Apache Seata·´ÐòÁл¯Îó²îÀ´Ï®£¬£¬£¬£¬£¬ £¬ÈËÉú¾ÍÊDz©Ìṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2024-09-23

Apache Seata ÊÇÒ»¿î¿ªÔ´µÄÂþÑÜʽÊÂÎñ½â¾ö¼Æ»®£¬£¬£¬£¬£¬ £¬ÖÂÁ¦ÓÚÔÚ΢ЧÀͼܹ¹ÏÂÌṩ¸ßÐÔÄܺͼòÆÓÒ×ÓõÄÂþÑÜʽÊÂÎñЧÀÍ¡£ ¡£¡£¡£¡£


2024Äê9Ô£¬£¬£¬£¬£¬ £¬ÈËÉú¾ÍÊDz©¼à¿Øµ½Apache Seata ¹Ù·½Ðû²¼ÁËCVE-2024-22399 Apache Seata Hessian·´ÐòÁл¯Îó²î¡£ ¡£¡£¡£¡£¸ÃÎó²îCVSS3.1ÏÖÔÚÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬ £¬²¢ÇÒÆä×ÛºÏÆÀ¼¶Îª¡°³¬Î£¡±¡£ ¡£¡£¡£¡£


¾­Ñо¿È·¶¨£¬£¬£¬£¬£¬ £¬Apache Seata ÓÃÓÚЧÀͶËÓë¿Í»§¶ËͨѶµÄRPC ЭÒ飨ĬÈ϶˿ÚΪ8091£©ÒÔ¼°×Ô2.0.0 °æ±¾ÆðʵÏÖµÄRaft ЭÒéÐÂÎÅ£¬£¬£¬£¬£¬ £¬¾ùÖ§³Ö½ÓÄÉHessian ¾ÙÐÐÊý¾ÝµÄÐòÁл¯Óë·´ÐòÁл¯²Ù×÷¡£ ¡£¡£¡£¡£ÔÚ2.1.0 ¼°1.8.1 °æ±¾Ö®Ç°£¬£¬£¬£¬£¬ £¬SeataÔÚ´¦Öóͷ£RPC ÇëÇóʱ£¬£¬£¬£¬£¬ £¬¶ÔRPC ÐÂÎÅÌåÖеÄÐòÁл¯Êý¾ÝУÑé»úÖÆ²»·óÑϿᡣ ¡£¡£¡£¡£ÕâÒ»ÇéÐÎÖÂʹ¹¥»÷ÕßÄܹ»½á¹¹°üÀ¨¶ñÒâHessian ÐòÁл¯Êý¾ÝµÄÐÂÎÅÌ壬£¬£¬£¬£¬ £¬²¢·¢ËͶñÒâRPC ÇëÇ󣬣¬£¬£¬£¬ £¬×îÖÕ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ ¡£¡£¡£¡£ÈôÀÖ³ÉʹÓôËÎó²î£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÔòÓпÉÄÜÍêÈ«ÕÆ¿ØÊÜÓ°ÏìµÄϵͳ£¬£¬£¬£¬£¬ £¬ÆäÖаüÀ¨»ñÈ¡Ãô¸ÐÊý¾ÝµÄ»á¼ûȨÏÞ¡¢Ö´ÐÐí§ÒâÖ¸Á£¬£¬£¬£¬ £¬»òÕßÌᳫ½øÒ»²½µÄÍøÂç¹¥»÷ÐÐΪ¡£ ¡£¡£¡£¡£ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì½ÓÄÉ·À»¤²½·¥¡£ ¡£¡£¡£¡£


ͼƬ1.png


Îó²î¸´ÏÖ


ͼƬ2.jpg


Ó°Ïì°æ±¾


Apache Seata 2.0.0 °æ±¾

Apache Seata 1.0.0 ÖÁ 1.8.0 °æ±¾


½â¾ö¼Æ»®


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®


ÏÖÔÚ¹Ù·½ÒÑÓпɸüа汾£¬£¬£¬£¬£¬ £¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾:

Apache Seata 2.1.0/1.8.1

¹Ù·½ÏÂÔØµØµã£º

https://github.com/apache/incubator-seata/releases/tag/v2.1.0


¶þ¡¢ÈËÉú¾ÍÊDz©½â¾ö¼Æ»®


1¡¢ÈËÉú¾ÍÊDz©Öն˲úÆ·¼Æ»®


Ìì«‘ÖÕ¶ËÇå¾²Ò»Ì廯£¨EDR£©ÌṩÎó²îµÄרÏîÑéÖ¤¼ì²éÄÜÁ¦¶ÔÎó²îפÁôÖն˾ÙÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬£¬£¬£¬£¬ £¬Í¬Ê±Ìṩʵʱ¸æ¾¯Òì³£×Ó¸¸Àú³Ì£¬£¬£¬£¬£¬ £¬¼à¿ØÖ÷»úÒì³£ÍâÁ¬¼ì²â»ò·ÀÓùÄÜÁ¦£¬£¬£¬£¬£¬ £¬µÖÓùÎó²î¹¥»÷Σº¦¡£ ¡£¡£¡£¡£


ͼƬ3.jpg


2¡¢ÈËÉú¾ÍÊDz©¼ì²âÀà²úÆ·¼Æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½Ä¿½ñ×îа汾ÊÂÎñ¿â¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦£¬£¬£¬£¬£¬ £¬ÊÂÎñ¿âÏÂÔØµØµã£º

https://venustech.download.venuscloud.cn/


3¡¢ÈËÉú¾ÍÊDz©Â©É¨²úÆ·¼Æ»®


£¨1£©¡°ÈËÉú¾ÍÊDz©Îó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£ ¡£¡£¡£¡£


ͼƬ4.png


£¨2£©ÈËÉú¾ÍÊDz©Îó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£ ¡£¡£¡£¡£


ͼƬ5.png


4¡¢ÈËÉú¾ÍÊDz©×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨£¨ASM£©²úÆ·¼Æ»®


ÈËÉú¾ÍÊDz©×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬£¬£¬£¬£¬ £¬¶ÔÈë¿â×ʲúÎó²îApache Seata ·´ÐòÁл¯Îó²î£¨CVE-2024-22399£©¾ÙÐÐÖÎÀí¡£ ¡£¡£¡£¡£


ͼƬ6.png


5¡¢ÈËÉú¾ÍÊDz©Çå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬£¬£¬£¬ £¬¾ÙÐйØÁªÕ½ÂÔÉèÖ㬣¬£¬£¬£¬ £¬Á¬ÏµÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬£¬£¬£¬£¬ £¬´Ó¶ø·¢Ã÷¡°Apache Seata ·´ÐòÁл¯Îó²î£¨CVE-2024-22399£©¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£ ¡£¡£¡£¡£


£¨1£© ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬£¬£¬£¬ £¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Apache Seata ·´ÐòÁл¯Îó²î£¨CVE-2024-22399£©¡±Îó²îɨÃèʹÃü£¬£¬£¬£¬£¬ £¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú¡£ ¡£¡£¡£¡£


ͼƬ7.png


£¨2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿£¿£¿£¿£¿£¿éÖУ¬£¬£¬£¬£¬ £¬Ìí¼Ó¡°L2_Apache Seata ·´ÐòÁл¯Îó²î¡±£¬£¬£¬£¬£¬ £¬Í¨¹ýÈËÉú¾ÍÊDz©¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬£¬£¬£¬£¬ £¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ¡£ ¡£¡£¡£¡£


ͼƬ8.png


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_Apache Seata·´ÐòÁл¯Îó²î"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬£¬£¬£¬£¬ £¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓᣠ¡£¡£¡£¡£


£¨3£© Ìí¼Ó¡°L3_Apache Seata·´ÐòÁл¯Îó²î¡±£¬£¬£¬£¬£¬ £¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_Apache Seata ·´ÐòÁл¯Îó²î¡±£¬£¬£¬£¬£¬ £¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬£¬£¬£¬£¬ £¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬£¬£¬£¬£¬ £¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£ ¡£¡£¡£¡£


ͼƬ9.png


£¨4£©ATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé


ƾ֤¶ÔCVE-2024-22399Îó²îµÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬ £¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒս׶Σ¬£¬£¬£¬£¬ £¬ÁýÕÖµÄTTP°üÀ¨£º


TA0001³õʼ»á¼û£ºT1190ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò

TA0002Ö´ÐУºT1059ÏÂÁîºÍ¾ç±¾Ú¹ÊÍÆ÷

TA0004ÌáȨ£º T1068ʹÓÃÎó²îÌáÉýȨÏÞ

TA0009Êý¾ÝÍøÂ磺 T1005´ÓÍâµØÏµÍ³ÍøÂçÊý¾Ý


ͼƬ10.png


ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦£¬£¬£¬£¬£¬ £¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬£¬£¬£¬ £¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£ ¡£¡£¡£¡£