SaltStack | RECÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-03

0x00 Îó²î¸ÅÊö


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



0x01 Îó²îÏêÇé


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



SaltStack Salt£¨ÓÖÃûSaltStack£©ÊÇÃÀ¹úSaltStack¹«Ë¾µÄÒ»Ì׿ªÔ´µÄÓÃÓÚÖÎÀí»ù´¡¼Ü¹¹µÄ¹¤¾ß¡£¡£¡£¡£


CVE-2020-11651ÊÇÈÏÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚSalt MasterÀú³ÌÖÐClearFuncsÀàÎÞ·¨×¼È·ÊµÏÖÒªÁìŲÓà £¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇó £¬£¬£¬£¬£¬ÈƹýSalt MasterµÄÑéÖ¤Âß¼­ £¬£¬£¬£¬£¬Å²ÓÃÏà¹ØÎ´ÊÚȨº¯Êý¹¦Ð§ £¬£¬£¬£¬£¬Ôì³ÉÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£


CVE-2020-11652ÊÇĿ¼±éÀúÎó²î¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚSalt MasterÀú³ÌÖÐClearFuncsÀàÔÊÐí»á¼ûijЩ²»×¼È·µÄsanitize pathsÒªÁì¡£¡£¡£¡£ ÕâЩҪÁìÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¾ÙÐÐí§ÒâĿ¼»á¼û¡£¡£¡£¡£µ¼Ö¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇó £¬£¬£¬£¬£¬¶ÁȡЧÀÍÆ÷ÉÏí§ÒâÎļþ £¬£¬£¬£¬£¬²¢»ñȡϵͳÃô¸ÐÐÅÏ¢¡£¡£¡£¡£


Óû§¿ÉÔËÐÐsalt¡ªversion È·ÈÏSaltStackµÄ°æ±¾ÊÇ·ñÓÐÓ°Ïì £¬£¬£¬£¬£¬É¨Ã軥ÁªÍø·¢Ã÷ÏÖÔÚÓÐ6000¸ö¿É¹ûÕæ»á¼ûµÄSaltStack £¬£¬£¬£¬£¬Í¬Ê±·¢Ã÷ʹÓøÃÎó²îµÄ¹¥»÷ÐÐΪ £¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±ÐÞ¸´¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


¡ñ Éý¼¶µ½×îа汾 £¬£¬£¬£¬£¬Éý¼¶Ç°½¨Òé×öºÃ±¸·Ý£»£»£»

¡ñ ¿ÉÉèÖÃSaltStackΪ×Ô¶¯¸üУ»£»£»

¡ñ ·À»ðǽÉÏÉèÖÃ×è¶ÏSaltStackЧÀ͵Ä4505ºÍ4506¶Ë¿Ú¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.securityweek.com/critical-vulnerability-salt-requires-immediate-patching


0x04 ²Î¿¼Á´½Ó


https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst

https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html

https://labs.f-secure.com/advisories/saltstack-authorization-bypass

https://www.suse.com/support/kb/doc/?id=000019619


0x05 ʱ¼äÏß


2020-05-03 VSRCÐû²¼Îó²îͨ¸æ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø