¡¾Îó²îͨ¸æ¡¿SplunkÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-20229)

Ðû²¼Ê±¼ä 2025-03-27

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

SplunkÔ¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-20229

Îó²îÀàÐÍ

Ô¶³Ì´úÂëÖ´ÐÐ

·¢Ã÷ʱ¼ä

2025-03-27

Îó²îÆÀ·Ö

8.0

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Splunk EnterpriseÊÇÒ»¿îǿʢµÄÊý¾ÝÆÊÎöƽ̨£¬×¨×¢ÓÚ»úеÊý¾ÝµÄÍøÂç¡¢¼à¿ØºÍÆÊÎö£¬ÆÕ±éÓ¦ÓÃÓÚÈÕÖ¾ÖÎÀí¡¢Çå¾²ÐÅÏ¢ÊÂÎñÖÎÀí£¨SIEM£©ºÍITÔËά£¬Äܹ»×ÊÖú×é֯ʵʱ»ñÈ¡²Ù×÷Êý¾Ý¡¢¼ì²âÒì³£¡¢ÆÊÎöÇ÷ÊÆ£¬²¢Ìṩ¿ÉÊÓ»¯±¨±íºÍ¾¯±¨¹¦Ð§¡£Splunk Cloud PlatformÊÇSplunkµÄÔÆ°æ±¾£¬ÌṩÓëEnterpriseÏàͬµÄÊý¾ÝÆÊÎö¹¦Ð§£¬µ«ÒÔSaaSÐÎʽÔËÐУ¬Óû§ÎÞÐè×ÔÐÐÖÎÀí»ù´¡ÉèÊ©¡£ËüÊÊÓÃÓÚÐèÒª¸ß¶È¿ÉÀ©Õ¹ÐÔºÍÎÞаÐÔµÄÆóÒµ£¬Ö§³Ö¿çƽ̨¡¢¿çÇéÐεÄÊý¾ÝÆÊÎöºÍÖÎÀí£¬×ÊÖú×éÖ¯¸ßЧ´¦Öóͷ£´óÊý¾Ý£¬²¢ÊµÏÖÉîÈëµÄÖÇÄܶ´²ì¡£


2025Äê3ÔÂ27ÈÕ£¬×ðÁú¿­Ê±¼¯ÍÅVSRC¼à²âµ½SplunkÐû²¼µÄÇ徲ͨ¸æ£¬Í¨¸æÖ¸³öSplunk EnterpriseºÍSplunk Cloud Platform±£´æÒ»¸ö¸ßΣÎó²î¡£ÔÚÌØ¶¨°æ±¾ÖУ¬µÍȨÏÞÓû§£¨Î´³ÖÓÐ"admin"»ò"power"½ÇÉ«£©ÓÉÓÚȱ·¦ÐëÒªµÄÊÚȨ¼ì²é£¬¿ÉÄÜͨ¹ý½«ÎļþÉÏ´«ÖÁ¡°$SPLUNK_HOME/var/run/splunk/apptemp¡±Ä¿Â¼£¬´Ó¶øÖ´ÐÐÔ¶³Ì´úÂ루RCE£©¡£


¶þ¡¢Ó°Ïì¹æÄ£


9.3.2408.100 <= Splunk Cloud Platform <= 9.3.2408.103
9.2.2406.100 <= Splunk Cloud Platform <= 9.2.2406.107
Splunk Cloud Platform < 9.2.2403.113
Splunk Cloud Platform < 9.1.2312.207
9.3.0 <= Splunk Enterprise <= 9.3.2
9.2.0 <= Splunk Enterprise 9.2.4
9.1.0 <= Splunk Enterprise 9.1.7


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì¸üС£


Splunk Enterprise 9.4Éý¼¶µ½9.4.0
Splunk Enterprise 9.3ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.3.3
Splunk Enterprise 9.2ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.2.5
Splunk Enterprise 9.1ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.1.8
Splunk Cloud Platform 9.3.2408ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.3.2408.104
Splunk Cloud Platform 9.2.2406ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.2.2406.108
Splunk Cloud Platform 9.2.2403ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.2.2403.114
Splunk Cloud Platform 9.1.2312ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.1.2312.208


ÏÂÔØÁ´½Ó£ºhttps://www.splunk.com/en_us/download.html/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://advisory.splunk.com/advisories/SVD-2025-0301