Apache SkywalkingÔ¶³Ì´úÂëÖ´Ðзì϶
°ä²¼¹¦·ò 2021-02-070x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-02-07 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Apache Skywalking < v8.4.0 |
0x01 ·ì϶ÏêÇé

Apache SkyWalkingÊÇÒ»¸ö¿ªÔ´ÀûÓûúÄÜ¼à¿ØÏµÍ³£¨APM£©£¬£¬£¬£¬£¬£¬£¬ÆäÖØÒªÕë¶Ô΢·þÎñ¡¢ÔÆÔÉúºÍÃæÏòÈÝÆ÷µÄϵͳ½á¹¹£¬£¬£¬£¬£¬£¬£¬Ö§³ÖÖ¸±ê¼à¿Ø¡¢×·×Ù¡¢ÏµÍ³»úÄÜÕï¶ÏÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£
2021Äê02ÔÂ04ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache Skywalking¹Ù·½°ä²¼8.4.0¸üв¼¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËSkywalkingÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚSkyWalkingÖеÄSQL×¢Èë·ì϶£¨º¹Çà×·×ÙΪCVE-2020-9483ºÍCVE-2020-13921£©µÄ½¨¸´²»¹»ÃÀÂú£¬£¬£¬£¬£¬£¬£¬ÈÔ´æÔÚÒ»¸öSQL×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâÒªÇóÀ´²éÎÊÊý¾Ý¿âÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»òͨ¹ýÀûÓÃH2Êý¾Ý¿âÀ´Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
½ØÖ¹Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬Í¨¹ýZoomEyeËÑË÷£¬£¬£¬£¬£¬£¬£¬Êܸ÷ì϶ӰÏìµÄÍøÕ¾ºÍÉ豸¹²194546598¸ö£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÖйúÉ¢²¼24334598£¬£¬£¬£¬£¬£¬£¬Î»¾ÓµÚ¶þ¡£¡£¡£¡£¡£¡£¡£

0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶Òѱ»½¨¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁApache Skywalking v8.4.0¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
http://skywalking.apache.org/downloads/
0x03 ²Î¿¼Á´½Ó
https://skywalking.apache.org/events/release-apache-skywalking-apm-8-4-0/
https://github.com/apache/skywalking/releases/tag/v8.4.0
0x04 ¹¦·òÏß
2021-02-04 SkyWalkingÍŶӰ䲼°²È«²¼¸æ
2021-02-07 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ