¡¾Îó²îͨ¸æ¡¿GitLabȨÏÞÈÆ¹ýÎó²î£¨CVE-2024-9164£©

Ðû²¼Ê±¼ä 2024-10-10


Ò»¡¢Îó²î¸ÅÊö

Îó²îÃû³Æ

 GitLabȨÏÞÈÆ¹ýÎó²î

CVE   ID

CVE-2024-9164

Îó²îÀàÐÍ

 ÈÏÖ¤/ȨÏÞÈÆ¹ý

·¢Ã÷ʱ¼ä

2024-10-10

Îó²îÆÀ·Ö

9.6

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷

 

GitLabÊÇÒ»¸öÓÃÓÚ¿ÍÕ»ÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿ £¬£¬£¬£¬£¬£¬ÆäʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß £¬£¬£¬£¬£¬£¬¿Éͨ¹ýWeb½çÃæ»á¼û¹ûÕæ»ò˽ÈËÏîÄ¿¡£¡£¡£¡£¡£

2024Äê10ÔÂ10ÈÕ £¬£¬£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨¼¯ÍÅVSRC¼à²âµ½GitLabÆóÒµ°æ£¨EE£©ÖÐÐÞ¸´ÁËÒ»¸öȨÏÞÈÆ¹ýÎó²î£¨CVE-2024-9164£© £¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.6 £¬£¬£¬£¬£¬£¬ÍþвÕß¿ÉʹÓøÃÎó²îÔÚí§Òâ·ÖÖ§ÉÏÔËÐÐGitLabµÄCI/CD¹ÜµÀ £¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÖ´ÐÐδÊÚȨ´úÂë¡¢Êý¾Ýй¶µÈ¡£¡£¡£¡£¡£

±ðµÄ £¬£¬£¬£¬£¬£¬GitLab CE/EEÖл¹ÐÞ¸´ÁËÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-8970 £¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö8.2£© £¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÍþвÕßÔÚijЩÇéÐÎÏÂÒÔÆäËûÓû§µÄÉí·Ý´¥·¢¹ÜµÀ£»£» £»£»£»ÒÔ¼°ÐÞ¸´ÁËGitLab EEÖеÄÒ»¸öЧÀÍÆ÷¶ËÇëÇóαÔìÎó²î£¨CVE-2024-8977 £¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö8.2£© £¬£¬£¬£¬£¬£¬µ±GitLab EEʵÀýÉèÖò¢ÆôÓÃÁ˲úÆ·ÆÊÎöÒDZí°åʱÈÝÒ×Êܵ½SSRF¹¥»÷ £¬£¬£¬£¬£¬£¬ÍþвÕß¿ÉʹÓøÃÎó²î»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÆäËû¶ñÒâ²Ù×÷¡£¡£¡£¡£¡£

 

¶þ¡¢Ó°Ïì¹æÄ£

CVE-2024-9164

12.5 <= GitLab EE < 17.2.9

17.3 <= GitLab EE < 17.3.5

17.4 <= GitLab EE < 17.4.2

CVE-2024-8970

11.6 <= GitLab CE/EE < 17.2.9

17.3 <= GitLab CE/EE< 17.3.5

17.4 <= GitLab CE/EE < 17.4.2

CVE-2024-8977

15.10 <= GitLab EE < 17.2.9

17.3 <= GitLab EE < 17.3.5

17.4 <= GitLab EE < 17.4.2

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´ £¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½GitLab CE/EE 17.4.2¡¢17.3.5¡¢17.2.9»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://about.gitlab.com/

3.2 ÔÝʱ²½·¥

ÔÝÎÞ¡£¡£¡£¡£¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î £¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://about.gitlab.com/releases/2024/10/09/patch-release-gitlab-17-4-2-released/

https://nvd.nist.gov/vuln/detail/CVE-2024-9164

  

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-10-10

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 c7c7ÓéÀÖÆ½Ì¨¼ò½é

c7c7ÓéÀÖÆ½Ì¨½¨ÉèÓÚ1996Äê £¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°c7c7ÓéÀÖÆ½Ì¨´óÏà £¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬£¬£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ £¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ £¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

5.2 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨

c7c7ÓéÀÖÆ½Ì¨Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯ £¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î £¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png