Apache SkywalkingÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2021-02-070x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-02-07 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache Skywalking < v8.4.0 |
0x01 Îó²îÏêÇé

Apache SkyWalkingÊÇÒ»¸ö¿ªÔ´Ó¦ÓÃÐÔÄÜ¼à¿ØÏµÍ³£¨APM£©£¬£¬£¬£¬£¬£¬ÆäÖ÷ÒªÕë¶Ô΢ЧÀÍ¡¢ÔÆÔÉúºÍÃæÏòÈÝÆ÷µÄϵͳ½á¹¹£¬£¬£¬£¬£¬£¬Ö§³ÖÖ¸±ê¼à¿Ø¡¢×·×Ù¡¢ÏµÍ³ÐÔÄÜÕï¶Ï¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
2021Äê02ÔÂ04ÈÕ£¬£¬£¬£¬£¬£¬Apache Skywalking¹Ù·½Ðû²¼8.4.0¸üÐÂͨ¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËSkywalkingÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚSkyWalkingÖеÄSQL×¢ÈëÎó²î£¨ÀúÊ·×·×ÙΪCVE-2020-9483ºÍCVE-2020-13921£©µÄÐÞ¸´²»·óÍêÉÆ£¬£¬£¬£¬£¬£¬ÈÔ±£´æÒ»¸öSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇóÀ´ÅÌÎÊÊý¾Ý¿âÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬»òͨ¹ýʹÓÃH2Êý¾Ý¿âÀ´Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬Í¨¹ýZoomEyeËÑË÷£¬£¬£¬£¬£¬£¬ÊܸÃÎó²îÓ°ÏìµÄÍøÕ¾ºÍ×°±¸¹²194546598¸ö£¬£¬£¬£¬£¬£¬ÆäÖÐÖйúÂþÑÜ24334598£¬£¬£¬£¬£¬£¬Î»¾ÓµÚ¶þ¡£¡£¡£¡£¡£¡£¡£

0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁApache Skywalking v8.4.0¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
http://skywalking.apache.org/downloads/
0x03 ²Î¿¼Á´½Ó
https://skywalking.apache.org/events/release-apache-skywalking-apm-8-4-0/
https://github.com/apache/skywalking/releases/tag/v8.4.0
0x04 ʱ¼äÏß
2021-02-04 SkyWalkingÍŶÓÐû²¼Ç徲ͨ¸æ
2021-02-07 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ