¡¾Îó²îͨ¸æ¡¿SaltStack¶à¸ö¸ßΣÎó²îͨ¸æ
2020-11-04
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½SaltStack¹Ù·½Ðû²¼Ç徲ͨ¸æÐÞ¸´ÁËÒÔÏÂ3¸ö¸ßΣÎó²î£¬
CVE-2020-16846£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇó£¬Ê¹ÓÃShell×¢Èë(shell injection)»ñÈ¡SSHÅþÁ¬£¬´Ó¶øÔÚSalt-APIÉÏÖ´ÐÐí§ÒâÏÂÁî¡£
CVE-2020-17490£ºÍâµØ¹¥»÷ÕßÓõÍȨÏÞÓû§µÇ¼ salt Ö÷»ú£¬¿ÉÒÔ´ÓÄ¿½ñ salt ³ÌÐòÖ÷»úÉ϶ÁÈ¡µ½ÃÜÔ¿ÄÚÈÝ£¬µ¼ÖÂÐÅÏ¢×ß©¡£
CVE-2020-25592£ºSaltÖеÄeauthºÍACL¹¦Ð§±£´æÈÏÖ¤ÈÆ¹ýÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ýsalt-apiÈÆ¹ýÉí·ÝÑéÖ¤£¬´Ó¶øÊ¹ÓÃsalt sshÅþÁ¬Ä¿µÄÖ÷»ú¡£
SaltStackÊÇÒ»¿î¿ªÔ´×Ô¶¯»¯ÔËά¹¤¾ß¡£¾ß±¸ÉèÖÃÖÎÀí¡¢Ô¶³ÌÖ´ÐС¢¼à¿ØµÈ¹¦Ð§£¬ÔËάְԱͨ¹ý°²ÅÅSaltStack£¬¿ÉÔÚ¶ą̀·þÎñÆ÷ÉÏÅúÁ¿Ö´ÐÐÏÂÁî¡£Æä¾ß±¸¹¦Ð§Ç¿Ê¢£¬ÎÞаÐÔÇ¿µÄÌØµã£¬Ó¦ÓÃÆÕ±é¡£ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
SaltStack = 2015
SaltStack = 2016
SaltStack = 2017
SaltStack = 2018
SaltStack = 2019
SaltStack = 3000
SaltStack = 3001
SaltStack = 3002
²»ÊÜÓ°Ïì°æ±¾
SaltStack >= 3002.1
SaltStack >= 3001.3
SaltStack >= 3000.5
SaltStack >= 2019.2.7
Èý. Îó²î¼ì²â
3.1 °æ±¾¼ì²â
Ïà¹ØÓû§¿Éͨ¹ýÏÂÁÐÏÂÁîÉó²éÄ¿½ñSaltStack°æ±¾£¬ÒÔÅжÏÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ¡£
|
salt --versions-report |
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚSaltStack¹Ù·½ÒѾÐû²¼Ð°汾ÐÞ¸´ÁËÒÔÉÏÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£ºhttps://repo.saltstack.com
4.2 ÐÞ¸´²¹¶¡
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐÐÉý¼¶²Ù×÷£¬Ò²¿É×°Öùٷ½ÎªÒÔϰ汾ÌṩµÄÐÞ²¹³ÌÐò¾ÙÐзÀ»¤£º
|
Ó°Ïì°æ±¾ |
Çå¾²²¹¶¡Á´½Ó |
|
SaltStack 2015.8.10¡¢2015.8.13 |
https://gitlab.com/saltstack/open/salt-patches |
|
SaltStack 2016.3.4¡¢2016.3.6¡¢2016.3.8 |
|
|
SaltStack 2016.11.3¡¢2016.11.6¡¢2016.11.10 |
|
|
SaltStack 2017.7.4¡¢2017.7.8 |
|
|
SaltStack 2018.3.5 |
|
|
SaltStack 2019.2.5¡¢2019.2.6 |
|
|
SaltStack 3000.3¡¢3000.4 |
|
|
SaltStack 3001.1¡¢3001.2 |
|
|
SaltStack 3002 |
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







