¡¾Îó²îͨ¸æ¡¿Kubernetes ingress-nginx¿ØÖÆÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î(CVE-2025-1974)
Ðû²¼Ê±¼ä 2025-03-28Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Kubernetes ingress-nginx¿ØÖÆÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-1974 | ||
Îó²îÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-28 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
ingress-nginx¿ØÖÆÆ÷ÊÇKubernetesÖеÄÒ»¸öÒªº¦×é¼þ£¬£¬£¬ÓÃÓÚÖÎÀí¼¯ÈºÄÚ²¿ºÍÍⲿÁ÷Á¿µÄ»á¼û¿ØÖÆ¡£¡£¡£¡£¡£¡£Ëüͨ¹ý½ç˵Ingress×ÊÔ´À´ÉèÖÃHTTPºÍHTTPS·ÓÉ£¬£¬£¬ÊµÏÖ¸ºÔØÆ½ºâ¡¢SSLÖÕÖ¹¡¢·´ÏòÊðÀíµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¸Ã¿ØÖÆÆ÷»ùÓÚNGINX£¬£¬£¬Ö§³ÖÎÞаµÄÁ÷Á¿ÖÎÀíÕ½ÂԺ͸߿ÉÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£
2025Äê3ÔÂ28ÈÕ£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½KubernetesÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬Ö¸³öÔÚKubernetesÖз¢Ã÷ÁËÒ»¸öÑÏÖØµÄÇå¾²Îó²î£¬£¬£¬¸ÃÎó²îÓ°Ïìingress-nginx¿ØÖÆÆ÷¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½öÐè»á¼ûPodÍøÂ磬£¬£¬±ã¿ÉÔÚingress-nginx¿ØÖÆÆ÷ÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬½ø¶øÐ¹Â¶¿ØÖÆÆ÷¿É»á¼ûµÄSecrets¡£¡£¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏ£¬£¬£¬ingress-nginx¿ØÖÆÓþßÓлá¼ûÕû¸ö¼¯ÈºËùÓÐSecretsµÄȨÏÞ¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬Îó²îÆ·¼¶ÑÏÖØ¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
ingress-nginx < v1.11.0
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/kubernetes/ingress-nginx/releases/