¡¾Îó²îͨ¸æ¡¿Apache IgniteÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2024-52577)
Ðû²¼Ê±¼ä 2025-02-19Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Apache IgniteÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2024-52577 | ||
Îó²îÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-02-19 |
Îó²îÆÀ·Ö | 9.5 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache IgniteÊÇÒ»¸ö¸ßÐÔÄÜ¡¢ÂþÑÜʽÊý¾Ý¿âºÍÅÌËãÆ½Ì¨£¬£¬£¬×¨Îª´ó¹æÄ£Êý¾Ý´¦Öóͷ£ºÍʵʱÆÊÎöÉè¼Æ¡£¡£¡£¡£¡£¡£ËüÖ§³ÖÄÚ´æÅÌËã¡¢SQLÅÌÎÊ¡¢¼üÖµ´æ´¢¡¢Êý¾ÝÁ÷´¦Öóͷ£µÈ¹¦Ð§£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ´óÊý¾Ý¡¢ÎïÁªÍø¡¢½ðÈÚЧÀ͵ÈÁìÓò¡£¡£¡£¡£¡£¡£IgniteÌṩ¸ß¿ÉÓÃÐÔ¡¢À©Õ¹ÐԺ͵ÍÑÓ³Ù£¬£¬£¬Ö§³ÖÓëÆäËû´óÊý¾Ý¿ò¼Ü£¨ÈçHadoop¡¢Spark£©¼¯³É¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
2.6.0 <= Apache Ignite < 2.17.0
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
Apache IgniteÍŶÓÒÑÔÚ°æ±¾2.17.0ÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£¡£¡£½¨ÒéÊÜÓ°Ïì°æ±¾µÄÓû§¾¡¿ìÉý¼¶µ½2.17.0»ò¸ü¸ß°æ±¾£¬£¬£¬ÒÔ½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£