ÓÉÍâÑóijÇå¾²ÍŶӹûÕæÅû¶
¹¥»÷ÕßÀÖ³ÉʹÓÃÉÏÊöÎó²î¿ÉʵÏÖδÊÚȨ»á¼û¡¢Ô¶³Ì´úÂëÖ´ÐС£
CVE-2021-25281
salt-apiδУÑéwheel_async¿Í»§¶ËµÄeauthƾ֤£¬ÊÜ´ËÎó²îÓ°Ïì¹¥»÷Õß¿ÉÔ¶³ÌŲÓÃmasterÉÏí§ÒâwheelÄ£¿é¡£
CVE-2021-25282
salt.wheel.pillar_roots.write ÒªÁì±£´æĿ¼´©Ô½Îó²î¡£
CVE-2021-25283
ÄÚÖÃJinjaäÖȾÒýÇæ±£´æSSTI£¨Server Side Template Injection£¬·þÎñ¶ËÄ£°å×¢È룩Îó²î¡£
CVE-2021-25284
webutils½«Ã÷ÎÄÃÜÂëдÈë/var/log/salt/minionSalt¡£Ä¬ÈÏÉèÖÃÖв»±£´æ´ËÎÊÌâ¡£
CVE-2021-3197
Salt-APIµÄSSH¿Í»§¶ËÈÝÒ×Êܵ½Shell×¢ÈëµÄ¹¥»÷£¬ÒªÁìÊÇÔÚ²ÎÊýÖаüÀ¨ProxyCommand»òͨ¹ýAPIÇëÇóÖÐÌṩµÄssh_options¡£´ËÄ£¿éÔÚĬÈÏÇéÐÎÏÂδÔËÐС£
CVE-2021-3148
salt.utils.thin.gen_thin() Öб£´æÏÂÁî×¢È롣ͨ¹ýSaltAPI£¬´ÓÃûÌû¯µÄ×Ö·û´®½á¹¹ÏÂÁÈôÊÇ extra_mods ÖÐÓе¥ÒýºÅ£¬Ôò¿ÉÒÔ½«ÏÂÁî½Ø¶Ï£¬ÓÉÓÚjson.dumps() »áתÒåË«ÒýºÅ£¬Í¬Ê±¼á³Öµ¥ÒýºÅÎȹ̡£
CVE-2020-35662
ĬÈÏÇéÐÎÏ£¬Salt±£´æ²»ÑéÖ¤SSLÖ¤ÊéµÄ¼¸¸öµØ·½¡£
CVE-2021-3144
eauthÁîÅÆÔÚÓâÆÚºóÈÔ¿ÉÒÔʹÓÃÒ»´Î¡£
CVE-2020-28972
ȱÉÙ¶ÔSSLÖ¤ÊéµÄÑéÖ¤£¬´úÂë¿âÎÞ·¨ÑéÖ¤·þÎñÆ÷µÄSSL/TLSÖ¤Ê飬Õâ¿ÉÄÜʹ¹¥»÷Õß¿ÉÒÔͨ¹ýÖÐÐÄÈ˹¥»÷»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
CVE-2020-28243
MinionÖеÄÍâµØÌØȨÌáÉýÎó²î£¬µ±ÎÞÌØȨµÄÓû§Äܹ»Í¨¹ýÀú³ÌÃû³ÆÖеÄÏÂÁî×¢Èë¶øÄܹ»ÔÚÈκÎδÁÐÈëºÚÃûµ¥µÄĿ¼Öн¨ÉèÎļþʱ£¬SaltStackµÄMinion¿ÉÒÔ¾ÙÐÐÌØȨÉý¼¶¡£
CVSSÆÀ·Ö£º
CVE | V3.1 Vector(Base) | Base Score | V3.1 Vector(Temporal Score) | Temporal Score |
CVE-2021-25281 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:P/RL:O/RC:C | 8.8 |
CVE-2021-25282 | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H | 9.1 | E:P/RL:O/RC:C | 8.2 |
CVE-2021-25283 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:P/RL:O/RC:C | 8.8 |
CVE-2021-25284 | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N | 4.4 | E:U/RL:O/RC:C | 3.9 |
CVE-2021-3197 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:U/RL:O/RC:C | 8.5 |
CVE-2021-3148 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | E:U/RL:O/RC:C | 8.5 |
CVE-2020-35662 | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N | 7.4 | E:U/RL:O/RC:C | 6.4 |
CVE-2021-3144 | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H | 9.1 | E:U/RL:O/RC:C | 7.9 |
CVE-2020-28972 | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | 5.9 | E:U/RL:O/RC:C | 5.2 |
CVE-2020-28243 | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 7.8 | E:U/RL:O/RC:C | 6.8 |
ÊÜÓ°Ïì²úÆ·£º
²úÆ·Ãû³Æ | ÊÜÓ°Ïì²úÆ·°æ±¾ | ÐÞ¸´²¹¶¡°ü/Éý¼¶°ü°æ±¾ |
AS13000 | 3.6.3.9 | 3.6.3.9:Salt-2015.8-AS13000--3.6.3.9-update.zip |
AS13000 | 3.6.3.9-SP1 | |
AS13000 | 3.6.3.9-SP2 | |
AS13000 | 3.6.3.9-SP3 | |
AS13000 | 3.6.3.9-SP4 | |
AS13000 | 3.6.3.9-SP5 | |
AS13000 | 3.4.3.7 | 3.4.3.6/7: salt-centos6-2015.8-AS13000-3.4.3.7-update.zip |
¹¥»÷Õßͨ¹ý×éºÏCVE-2021-25281¡¢CVE-2021-25282¡¢CVE-2021-25283¹¥»÷£¬¿ÉÒÔµÖ´ïÎÞÐèµÇ¼ʵÏÖÔ¶³ÌÏÂÁîÖ´ÐеÄЧ¹û¡£
Îó²î½â¾ö¼Æ»®£ºÇëÓû§Ö±½ÓÁªÏµ¿Í»§·þÎñÖ°Ô±»ò·¢ËÍÓʼþÖÁsun.meng@inspur.com£¬»ñÈ¡²¹¶¡£¬ÒÔ¼°Ïà¹ØµÄÊÖÒÕÐÖú¡£
˵Ã÷£ºÉý¼¶²¹¶¡°ü¶Ô´æ´¢ÓªÒµÎÞÓ°Ïì
ÎÞ
¸üмͼ£º20210323-V1.0-Initial Release
ºÀÔ˹ú¼ÊÇå¾²Ó¦¼±ÏìÓ¦¶ÔÍâ·þÎñ£º»ñÈ¡ÊÖÒÕÖ§³Ö£º/lcjtww/2317452/2317456/2317460/index.html
±¾ÎĵµÌṩµÄËùÓÐÊý¾ÝºÍÐÅÏ¢½ö¹©²Î¿¼£¬ÇÒ"°´ÔÑù"Ìṩ£¬²»ÔÊÐíÈκÎÕÑʾ¡¢Ä¬Ê¾ºÍ·¨¶¨µÄµ£±££¬°üÀ¨(µ«²»ÏÞÓÚ)¶ÔÊÊÏúÐÔ¡¢ÊÊÓÃÐÔ¼°²»ÇÖȨµÄµ£±£¡£ÔÚÈκÎÇéÐÎÏ£¬ºÀÔ˹ú¼Ê»òÆäÖ±½Ó»ò¼ä½Ó¿ØÖƵÄ×Ó¹«Ë¾£¬»òÆ乩ӦÉÌ£¬¾ù²î³ØÈκÎÒ»·½ÒòÒÀÀµ»òʹÓñ¾ÐÅÏ¢¶øÔâÊܵÄÈκÎËðʧ¼ç¸ºÔðÈΣ¬°üÀ¨Ö±½Ó£¬¼ä½Ó£¬ÎÞÒ⣬һ¶¨µÄÉÌÒµÀûÈóËðʧ»òÌØÊâËðʧ¡£ºÀÔ˹ú¼Ê±£´æËæʱ¸ü¸Ä»ò¸üдËÎĵµµÄȨÁ¦¡£