¡¾Îó²îͨ¸æ¡¿GitLabÖØÖÃÃÜÂëÎó²î£¨CVE-2023-7028£©
Ðû²¼Ê±¼ä 2024-01-12Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | GitLabÖØÖÃÃÜÂëÎó²î | ||
CVE ID | CVE-2023-7028 | ||
Îó²îÀàÐÍ | ÃÜÂëÖØÖà | ·¢Ã÷ʱ¼ä | 2024-01-12 |
Îó²îÆÀ·Ö | 10.0 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ֪ |
GitLabÊÇÒ»¸öÓÃÓÚ¿ÍÕ»ÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬£¬£¬£¬£¬ÆäʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬¿Éͨ¹ýWeb½çÃæ»á¼û¹ûÕæ»ò˽ÈËÏîÄ¿¡£¡£¡£¡£¡£¡£
2024Äê1ÔÂ12ÈÕ£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøVSRC¼à²âµ½GitLabÉçÇø°æ£¨CE£©ºÍÆóÒµ°æ£¨EE£©ÖÐÐÞ¸´ÁËÒ»¸öÖØÖÃÃÜÂëÎó²î£¨CVE-2023-7028£©£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ10.0¡£¡£¡£¡£¡£¡£
GitLab CE/EEÖÐÖ§³ÖÓû§Í¨¹ý¸¨Öúµç×ÓÓʼþµØµãÖØÖÃÃÜÂë¡£¡£¡£¡£¡£¡£GitLab CE/EE¶à¸öÊÜÓ°Ïì°æ±¾ÖУ¬£¬£¬£¬£¬ÓÉÓÚµç×ÓÓʼþÑéÖ¤Àú³ÌÖб£´æ¹ýʧ£¬£¬£¬£¬£¬Óû§ÕÊ»§ÃÜÂëÖØÖõç×ÓÓʼþ¿ÉÒÔ·¢Ë͵½Î´ÂÄÀúÖ¤µÄµç×ÓÓʼþµØµã£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔÚÎÞÐèÓû§½»»¥µÄÇéÐÎÏÂͨ¹ýÃÜÂëÖØÖþÙÐÐÕÊ»§½ÓÊÜ¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬GitLab CE/EE¶à¸öÊÜÓ°Ïì°æ±¾Öл¹ÐÞ¸´ÁËÒ»¸öÊÚȨ¼ì²é²»µ±Îó²î£¨CVE-2023-5356£¬£¬£¬£¬£¬CVSSv3ÆÀ·Ö9.6£©£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÓû§ÀÄÓÃSlack/Mattermost¼¯³ÉÒÔÆäËûÓû§µÄÉí·ÝÖ´ÐÐб¸ÜÏÂÁî¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
CVE-2023-7028
GitLab CE/EE 16.1 < 16.1.5
GitLab CE/EE 16.2 < 16.2.8
GitLab CE/EE 16.3 < 16.3.6
GitLab CE/EE 16.4 < 16.4.4
GitLab CE/EE 16.5 < 16.5.6
GitLab CE/EE 16.6 < 16.6.4
GitLab CE/EE 16.7 < 16.7.2
CVE-2023-5356
8.13<= GitLab CE/EE°æ±¾ < 16.5.6
GitLab CE/EE 16.6 < 16.6.4
GitLab CE/EE 16.7 < 16.7.2
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½GitLab CE/EE °æ±¾16.5.6¡¢16.6.4 ºÍ 16.7.2¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬CVE-2023-7028µÄÇå¾²ÐÞ¸´³ÌÐòÒÑÏòºóÒÆÖ²µ½GitLab°æ±¾16.1.6¡¢16.2.9¡¢16.3.7ºÍ16.4.5¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://about.gitlab.com/
×¢£ºÕë¶ÔCVE-2023-7028£¬£¬£¬£¬£¬SSO Óû§£¨ÀýÈç SAML£©»áÊܵ½Ó°Ï죬£¬£¬£¬£¬µ« LDAP Óû§²»»áÊܵ½Ó°Ï죬£¬£¬£¬£¬ÓÉÓÚûÓÐÒÅÍü/ÖØÖÃÃÜÂëÑ¡Ïî¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ÆôÓÃÁËË«ÒòËØÉí·ÝÑéÖ¤µÄÓû§ºÜÈÝÒ×Êܵ½ÃÜÂëÖØÖõÄÓ°Ï죬£¬£¬£¬£¬µ«ÕÊ»§²»»á±»½ÓÊÜ£¬£¬£¬£¬£¬ÓÉÓÚÐèÒªµÚ¶þ¸öÉí·ÝÑéÖ¤ÒòËØ²Å»ªµÇ¼¡£¡£¡£¡£¡£¡£
3.2 ÔÝʱ²½·¥
Õë¶ÔCVE-2023-7028£º
½¨ÒéÉý¼¶µ½Ä¿½ñ×îÐÂÐÞ¸´°æ±¾£¬£¬£¬£¬£¬ÈçÎÞ·¨Á¬Ã¦Éý¼¶£¬£¬£¬£¬£¬¿ÉΪËùÓÐ GitLab ÕÊ»§ÆôÓÃË«ÒòËØÉí·ÝÑéÖ¤(2FA)£¬£¬£¬£¬£¬ÓÈÆäÊǾßÓи߼¶È¨ÏÞµÄÓû§£¨ÀýÈçÖÎÀíÔ±ÕÊ»§£©£»£»£»£»£»ÈôÊÇÒѾÆôÓÃÁË2FA£¬£¬£¬£¬£¬ÍþвÕß½«ÎÞ·¨½ÓÊܸÃÕÊ»§£¬£¬£¬£¬£¬µ«Æä¿ÉÄÜÈÔÈ»Äܹ»ÖØÖÃÃÜÂ룬£¬£¬£¬£¬µ«ÎÞ·¨»á¼ûµÚ¶þÒòËØÉí·ÝÑéÖ¤ÒªÁì¡£¡£¡£¡£¡£¡£
Óû§¿ÉÒÔÉó²éÈÕÖ¾ÒÔ¼ì²éÊÇ·ñ±£´æ¿ÉÄܵÄÎó²îʹÓÃʵÑ飺
l ¼ì²é gitlab-rails/production_json.log£¬£¬£¬£¬£¬ÒÔÉó²éÊÇ·ñ±£´æÖ¸Ïò /users/password ·¾¶µÄ HTTP ÇëÇ󣬣¬£¬£¬£¬ÆäÖаüÀ¨params.value.email£¬£¬£¬£¬£¬ÓɾßÓжà¸öµç×ÓÓʼþµØµãµÄjsonÊý×é×é³É¡£¡£¡£¡£¡£¡£
l ¼ì²é gitlab-rails/audit_json.log£¬£¬£¬£¬£¬ÒÔ²éÕÒ°üÀ¨meta.caller.idµÄPasswordsController#createºÍtarget_detailsµÄÌõÄ¿£¬£¬£¬£¬£¬ÕâЩÌõÄ¿ÓɾßÓжà¸öµç×ÓÓʼþµØµãµÄjsonÊý×é×é³É¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/
https://nvd.nist.gov/vuln/detail/CVE-2023-7028
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-01-12 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£
5.2 ¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º