Puppet EnterpriseĬÈÏÃÜÂëÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-05

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10694£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.4£¬ £¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚPuppet Enterprise 2019.0.3֮ǰ°æ±¾¡£¡£¡£


Îó²î¸ÅÊö


PuppetÊÇ¿ªÔ´µÄ»ùÓÚRubyµÄϵͳÉèÖÃÖÎÀí¹¤¾ß£¬ £¬£¬£¬£¬»ùÓÚC/SµÄ°²Åżܹ¹¡£¡£¡£ÊÇÒ»¸öΪʵÏÖÊý¾ÝÖÐÐÄ×Ô¶¯»¯ÖÎÀí¶øÉè¼ÆµÄÉèÖÃÖÎÀíÈí¼þ£¬ £¬£¬£¬£¬ËüʹÓÃ¿çÆ½Ì¨ÓïÑԹ淶£¬ £¬£¬£¬£¬ÖÎÀíÉèÖÃÎļþ¡¢Óû§¡¢Èí¼þ°ü¡¢ÏµÍ³Ð§À͵È¡£¡£¡£¿ £¿£¿Í»§¶ËĬÈÏÿ¸ô°ëСʱ»áºÍЧÀÍÆ÷ͨѶһ´Î£¬ £¬£¬£¬£¬È·ÈÏÊÇ·ñÓиüС£¡£¡£ËäȻҲ¿ÉÒÔÉèÖÃ×Ô¶¯´¥·¢À´Ç¿Öƿͻ§¶Ë¸üС£¡£¡£ÕâÑù¾Í°ÑÒ»Ñùƽ³£µÄϵͳÖÎÀíʹÃü´úÂ뻯ÁË£¬ £¬£¬£¬£¬´úÂ뻯µÄÀûÒæÊÇ¿ÉÒÔ·ÖÏí£¬ £¬£¬£¬£¬ÉúÑÄ£¬ £¬£¬£¬£¬×èÖ¹ÖØ¸´ÀͶ¯£¬ £¬£¬£¬£¬Ò²¿ÉÒÔ¿ìËÙ»Ö¸´ÒÔ¼°¿ìËٵĴó¹æÄ£°²ÅÅЧÀÍÆ÷¡£¡£¡£Puppet EnterpriseÊÇPuppetµÄÆóÒµ°æ¡£¡£¡£


Puppet Enterprise 2019.0.3֮ǰ°æ±¾Öб£´æÄ¬ÈÏÃÜÂëÎó²î£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÈÆ¹ýÏÞÖÆ£¬ £¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£


¾Ýͳ¼Æ£¬ £¬£¬£¬£¬Öйú̻¶ÔÚ¹«ÍøÉϵÄPuppet´ï3000¶à¸ö£¬ £¬£¬£¬£¬ÏêϸÂþÑÜÇéÐÎÈçÏ£º

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬ £¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://puppet.com/security/cve/CVE-2019-10694


²Î¿¼Á´½Ó


https://puppet.com/security/cve/CVE-2019-10694