K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Ôƹٷ½É̳Ç
ÌìÔªÊý¾ÝÍø
ÔÆERP¹Ù·½É̳Ç
×÷ΪÖйú×î¾ßÓ°ÏìÁ¦µÄITÆ·ÅÆÖ®Ò»£¬K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾½èÅÌËãÖ®Á¦£¬´òÔ컥Áª»¥Í¨µÄÊý¾ÝÉú̬£¬ÒÔÊý¾ÝÖ®Ãû£¬¿ªÆôÈ«ÐÂÕ³̵ÄÌìÏÂÎÄÃ÷¡£
Éó²é¸ü¶àÊÓÆµ >K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÃñÕþÔÆÆ½Ì¨Æ¾Ö¤ÌìÏÂÃñÕþϽµµÍìÏÈ¡¢Õþ¸®²¿·ÖÒ»Á÷µÄ±ê×¼ÍýÏëÉè¼Æ£¬Æ½Ì¨ÈÚºÏÃñÕþÓªÒµ¹ÜÀí¡¢¹«¹²·þÎñ¡¢´óÊý¾Ý×ÊÔ´·þÎñ¡£
ÏàʶÏêÇé >K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Ôƹٷ½É̳Ç
ÌìÔªÊý¾ÝÍø
ÔÆERP¹Ù·½É̳Ç
CVE-2020-11651£ºSaltStackÈÏÖ¤ÈÆ¹ýÎó²î,¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬿ÉÒÔÈÆ¹ýSalt MasterµÄÑéÖ¤Âß¼£¬Å²ÓÃÏà¹ØÎ´ÊÚȨº¯Êý¹¦Ð§£¬´Ó¶ø¿ÉÒÔÔì³ÉÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£
CVE-2020-11652£ºSalt MasterĿ¼±éÀúÎó²î£¬¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬶ÁÈ¡·þÎñÆ÷ÉÏí§ÒâÎļþ¡£
ÆäËûµÚÈý·½×é¼þÎó²î£º
CVE-2015-5589£ºPHPÔ¶³Ì¾Ü¾ø·þÎñÎó²î
CVE-2016-2554£ºPHP»ùÓÚÕ»µÄ»º³åÇøÒç³öÎó²î
CVE-2018-7584£ºPHPÕ»»º³åÇøÒç³öÎó²î
CVE-2016-7568£ºPHPÕûÊýÒç³öÎó²î
CVE-2019-9023£ºPHP»º³åÇø¹ýʧÎó²î
CVE-2017-12933£ºPHP¶Ñ»º³åÇøÒç³öÎó²î
²úÆ·Ãû³Æ | ÊÜÓ°Ïì²úÆ·°æ±¾ | ÐÞ¸´²¹¶¡°ü/Éý¼¶°ü°æ±¾ |
AS13000 | 3.6.3.9 | Salt-2015.8-AS13000--3.6.3.9-update.zip php-5.6.40-AS13000-3.6.3.9-update.zip |
AS13000 | 3.6.3.9-SP1 | |
AS13000 | 3.6.3.9-SP2 | |
AS13000 | 3.6.3.9-SP3 | |
AS13000 | 3.6.3.9-SP4 | |
AS13000 | 3.6.3.9-SP5 |
ÀÖ³ÉʹÓÃÉÏÊöÎó²î¿ÉʵÏÖÔ¶³Ì´úÂëÖ´Ðлòµ¼ÖÂPHP¾Ü¾ø·þÎñ¡£
Îó²îµÃ·Ö£ºCVE | V3.1 Vector(Base) | Base Score | V3.1 Vector(Temporal Score) | Temporal Score |
CVE-2020-11651 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:F/RL:O/RC:C | 9.1 |
CVE-2020-11652 | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 6.5 | E:F/RL:O/RC:C | 6 |
CVE-2015-5589 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:U/RL:O/RC:C | 8.5 |
CVE-2016-2554 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:P/RL:O/RC:C | 8.8 |
CVE-2018-7584 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:P/RL:O/RC:C | 8.8 |
CVE-2016-7568 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:U/RL:O/RC:C | 8.5 |
CVE-2019-9023 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:P/RL:O/RC:C | 8.8 |
CVE-2017-12933 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:U/RL:O/RC:C | 8.5 |
Îó²îʹÓÃÌõ¼þ£º
CVE-2020-11651£¬ÒªÇóÄ¿µÄϵͳ¿ªÆôsaltstack·þÎñ£¨Ä¬ÈÏ4506¶Ë¿Ú£©£¬²¢¿ÉÒÔͨ¹ý¹«Íø»á¼û¡£
Îó²îÏêϸÐÎò£º
CVE-2020-11651£¬¸ÃÎó²î¿É±»Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆµÄÇëÇóÔÚminion¶Ë·þÎñÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£
ÇëÓû§Ö±½ÓÁªÏµ¿Í»§·þÎñÖ°Ô±»ò·¢ËÍÓʼþÖÁsun.meng@inspur.com£¬»ñÈ¡²¹¶¡£¬ÒÔ¼°Ïà¹ØµÄÊÖÒÕÐÖú¡£
¹æ±Ü²½·¥£ºÎÞ
Îó²îȪԴ£ºÓÉÍâÑóijÇå¾²ÍŶӹûÕæÅû¶
¸üмͼ£º20200519-V1.0-Initial Release
FAQs£ºÎÞ
K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Çå¾²Ó¦¼±ÏìÓ¦¶ÔÍâ·þÎñ£ºK8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Ò»Ö±Ö÷Õž¡È«Á¦°ü¹Ü²úÆ·Óû§µÄ×îÖÕÀûÒæ£¬×ñÕÕÈÏÕæÈεÄÇå¾²ÊÂÎñÅû¶ÔÔò£¬²¢Í¨¹ý²úÆ·Çå¾²ÎÊÌâ´¦Öóͷ£»úÖÆ´¦Öóͷ£²úÆ·Çå¾²ÎÊÌâ¡£
·´ÏìK8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾²úÆ·Ïà¹ØµÄÇå¾²ÎÊÌâ,ÇëÓʼþÖÁK8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾PSIRTÓÊÏäsec@inspur.com£¬ÏêÇé²Î¿¼£º
/lcjtww/2312126/2432763/index.html
·þÎñÆ÷¡¢´æ´¢¡¢ÍøÂç²úÆ·¹ºÖÃÈÈÏߣº
ERP¡¢¹ÜÀíÈí¼þ¹ºÖÃÈÈÏߣº
ÔÆ·þÎñ²úÆ·ÏúÊÛÈÈÏߣº
K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÍøÂçÊÛºóÈÈÏߣº