Apache SkywalkingÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ðû²¼Ê±¼ä 2021-02-07

0x00 Îó²î¸ÅÊö

CVE  ID


ʱ  ¼ä

2021-02-07

Àà   ÐÍ

RCE

µÈ  ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Skywalking < v8.4.0

 

0x01 Îó²îÏêÇé

image.png

 

Apache SkyWalkingÊÇÒ»¸ö¿ªÔ´Ó¦ÓÃÐÔÄÜ¼à¿ØÏµÍ³£¨APM£©£¬£¬£¬£¬£¬£¬£¬ÆäÖ÷ÒªÕë¶Ô΢ЧÀÍ¡¢ÔÆÔ­ÉúºÍÃæÏòÈÝÆ÷µÄϵͳ½á¹¹£¬£¬£¬£¬£¬£¬£¬Ö§³ÖÖ¸±ê¼à¿Ø¡¢×·×Ù¡¢ÏµÍ³ÐÔÄÜÕï¶Ï¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

2021Äê02ÔÂ04ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache Skywalking¹Ù·½Ðû²¼8.4.0¸üÐÂͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËSkywalkingÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£

ÓÉÓÚSkyWalkingÖеÄSQL×¢ÈëÎó²î£¨ÀúÊ·×·×ÙΪCVE-2020-9483ºÍCVE-2020-13921£©µÄÐÞ¸´²»·óÍêÉÆ£¬£¬£¬£¬£¬£¬£¬ÈÔ±£´æÒ»¸öSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇóÀ´ÅÌÎÊÊý¾Ý¿âÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»òͨ¹ýʹÓÃH2Êý¾Ý¿âÀ´Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£

×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýZoomEyeËÑË÷£¬£¬£¬£¬£¬£¬£¬ÊܸÃÎó²îÓ°ÏìµÄÍøÕ¾ºÍ×°±¸¹²194546598¸ö£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÖйúÂþÑÜ24334598£¬£¬£¬£¬£¬£¬£¬Î»¾ÓµÚ¶þ¡£¡£¡£¡£¡£¡£¡£

image.png

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁApache Skywalking v8.4.0¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

http://skywalking.apache.org/downloads/

 

0x03 ²Î¿¼Á´½Ó

https://skywalking.apache.org/events/release-apache-skywalking-apm-8-4-0/

https://github.com/apache/skywalking/releases/tag/v8.4.0

 

0x04 ʱ¼äÏß

2021-02-04  SkyWalkingÍŶÓÐû²¼Ç徲ͨ¸æ

2021-02-07  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png