓ¦ÓÃÎó²îɨÃèϵͳ(WVSS)ÒѾ߱¸¶Ô£¨CVE-2020-13922£©Îó²îµÄɨÃèÓë¼ì²âÄÜÁ¦£¬ÇëÓа²ÅÅÒÔÉÏ×°±¸µÄÓû§Éý¼¶ÖÁ×îа汾¡£
|
|
Éý¼¶°ü°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
RSAS V6 ϵͳ²å¼þ°ü |
V6.0R02F01.1914 |
http://update.nsfocus.com/update/downloads/id/108317 |
|
RSAS V6 Web²å¼þ°ü |
V6.0R02F00.1811 |
http://update.nsfocus.com/update/downloads/id/108341 |
|
WVSS V6²å¼þÉý¼¶°ü |
V6.0R03F00.177 |
http://update.nsfocus.com/update/downloads/id/108342 |
¹ØÓÚRSASµÄÉý¼¶ÉèÖÃÖ¸µ¼£¬Çë²Î¿¼ÈçÏÂÁ´½Ó£º
https://mp.weixin.qq.com/s/aLAWXs5DgRhNHf4WHHhQyg
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˴˴εÄÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾ÖÁ1.3.2¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£ºhttps://dolphinscheduler.apache.org/zh-cn/docs/release/download.html
4.2 ²úÆ··À»¤
Õë¶Ô£¨CVE-2020-11974£©Îó²î£¬AG¹«Ë¾¿Æ¼¼ÍøÂçÈëÇÖ·À»¤ÏµÍ³(IPS) ÓëÏÂÒ»´ú·À»ðǽ £¨NF£©¡¢×ÛºÏÍþв̽Õ루UTS£©ÒÑÐû²¼¹æÔòÉý¼¶°ü£¬ÇëÏà¹ØÓû§Éý¼¶ÖÁ×îа汾¹æÔò£¬ÒÔÐγÉÇå¾²²úÆ··À»¤ÄÜÁ¦¡£Çå¾²·À»¤²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º
|
Çå¾²·À»¤²úÆ· |
¹æÔò°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
IPS |
5.6.9.23507 |
http://update.nsfocus.com/update/downloads/id/108318 |
|
5.6.10.23507 |
http://update.nsfocus.com/update/downloads/id/108319 |
|
|
NF |
6.0.1.823 |
http://update.nsfocus.com/update/downloads/id/108335 |
|
6.0.2.823 |
http://update.nsfocus.com/update/downloads/id/108336 |
|
|
UTS |
5.6.10.23507 |
http://update.nsfocus.com/update/downloads/id/108357 |
²úÆ·¹æÔòÉý¼¶µÄ²Ù×÷°ì·¨Ïê¼ûÈçÏÂÁ´½Ó£º
WAF£ºhttps://mp.weixin.qq.com/s/oubjPqR4DURWPvrQ9W9mWA
IPS£ºhttps://mp.weixin.qq.com/s/JsRktENQNj1TdZSU62N0Ww
NF£ºhttps://mp.weixin.qq.com/s/bggqcm9VqHiPnfV1XoNuDQ
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







