¡¾Îó²îͨ¸æ¡¿Splunk Enterprise 2Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2023-02-160x00 Îó²î¸ÅÊö
Splunk EnterpriseÊÇÒ»¿îרҵµÄÊý¾ÝÆÊÎöÈí¼þ£¬£¬£¬£¬£¬Äܹ»¶Ô²ÉÑùµÄÊý¾ÝÒÔ¼°Í³¼ÆÍ¼×ö³öרҵÆÊÎö£¬£¬£¬£¬£¬Ö§³Ö¿çƽ̨ʹÓ㬣¬£¬£¬£¬³£ÓÃÓÚ½ðÈÚ¡¢IT¡¢²ÆÎñµÈ¶à¸öÁìÓò¡£¡£
2023Äê2ÔÂ14ÈÕ£¬£¬£¬£¬£¬SplunkÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÁËÓ°ÏìSplunk EnterpriseµÄ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ÕâЩÎó²î¿ÉÄܵ¼ÖÂÇå¾²ÈÆ¹ý»ò¿çÕ¾¾ç±¾£¨XSS£©¹¥»÷µÈ¡£¡£
0x01 Îó²îÏêÇé
±¾´ÎÐÞ¸´µÄ²¿·Ö¸ßΣÎó²î°üÀ¨£º
CVE | ÆÀ·Ö | ˵Ã÷ | Ó°Ïì¹æÄ£ | ÐÞ¸´°æ±¾ |
CVE-2023-22939 | 8.1 | Splunk EnterpriseÖÐͨ¹ý'map'SPLÏÂÁîÈÆ¹ýSPL±£»£»£»£»¤²½·¥¡£¡£¸ÃÎó²îÐèÒª¸ü¸ßȨÏÞµÄÓû§ÔÚÆää¯ÀÀÆ÷ÖÐÌᳫÇëÇ󣬣¬£¬£¬£¬²¢ÇÒ½öÓ°ÏìÆôÓÃÁË Splunk Web µÄʵÀý¡£¡£ | Splunk Enterprise£¨Splunk Web£© <= 8.1.12¡¢8.2.0 - 8.2.9¡¢9.0.0 - 9.0.3£»£»£»£»Splunk Cloud Platform<= 9.2.2209 | Splunk Enterprise£ºÉý¼¶µ½ 8.1.13¡¢8.2.10¡¢9.0.4 »ò¸ü¸ß°æ±¾£»£»£»£»Splunk Cloud Platform£ºÉý¼¶µ½9.2.2209.3¡£¡£ |
CVE-2023-22935 | 8.1 | Splunk EnterpriseÖÐͨ¹ý"display.page.search.patterns.sensitivity "ËÑË÷²ÎÊýÈÆ¹ýSPL±£»£»£»£»¤²½·¥¡£¡£¸ÃÎó²îÐèÒª¸ü¸ßȨÏÞµÄÓû§ÔÚÆää¯ÀÀÆ÷ÖÐÌᳫÇëÇ󣬣¬£¬£¬£¬²¢ÇÒ½öÓ°ÏìÆôÓÃÁË Splunk Web µÄʵÀý¡£¡£ | ||
CVE-2023-22934 | 7.3 | Splunk EnterpriseÖÐͨ¹ý'pivot'SPLÏÂÁîÈÆ¹ýSPL±£»£»£»£»¤²½·¥¡£¡£¸ÃÎó²îÐèÒª¾ÓÉÉí·ÝÑéÖ¤µÄÓû§ÖÆ×÷ÉúÑĵÄ×÷Òµ£¬£¬£¬£¬£¬²¢ÐèÒª¸ü¸ßȨÏÞµÄÓû§ÔÚÆää¯ÀÀÆ÷ÖÐÌᳫÇëÇ󡣡£¸ÃÎó²îÓ°ÏìÆôÓÃÁË Splunk Web µÄʵÀý¡£¡£ | ||
CVE-2023-22933 | 8.0 | ÔÚSplunk EnterpriseÖÐͨ¹ý'Ä£¿£¿£¿£¿é'±êÇ©ÖеÄ'layoutPanel'ÊôÐÔÒÔ¿ÉÀ©Õ¹±ê¼ÇÓïÑÔ£¨XML£©ÊÓͼ¾ÙÐпçÕ¾µã¾ç±¾£¨XSS£©¹¥»÷¡£¡£¸ÃÎó²îÓ°ÏìÆôÓÃÁËSplunk WebµÄʵÀý¡£¡£ | Splunk Enterprise£¨Splunk Web£© <= 8.1.12¡¢8.2.0 - 8.2.9¡¢9.0.0 - 9.0.3£»£»£»£»Splunk Cloud Platform<= 9.0.2208 | Splunk Enterprise£ºÉý¼¶µ½ 8.1.13¡¢8.2.10¡¢9.0.4 »ò¸ü¸ß°æ±¾£»£»£»£»Splunk Cloud Platform£ºÉý¼¶µ½9.0.2209¡£¡£ |
CVE-2023-22932 | 8.0 | ͨ¹ýSplunk EnterpriseÊÓͼÖÐBase64±àÂëµÄͼÏñÖеĹýʧÐÅÏ¢¾ÙÐпçÍøÕ¾¾ç±¾£¨XSS£©£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÆôÓÃÁË Splunk Web µÄʵÀý¡£¡£ | Splunk Enterprise£¨Splunk Web£©9.0.0 - 9.0.3£»£»£»£»Splunk Cloud Platform<= 9.0.2209 | Splunk EnterpriseºÍSplunk Cloud Platform£ºÉý¼¶µ½9.0.2209.3¡£¡£ ×¢£º¸ÃÎó²î²»Ó°ÏìSplunk Enterprise 9.0֮ǰµÄ°æ±¾¡£¡£ |
Splunk»¹Õë¶Ô Splunk Enterprise ÖеĶàÆäÖÐΣÎó²îÐû²¼Á˲¹¶¡£¬£¬£¬£¬£¬ÆäÖÐһЩÎó²î¿ÉÄܵ¼ÖÂÐÅϢй¶¡¢ÒÔ Splunk ʵÀýÉí·Ý·¢Ë͵ç×ÓÓʼþ¡¢ÉÏ´«´øÓв»ÐëÒªÎļþÀ©Õ¹ÃûµÄ²éÕÒ±íÒÔ¼°Ð§ÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©µÈ¡£¡£
±ðµÄ£¬£¬£¬£¬£¬Splunk»¹Õë¶ÔSplunk EnterpriseµÚÈý·½¿âÖеĶà¸öÎó²îÐû²¼Á˲¹¶¡£¬£¬£¬£¬£¬ÆäÖнÏΪÑÏÖØµÄÎó²î°üÀ¨llibxml2ÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-3518£¬£¬£¬£¬£¬CVSSÆÀ·Ö8.8£©ºÍllibxml2ÖеÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-3517£¬£¬£¬£¬£¬CVSSÆÀ·Ö8.6£©£¬£¬£¬£¬£¬ÕâЩÎó²î¿ÉÄÜ»áÓ°ÏìÓ¦ÓóÌÐòµÄ¿ÉÓÃÐÔ¡¢ÉñÃØÐÔºÍÍêÕûÐÔ¡£¡£
Splunk»¹ÐÞ¸´Á˵ÚÈý·½¿âNode.jsÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2022-32212£¬£¬£¬£¬£¬CVSSÆÀ·Ö8.1£©£¬£¬£¬£¬£¬ÒÔ¼°Moment.jsÖеÄ·¾¶±éÀúÎó²î£¨CVE-2022-24785 £¬£¬£¬£¬£¬CVSSÆÀ·Ö7.5£©ºÍµÍЧÆÊÎöËã·¨ÎÊÌ⣨CVE-2022-31129£¬£¬£¬£¬£¬CVSSÆÀ·Ö7.5£©£¬£¬£¬£¬£¬ºóÕß¿ÉÄܵ¼ÖÂ(Re)DoS ¹¥»÷¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉʵʱÉý¼¶µ½ÏìÓ¦ÐÞ¸´°æ±¾¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.splunk.com/
0x03 ²Î¿¼Á´½Ó
https://advisory.splunk.com/advisories
https://nvd.nist.gov/vuln/detail/CVE-2023-22939
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2023-02-16 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
ÈËÉú¾ÍÊDz©¼ò½é
ÈËÉú¾ÍÊDz©½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÈËÉú¾ÍÊDz©´óÏ㬣¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬ÈËÉú¾ÍÊDz©ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£
¹ØÓÚÈËÉú¾ÍÊDz©
ÈËÉú¾ÍÊDz©Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ