¸ü¶à Ñ¡ÔñÓïÑÔ
< ·µ»ØÖ÷²Ëµ¥
Çå¾²Ô¤¾¯ - Éæ¼°K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾²¿·Ö²úÆ·µÄSaltStackÎó²îÇå¾²¸üÐÂ
Ô¤¾¯±àºÅ£ºINSPUR-SA-202011-001
³õʼÐû²¼Ê±¼ä£º2020-11-25 18:32:32
¸üÐÂÐû²¼Ê±¼ä£º2020-11-25 18:32:32
Îó²îȪԴ£º

saltstack¹Ù·½Åû¶

Îó²îÓ°Ï죺

¹¥»÷ÕßÀÖ³ÉʹÓÃÉÏÊöÎó²î¿ÉÈƹýÉí·ÝÑéÖ¤£¬ÊµÏÖÔ¶³Ì´úÂëÖ´Ðлò»ñȡϵͳÃô¸ÐÐÅÏ¢¡£

Îó²îÐÎò£º

CVE-2020-16846£ºÏÂÁî×¢ÈëÎó²î£¬Î´¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆÇëÇó°ü£¬¿Éͨ¹ý Salt API ×¢Èë ssh ÅþÁ¬ÏÂÁî¡£µ¼ÖÂÏÂÁîÖ´ÐÐ
CVE-2020-17490£ºÂß¼­Îó²î£¬Salt tlsÖ´ÐÐÄ£¿éÖк¯Êý create_ca£¬create_csrºÍcreate_self_signed_certÖб£´æÂß¼­Îó²î£¬ÍâµØ¹¥»÷Õßͨ¹ýÒÔµÍȨÏÞÓû§µÇ¼saltÖ÷»ú£¬¿ÉÒÔ´ÓÄ¿½ñsalt³ÌÐòÖ÷»úÉ϶ÁÈ¡µ½ÃÜÔ¿ÄÚÈÝ£¬µ¼ÖÂÐÅÏ¢×ß©¡£
CVE-2020-25592£ºÑéÖ¤ÈƹýÎó²î£¬SaltÔÚÑéÖ¤eauthƾ֤ºÍ»á¼û¿ØÖÆÁбíACLʱ±£´æÒ»´¦ÑéÖ¤ÈƹýÎó²î£¬Î´¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËÍÌØÖƵÄÇëÇó°ü£¬¿ÉÒÔͨ¹ýsalt-apiÈƹýÉí·ÝÑéÖ¤£¬²¢Ê¹Óà salt sshÅþÁ¬Ä¿µÄ·þÎñÆ÷£¬ÍŽáCVE-2020-16846¿ÉÄÜÔì³ÉÏÂÁîÖ´ÐС£

CVSSÆÀ·Ö£º

CVE V3.1 Vector(Base) Base Score V3.1 Vector(Temporal Score) Temporal Score
CVE-2020-16846 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 E:P/RL:O/RC:C 8.8
CVE-2020-17490 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 7.5 E:U/RL:O/RC:C 6.5
CVE-2020-25592 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 E:P/RL:O/RC:C 8.8

ÊÜÓ°Ïì²úÆ·£º

²úÆ·Ãû³Æ ÊÜÓ°Ïì²úÆ·°æ±¾ ÐÞ¸´²¹¶¡°ü/Éý¼¶°ü°æ±¾
AS13000 3.6.3.9 3.6.3.9:Salt-2015.8-AS13000--3.6.3.9-update.zip
AS13000 3.6.3.9-SP1
AS13000 3.6.3.9-SP2
AS13000 3.6.3.9-SP3
AS13000 3.6.3.9-SP4
AS13000 3.6.3.9-SP5
AS13000 3.4.3.7 3.4.3.6/7:salt-centos6-2015.8-AS13000-3.4.3.7-update.zip
AS13000 3.4.3.6

ÊÖÒÕϸ½Ú£º

CVE-2020-16846ºÍCVE-2020-25592×éºÏʹÓÿÉÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýsalt-api½Ó¿ÚÖ´ÐÐí§ÒâÏÂÁî¡£CVE-2020-25592ÔÊÐíí§ÒâÓû§Å²ÓÃSSHÄ£¿é£¬CVE-2020-16846ÔÊÐíÓû§Ö´ÐÐí§ÒâÏÂÁî¡£salt-apiËä²»ÊÇĬÈÏ¿ªÆôÉèÖ㬵«¾ø´ó´ó¶¼SaltStackÓû§»áÑ¡Ôñ¿ªÆôsalt-api£¬¹Ê±£´æ½Ï¸ßΣº¦¡£

Îó²î½â¾ö¼Æ»®£º

ÇëÓû§Ö±½ÓÁªÏµ¿Í»§·þÎñÖ°Ô±»ò·¢ËÍÓʼþÖÁsun.meng@inspur.com£¬»ñÈ¡²¹¶¡£¬ÒÔ¼°Ïà¹ØµÄÊÖÒÕЭÖú¡£

FAQ£º

ÎÞ

¸üмͼ£º

20201125-V1.0-Initial Release

K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Çå¾²Ó¦¼±ÏìÓ¦¶ÔÍâ·þÎñ£º
K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Ò»Ö±Ö÷Õž¡È«Á¦°ü¹Ü²úÆ·Óû§µÄ×îÖÕÀûÒ棬×ñÕÕÈÏÕæÈεÄÇå¾²ÊÂÎñÅû¶ԭÔò£¬²¢Í¨¹ý²úÆ·Çå¾²ÎÊÌâ´¦Öóͷ£»úÖÆ´¦Öóͷ£²úÆ·Çå¾²ÎÊÌâ¡£
·´ÏìK8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾²úÆ·Çå¾²ÎÊÌ⣺ /lcjtww/psirt/vulnerability-management/index.html#report_ldbg

»ñÈ¡ÊÖÒÕÖ§³Ö£º/lcjtww/2317452/2317456/2317460/index.html

ÉùÃ÷

±¾ÎĵµÌṩµÄËùÓÐÊý¾ÝºÍÐÅÏ¢½ö¹©²Î¿¼£¬ÇÒ"°´Ô­Ñù"Ìṩ£¬²»ÔÊÐíÈκÎÕÑʾ¡¢Ä¬Ê¾ºÍ·¨¶¨µÄµ£±££¬°üÀ¨(µ«²»ÏÞÓÚ)¶ÔÊÊÏúÐÔ¡¢ÊÊÓÃÐÔ¼°²»ÇÖȨµÄµ£±£¡£ÔÚÈκÎÇéÐÎÏ£¬K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾»òÆäÖ±½Ó»ò¼ä½Ó¿ØÖƵÄ×Ó¹«Ë¾£¬»òÆ乩ӦÉÌ£¬¾ù²î³ØÈκÎÒ»·½ÒòÒÀÀµ»òʹÓñ¾ÐÅÏ¢¶øÔâÊܵÄÈκÎËðʧ¼ç¸ºÔðÈΣ¬°üÀ¨Ö±½Ó£¬¼ä½Ó£¬ÎÞÒ⣬һ¶¨µÄÉÌÒµÀûÈóËðʧ»òÌØÊâËðʧ¡£K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾±£´æËæʱ¸ü¸Ä»ò¸üдËÎĵµµÄȨÁ¦¡£

ÔÚ
Ïß
¿Í
·þ
?
Áª
ϵ
ÎÒ
ÃÇ
¡Á
k8¡¤¿­·¢(Öйú)ÌìÉúÓ®¼Ò¡¤Ò»´¥¼´·¢ ÁªÏµK8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾
ERP¡¢ÆóÒµÈí¼þ¹ºÖÃÈÈÏß
400-018-7700
ÔÆ·þÎñ²úÆ·ÏúÊÛÈÈÏß
400-607-6657
¼¯ÍÅ¿Í»§Í¶ËßÈÈÏß
400-691-8711
ÖÇÄÜÖն˲úÆ·¿Í·þÈÈÏß
400-658-6111
ÍøÕ¾µØͼ