SaltStack | RECÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-05-030x00 Îó²î¸ÅÊö

0x01 Îó²îÏêÇé
SaltStack Salt£¨ÓÖÃûSaltStack£©ÊÇÃÀ¹úSaltStack¹«Ë¾µÄÒ»Ì׿ªÔ´µÄÓÃÓÚÖÎÀí»ù´¡¼Ü¹¹µÄ¹¤¾ß¡£
CVE-2020-11651ÊÇÈÏÖ¤ÈÆ¹ýÎó²î¡£¸ÃÎó²îÔ´ÓÚSalt MasterÀú³ÌÖÐClearFuncsÀàÎÞ·¨×¼È·ÊµÏÖÒªÁìŲÓ㬵¼Ö¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇó£¬ÈƹýSalt MasterµÄÑéÖ¤Âß¼£¬Å²ÓÃÏà¹ØÎ´ÊÚȨº¯Êý¹¦Ð§£¬Ôì³ÉÔ¶³ÌÏÂÁîÖ´ÐС£
CVE-2020-11652ÊÇĿ¼±éÀúÎó²î¡£¸ÃÎó²îÔ´ÓÚSalt MasterÀú³ÌÖÐClearFuncsÀàÔÊÐí»á¼ûijЩ²»×¼È·µÄsanitize pathsÒªÁì¡£ ÕâЩҪÁìÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÓû§¾ÙÐÐí§ÒâĿ¼»á¼û¡£µ¼Ö¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇ󣬶ÁÈ¡·þÎñÆ÷ÉÏí§ÒâÎļþ£¬²¢»ñȡϵͳÃô¸ÐÐÅÏ¢¡£
Óû§¿ÉÔËÐÐsalt¡ªversion È·ÈÏSaltStackµÄ°æ±¾ÊÇ·ñÓÐÓ°Ï죬ɨÃ軥ÁªÍø·¢Ã÷ÏÖÔÚÓÐ6000¸ö¿É¹ûÕæ»á¼ûµÄSaltStack£¬Í¬Ê±·¢Ã÷ʹÓøÃÎó²îµÄ¹¥»÷ÐÐΪ£¬½¨ÒéÓû§ÊµÊ±ÐÞ¸´¡£
0x02 ´¦Öóͷ£½¨Òé
¡ñ Éý¼¶µ½×îа汾£¬Éý¼¶Ç°½¨Òé×öºÃ±¸·Ý£»
¡ñ ¿ÉÉèÖÃSaltStackΪ×Ô¶¯¸üУ»
¡ñ ·À»ðǽÉÏÉèÖÃ×è¶ÏSaltStack·þÎñµÄ4505ºÍ4506¶Ë¿Ú¡£
0x03 Ïà¹ØÐÂÎÅ
https://www.securityweek.com/critical-vulnerability-salt-requires-immediate-patching
0x04 ²Î¿¼Á´½Ó
https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
https://labs.f-secure.com/advisories/saltstack-authorization-bypass
https://www.suse.com/support/kb/doc/?id=000019619
0x05 ʱ¼äÏß
2020-05-03 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ