ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208) À´Ï®£¬GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2025-03-31Vite ÊÇÒ»¿îÏÖ´ú»¯µÄǰ¶Ë¿ª·¢¹¹½¨¹¤¾ß£¬ËüÌṩÁ˼±¾çµÄ¿ª·¢·þÎñÆ÷ºÍ¸ßЧµÄ¹¹½¨ÄÜÁ¦£¬¿í·ºÀûÓÃÓÚ Vue.js ÏîÖ÷ÕÅ¿ª·¢¹ý³ÌÖС£
2025Äê3Ô£¬GA»Æ½ð¼×¼à¿Øµ½ViteËÁÒâÎļþ¶ÁÈ¡·ì϶µý±¨(CVE-2025-30208)£¬¸Ã·ì϶ԴÓÚ Vite ¿ª·¢·þÎñÆ÷ÔÚ´¦ÖÃÌØ¶¨ URL ÒªÇóʱ£¬Ã»ÓжÔÒªÇóµÄõè¾¶½øÐÐÑϸñµÄ°²È«²é³ºÍÏÞ¶È£¬µ¼Ö¹¥»÷ÕßÄܹ»Èƹý±£»¤»úÔ죬·¸·¨½Ó¼ûÏîÄ¿¸ùĿ¼±íµÄÃô¸ÐÎļþ¡£

·ì϶¸´ÏÖ½ØÍ¼

Ó°Ïì°æ±¾
6.2.0 <= Vite <= 6.2.2
6.1.0 <= Vite <= 6.1.1
6.0.0 <= Vite <= 6.0.11
5.0.0 <= Vite <= 5.4.14
Vite <= 4.5.9
½¨¸´½¨Òé
Ò»¡¢¹Ù·½½¨¸´¹æ»®£º
ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾½øÐзÀ»¤£¬ÏÂÔØÁ´½Ó£ºhttps://github.com/vitejs/vite/releases
¶þ¡¢GA»Æ½ð¼×¹æ»®£º
1¡¢GA»Æ½ð¼×¼ì²âÀà²úÆ·¹æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEB°²È«ÀûÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬Éý¼¶µ½×îа汾¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ¡£
ÊÂÎñ¿âÏÂÔØµØÖ·£ºhttps://venustech.download.venuscloud.cn/
2¡¢GA»Æ½ð¼×©ɨ²úÆ·¹æ»®
£¨1£©¡°GA»Æ½ð¼×·ì϶ɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè

£¨2£©GA»Æ½ð¼×·ì϶ɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè

3¡¢GA»Æ½ð¼×Öն˲úÆ·¹æ»®
Ìì«‘Öն˰²È«Ò»Ì廯£¨EDR£©Ìṩ·ì϶µÄרÏîÑéÖ¤²é³ÄÜÁ¦¿É¶Ô·ì϶פÁôÖն˽øÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬Æ¥Åä·ì϶×ʲú£¬Ô¤·À·ì϶¹¥»÷·çÏÕ¡£

4¡¢GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®
GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬¶ÔÈë¿â×ʲúViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)½øÐÐÖÎÀí¡£

5¡¢GA»Æ½ð¼×°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®
Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬½øÐйØÁªÕ½ÊõÅäÖ㬽áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£
1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±·ì϶ɨÃ蹤×÷£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄ³ÁÒª×ʲú£»

2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬Ôö³¤¡°L2_ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±£¬Í¨¹ýGA»Æ½ð¼×¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖ±í²¿¹¥»÷ÐÐΪ£º

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓã»
3£©Ôö³¤¡°L3_ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÅ×Ú»òÔ̺¬¡°L2_ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±£¬¹¥»÷Á˾ֵÅ×Ú»òÊôÓÚ¡°¹¥»÷³É¹¦¡±£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶȡ£

4£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé
ƾ¾Ý¶ÔViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬¸²¸ÇµÄTTPÔ̺¬£º
TA0001-³õʼ½Ó¼û£ºT1190-ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½
TA0010-Êý¾Ýй¶£ºT1041-ͨ¹ýC2ͨ·ÇÔÈ¡

ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬½øÐÐ×Ô¶¯»¯´ëÖá£


¾©¹«Íø°²±¸11010802024551ºÅ