¡¾Îó²îͨ¸æ¡¿MongoDB zlib ѹËõÄÚ´æÐ¹Â¶Îó²î(CVE-2025-14847)
Ðû²¼Ê±¼ä 2025-12-29Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | MongoDB zlib ѹËõÄÚ´æÐ¹Â¶Îó²î | ||
CVE ID | CVE-2025-14847 | ||
Îó²îÀàÐÍ | ÐÅϢй¶ | ·¢Ã÷ʱ¼ä | 2025-12-29 |
Îó²îÆÀ·Ö | 8.7 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
MongoDBÊÇÒ»¸ö¿ªÔ´µÄNoSQLÊý¾Ý¿âÖÎÀíϵͳ£¬½ÓÄÉÎĵµµ¼Ïò´æ´¢·½·¨£¬ÒÔBSON£¨ÀàËÆJSON£©ÃûÌô洢Êý¾Ý¡£Ëü¾ßÓиßÀ©Õ¹ÐÔ¡¢ÎÞаµÄģʽÉè¼ÆºÍÓÅÒìµÄÐÔÄÜ£¬ÌØÊâÊÊÓÃÓÚ´¦Öóͷ£´ó¹æÄ£Êý¾ÝºÍ¶¯Ì¬×ª±äµÄÓ¦Óó¡¾°¡£MongoDBÖ§³ÖˮƽÀ©Õ¹£¬Í¨Ì«¹ýƬÊÖÒÕʵÏÖÊý¾ÝÂþÑÜ£¬ÊÊÓÃÓÚ´óÊý¾ÝÆÊÎö¡¢ÊµÊ±Êý¾Ý´¦Öóͷ£µÈÁìÓò¡£ÆäÎÞаµÄÊý¾Ý½á¹¹Ê¹ÆäÄܹ»¸ßЧ´¦Öóͷ£ÖØ´óµÄÅÌÎʺͶàÑù»¯µÄÓ¦ÓÃÐèÇó¡£
2025Äê12ÔÂ29ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½MongoDB ServerÖеÄÒ»¸ö¸ßΣÎó²î£¬Ô´ÓÚzlibѹËõÐÒéÍ·µÄ´¦Öóͷ£²»µ±£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏ´¥·¢Ô¶³ÌÄÚ´æÐ¹Â¶¡£¸ÃÎó²îÓ°Ïì¶à¸öMongoDB°æ±¾£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆµÄѹËõÊý¾Ý°ü£¬ÓÕʹ·þÎñÆ÷ÆÊÎöʱ·µ»ØÎ´³õʼ»¯µÄ¶ÑÄÚ´æ¡£ÕâЩδ³õʼ»¯µÄÄÚ´æÇøÓò¿ÉÄܰüÀ¨Ãô¸ÐÐÅÏ¢£¬ÈçÊý¾Ý¿âƾ֤¡¢Óû§Êý¾ÝµÈ¡£Îó²îÆÀ·Ö8.7·Ö£¬Îó²î¼¶±ð¸ßΣ¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/mongodb/mongo/tags/


¾©¹«Íø°²±¸11010802024551ºÅ