Apache Seata·´ÐòÁл¯·ì϶À´Ï®£¬GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2024-09-23Apache Seata ÊÇÒ»¿î¿ªÔ´µÄÉ¢²¼Ê½ÊÂÎñ½â¾ö¹æ»®£¬ÖÂÁ¦ÓÚÔÚ΢·þÎñ¼Ü¹¹ÏÂÌṩ¸ß»úÄܺ͵¥Ò»Ò×ÓõÄÉ¢²¼Ê½ÊÂÎñ·þÎñ¡£
2024Äê9Ô£¬GA»Æ½ð¼×¼à¿Øµ½Apache Seata ¹Ù·½°ä²¼ÁËCVE-2024-22399 Apache Seata Hessian·´ÐòÁл¯·ì϶¡£¸Ã·ì϶CVSS3.1ĿǰÆÀ·ÖΪ9.8·Ö£¬²¢ÇÒÆä×ÛºÏÆÀ¼¶Îª¡°³¬Î£¡±¡£
¾×êÑÐÈ·¶¨£¬Apache Seata ÓÃÓÚ·þÎñ¶ËÓë¿Í»§¶ËͨѶµÄRPC ºÍ̸£¨Ä¬È϶˿ÚΪ8091£©ÒÔ¼°×Ô2.0.0 °æ±¾ÆðʵÏÖµÄRaft ºÍ̸ÐÂÎÅ£¬¾ùÖ§³ÖѡȡHessian ½øÐÐÊý¾ÝµÄÐòÁл¯Óë·´ÐòÁл¯²Ù×÷¡£ÔÚ2.1.0 ¼°1.8.1 °æ±¾Ö®Ç°£¬SeataÔÚ´¦ÖÃRPC ÒªÇóʱ£¬¶ÔRPC ÐÂÎÅÌåÖеÄÐòÁл¯Êý¾ÝУÑé»úÔì²»¹»Ñϸñ¡£ÕâÒ»Çé¿öÒÔÖÁ¹¥»÷Õß¿ÉÄÜ»ú¹ØÔ̺¬¶ñÒâHessian ÐòÁл¯Êý¾ÝµÄÐÂÎÅÌ壬²¢·¢ËͶñÒâRPC ÒªÇó£¬×îÖÕ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Èô³É¹¦ÀûÓô˷ì϶£¬¹¥»÷ÕßÔòÓпÉÄÜÆëÈ«ÕÆ¿ØÊÜÓ°ÏìµÄϵͳ£¬ÆäÖÐÔ̺¬»ñÈ¡Ãô¸ÐÊý¾ÝµÄ½Ó¼ûȨÏÞ¡¢Ö´ÐÐËÁÒâÖ¸Á»òÕßÌáÒé½øÒ»²½µÄÍøÂç¹¥»÷ÐÐΪ¡£ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì²ÉÈ¡·À»¤´ëÊ©¡£

·ì϶¸´ÏÖ

Ó°Ïì°æ±¾
Apache Seata 2.0.0 °æ±¾
Apache Seata 1.0.0 ÖÁ 1.8.0 °æ±¾
½â¾ö¹æ»®
Ò»¡¢¹Ù·½½¨¸´¹æ»®
Ŀǰ¹Ù·½ÒÑÓпɸüа汾£¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾:
Apache Seata 2.1.0/1.8.1
¹Ù·½ÏÂÔØµØÖ·£º
https://github.com/apache/incubator-seata/releases/tag/v2.1.0
¶þ¡¢GA»Æ½ð¼×½â¾ö¹æ»®
1¡¢GA»Æ½ð¼×Öն˲úÆ·¹æ»®
Ìì«‘Öն˰²È«Ò»Ì廯£¨EDR£©Ìṩ·ì϶µÄרÏîÑéÖ¤²é³ÄÜÁ¦¶Ô·ì϶פÁôÖն˽øÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬Í¬Ê±Ìṩʵʱ¸æ¾¯Òì³£×Ó¸¸¹ý³Ì£¬¼à¿ØÖ÷»úÒì³£±íÁ¬¼ì²â»ò·ÀÓùÄÜÁ¦£¬Õмܷì϶¹¥»÷·çÏÕ¡£

2¡¢GA»Æ½ð¼×¼ì²âÀà²úÆ·¹æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½µ±Ç°×îа汾ÊÂÎñ¿â¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ£¬ÊÂÎñ¿âÏÂÔØµØÖ·£º
https://venustech.download.venuscloud.cn/
3¡¢GA»Æ½ð¼×©ɨ²úÆ·¹æ»®
£¨1£©¡°GA»Æ½ð¼×·ì϶ɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè¡£

£¨2£©GA»Æ½ð¼×·ì϶ɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè¡£

4¡¢GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨£¨ASM£©²úÆ·¹æ»®
GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬¶ÔÈë¿â×ʲú·ì϶Apache Seata ·´ÐòÁл¯·ì϶£¨CVE-2024-22399£©½øÐÐÖÎÀí¡£

5¡¢GA»Æ½ð¼×°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®
Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬½øÐйØÁªÕ½ÊõÅäÖ㬽áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°Apache Seata ·´ÐòÁл¯·ì϶£¨CVE-2024-22399£©¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£
£¨1£© ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°Apache Seata ·´ÐòÁл¯·ì϶£¨CVE-2024-22399£©¡±·ì϶ɨÃ蹤×÷£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄ³ÁÒª×ʲú¡£

£¨2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬Ôö³¤¡°L2_Apache Seata ·´ÐòÁл¯·ì϶¡±£¬Í¨¹ýGA»Æ½ð¼×¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖ±í²¿¹¥»÷ÐÐΪ¡£

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_Apache Seata·´ÐòÁл¯·ì϶"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓá£
£¨3£© Ôö³¤¡°L3_Apache Seata·´ÐòÁл¯·ì϶¡±£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÅ×Ú»òÔ̺¬¡°L2_Apache Seata ·´ÐòÁл¯·ì϶¡±£¬¹¥»÷Á˾ֵÅ×Ú¡°¹¥»÷³É¹¦¡±£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶȡ£

£¨4£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé
ƾ¾Ý¶ÔCVE-2024-22399·ì϶µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬¸²¸ÇµÄTTPÔ̺¬£º
TA0001³õʼ½Ó¼û£ºT1190ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½
TA0002Ö´ÐУºT1059ºÅÁîºÍ¾ç±¾Ú¹ÊÍÆ÷
TA0004ÌáȨ£º T1068ÀûÓ÷ì϶ÌáÉýȨÏÞ
TA0009Êý¾ÝÍøÂ磺 T1005´Ó±¾µØÏµÍ³ÍøÂçÊý¾Ý

ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬½øÐÐ×Ô¶¯»¯´ëÖá£


¾©¹«Íø°²±¸11010802024551ºÅ