Puppet EnterpriseĬÈÏÃÜÂë·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-05

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10694 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.4 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ºÏÓÃÓÚPuppet Enterprise 2019.0.3֮ǰ°æ±¾ ¡£


·ì϶¸ÅÊö


PuppetÊÇ¿ªÔ´µÄ»ùÓÚRubyµÄϵͳÅäÖÃÖÎÀí¹¤¾ß £¬»ùÓÚC/SµÄ²¿Êð¼Ü¹¹ ¡£ÊÇÒ»¸öΪʵÏÖÊý¾ÝÖÐÐÄ×Ô¶¯»¯ÖÎÀí¶øÉè¼ÆµÄÅäÖÃÖÎÀíÈí¼þ £¬ËüʹÓÃ¿çÆ½Ì¨Ëµ»°¹æ·¶ £¬ÖÎÀíÅäÖÃÎļþ¡¢Óû§¡¢Èí¼þ°ü¡¢ÏµÍ³·þÎñµÈ ¡£¿Í»§¶ËĬÈÏÿ¸ô°ëÓ×ʱ»áºÍ·þÎñÆ÷ͨѶһ´Î £¬È·ÈÏÊÇ·ñÓиüР¡£µ±È»Ò²Äܹ»ÅäÖÃ×Ô¶¯´¥·¢À´Ç¿Ôì¿Í»§¶Ë¸üР¡£ÕâÑù¾Í°ÑÈÕ³£µÄϵͳÖÎÀí¹¤×÷´úÂ뻯ÁË £¬´úÂ뻯µÄÒæ´¦ÊÇÄܹ»·ÖÏí £¬±£Áô £¬Ô¤·À³Á¸´ÀͶ¯ £¬Ò²Äܹ»¼±¾ç¸´Ô­ÒÔ¼°¼±¾çµÄ´ó¹æÄ£²¿Êð·þÎñÆ÷ ¡£Puppet EnterpriseÊÇPuppetµÄÆóÒµ°æ ¡£


Puppet Enterprise 2019.0.3֮ǰ°æ±¾ÖдæÔÚĬÈÏÃÜÂë·ì϶ £¬¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÈÆ¹ýÏÞ¶È £¬ÌáÉýȨÏÞ ¡£


¾Ýͳ¼Æ £¬Öйú¶³öÔÚ¹«ÍøÉϵÄPuppet´ï3000¶à¸ö £¬¾ßÌåÉ¢²¼Çé¿öÈçÏ£º

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP ¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://puppet.com/security/cve/CVE-2019-10694


²Î¿¼Á´½Ó


https://puppet.com/security/cve/CVE-2019-10694