CVE-2020-11710| Kong Admin Rest APIδÊÚȨ»á¼ûÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-160x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-11710 |
ʱ ¼ä |
2020-04-16 |
|
Àà ÐÍ |
UA |
µÈ ¼¶ |
ÑÏÖØ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
Kong <= 2.0.3 |
0x01 Îó²îÏêÇé
docker-kongÊÇÒ»¿îʹÓÃÔÚDockerÓ¦ÓÃÈÝÆ÷ÒýÇæÖеÄAPI3Íø¹Ø²úÆ·¡£¡£¡£¡£¡£¡£¡£¡£Kong APIÍø¹ØÊÇÏÖÔÚ×îÊܽӴýµÄÔÆÔÉúAPIÍø¹ØÖ®Ò»£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý²å¼þµÄÐÎʽÌṩ¸ºÔØÆ½ºâµÈ¶àÖØ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£
Kong APIÍø¹ØÔÚĬÈÏDocker°²ÅŵÄÇéÐÎϱ£´æÎ´ÊÚȨ»á¼ûÎó²î£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£¡£ÔÚʹÓÃDockerÈÝÆ÷µÄ·½·¨´î½¨Kong APIÍø¹ØÊ±£¬£¬£¬£¬£¬£¬£¬£¬Ä¬ÈÏÉèÖûὫδ¾¼øÈ¨µÄAdmin Rest API̻¶ÔÚ¹«Íø£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔδÊÚȨ»á¼ûAdmin Rest API£¬£¬£¬£¬£¬£¬£¬£¬½øÒ»²½¿ØÖÆKong APIÍø¹Ø¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
Éý¼¶²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://github.com/Kong/docker-kong/commit/dfa095cadf7e8309155be51982d8720daf32e31c
ÔÝʱ²½·¥£º
? ½«Kong Admin APIĬÈϼàÌý¶Ë¿Ú£¨Ä¬ÈÏ8001ºÍ8444£©ÉèΪեȡ¶Ô¹«Íø¿ª·Å£¬£¬£¬£¬£¬£¬£¬£¬»ò½ö¶Ô¿ÉÐŹ¤¾ß¿ª·Å£»£»£»£»£»£»
? ÐÞ¸Ä docker-compose.yaml ÖеÄÄÚÈݽ«¶Ë¿ÚÓ³ÉäÏÞÖÆÎª 127.0.0.1¡£¡£¡£¡£¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-11710
0x04 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2020-11710
https://github.com/Kong/kong
0x05 ʱ¼äÏß
2020-03-31 KongÐÞ¸´¸ÃÎó²î
2020-04-12 CVE Ðû²¼¸ÃÎó²î


¾©¹«Íø°²±¸11010802024551ºÅ