Saltstack | ¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-11-040x00 Îó²î¸ÅÊö
²úÆ· | CVE ID | Àà ÐÍ | Îó²îÆ·¼¶ | Ô¶³ÌʹÓà | Ó°Ïì¹æÄ£ |
Saltstack | CVE-2020-16846 | ÏÂÁî×¢Èë | ¸ßΣ | ÊÇ | SaltStack < 3002.1 SaltStack < 3001.3 SaltStack < 3000.5 SaltStack < 2019.2.7
|
CVE-2020-25592 | ÑéÖ¤ÈÆ¹ý | ¸ßΣ | ÊÇ | ||
CVE-2020-17490 | Âß¼Îó²î | µÍΣ | ÊÇ |
0x01 Îó²îÏêÇé
SaltStackÊÇPythonÓïÑÔ±àдµÄ¿ªÔ´IT»ù´¡¼Ü¹¹½â¾ö¼Æ»®£¬£¬£¬ÏÖÒѱ»È«ÌìϵÄÊý¾ÝÖÐÐÄÆÕ±éʹÓᣡ£¡£¡£¡£
2020Äê11ÔÂ03ÈÕ£¬£¬£¬SaltStackÐû²¼Çå¾²¸üУ¬£¬£¬±¾´Î¸üй²ÐÞ¸´ÁËÈý¸öÒªº¦Îó²î£¬£¬£¬ÏêÇéÈçÏ£º
SaltStackÏÂÁî×¢ÈëÎó²î£¨CVE-2020-16846£©
¾ßÓÐSalt APIÍøÂç»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓÃSSH¿Í»§¶Ëͨ¹ýSalt API¾ÙÐÐShell×¢Èë¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÔÚSalt APIÉÏÔËÐдúÂë¡£¡£¡£¡£¡£¸ÃÎó²î¿Éͨ¹ýÔÚŲÓá°subprocess¡±Ê±É¾³ý¡°shell=True¡±Ñ¡ÏîÀ´ÐÞ²¹£¬£¬£¬ÈçÏ£º
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16846
SaltStackÂß¼Îó²î£¨CVE-2020-17490£©
ÔÚTLSÖ´ÐÐÄ£¿£¿£¿£¿£¿éʹÓú¯Êýcreate_ca¡¢create_csrºÍcreate_self_signed_certʱ£¬£¬£¬Ëü½«ÎÞ·¨È·±£Ê¹ÓÃ׼ȷµÄȨÏÞ½¨ÉèÃÜÔ¿¡£¡£¡£¡£¡£¹¥»÷Õ߿ɵǼsaltÖ÷»ú¶ÁÈ¡µ½ÃÜÔ¿ÄÚÈÝ£¬£¬£¬µ¼ÖÂÐÅϢй¶¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17490
SaltStackÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-25592£©
SaltStackÔÚÑéÖ¤eauthƾ֤¼°Æä»á¼û¿ØÖÆÁбíACLʱ±£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýsalt-apiÈÆ¹ýÉí·ÝÑéÖ¤²¢Ê¹ÓÃSSHÅþÁ¬Ä¿µÄЧÀÍÆ÷¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25592
×èÖ¹ÏÖÔÚ£¬£¬£¬ShodanÉϹ²ÁгöÁË6,000¶à¸ö̻¶ÓÚInternetµÄSalt Master½Úµã£¬£¬£¬µ«²¢·ÇËùÓнڵ㶼ÊÇÔËÐеÄ×îа汾¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚSaltstack¹Ù·½ÒѾÐû²¼Ð°汾£¬£¬£¬½¨ÒéʵʱÉý¼¶¡£¡£¡£¡£¡£
ÏÂÔØµØµã£º
https://repo.saltstack.com/
https://pypi.org/project/salt/#history
0x03 ²Î¿¼Á´½Ó
https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/
https://docs.saltstack.com/en/latest/
https://docs.saltstack.com/en/latest/topics/releases/3002.1.html
https://docs.saltstack.com/en/latest/topics/releases/3001.3.html
https://www.bleepingcomputer.com/news/security/saltstack-reveals-new-critical-vulnerabilities-patch-now/?
0x04 ʱ¼äÏß
2020-11-03 SaltstackÐû²¼Ç徲ͨ¸æ
2020-11-04 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/