Harbor¶à¸ö·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-12-04·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-19029£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19026£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19025£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-3990£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19023£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-16919£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-16097£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Harbor 1.7.*
Harbor 1.8.*<1.8.6
Harbor 1.9.*<1.9.3
·ì϶¸ÅÊö
HarborÊÇÒ»¸öÓÃÓÚ´æ´¢ºÍ·Ö·¢Docker¾µÏñµÄÆóÒµ¼¶Registry·þÎñÆ÷£¬Í¨¹ýÔö³¤Ò»Ð©ÆóÒµ±ØÐëµÄÖ°ÄܸöÐÔ£¬ÀýÈ簲ȫ¡¢±êʶºÍÖÎÀíµÈ£¬À©´óÁË¿ªÔ´Docker Distribution¡£×÷Ϊһ¸öÆóÒµ¼¶Ë½ÓÐRegistry·þÎñÆ÷£¬HarborÌṩÁ˸üºÃµÄ»úÄܺͰ²È«¡£ÌáÉýÓû§Ê¹ÓÃRegistry¹¹½¨ºÍÔËÐл·¾³´«Êä¾µÏñµÄЧÄÜ¡£HarborÖ§³Ö×°ÖÃÔÚ¶à¸öRegistry½ÚµãµÄ¾µÏñ×ÊÔ´¸´Ô죬¾µÏñÈ«Êý±£ÁôÔÚ˽ÓÐRegistryÖУ¬È·±£Êý¾ÝºÍ֪ʶ²úȨÔÚ¹«Ë¾ÄÚ²¿ÍøÂçÖйܿء£Áí±í£¬HarborÒ²ÌṩÁ˸߼¶µÄ°²È«¸öÐÔ£¬ÖîÈçÓû§ÖÎÀí£¬½Ó¼û½ÚÔìºÍ»î¶¯Éó¼ÆµÈ¡£
ƾ¾ÝHarbor¹Ù·½°²È«¹«¸æ, Harbor´æÔÚÒÔϰ²È«ÎÊÌ⣺
CVE-2019-19026¡¢CVE-2019-19029·ì϶£ºHarbor´æÔÚSQL²éÎÊÓï¾ä¹ýÂ˲»Ñϵ¼ÖÂSQL×¢È룻
CVE-2019-19023·ì϶£ºHarborÔÚŲÓÃAPIʱδ¶ÔAPIÒªÇó½øÐÐÑϸñÏÞ¶È£¬´æÔÚͨ³£Óû§Äܹ»Í¨¹ýŲÓÃAPIÅú¸ÄÌØ¶¨Óû§µÄµç×ÓÓʼþµØÖ·£¬´Ó¶ø»ñµÃÖÎÀíÔ¹ØÊ»§È¨ÏÞ£¬±ã¿É³ÁÖøõç×ÓÓʼþµØÖ·µÄÃÜÂë²¢»ñµÃ¶Ô¸ÃÕÊ»§µÄ½Ó¼ûȨÏÞ¡£
CVE-2019-3990·ì϶£ºHarborÔÚʹÓÃapi/users/searchʱδ½øÐкÏÀíÉí·ÝУÑ飬´æÔÚÈÆ¹ýÖÎÀíÔ±Ï޶ȽøÐÐÓû§Ãûö¾Ù¡£
CVE-2019-19025·ì϶£ºHarborÔÚWeb½çÃæÔÚʹÓÃÖУ¬´æÔÚÉí·Ý¶þ´ÎУÑé²»ÑϵÄÇé¿ö£¬´Ó¶øµ¼ÖÂCSRFµÈ·ì϶¡£
CVE-2019-16919·ì϶£ºÈ¨ÏÞÌáÉý·ì϶¡£
CVE-2019-16097·ì϶£ºÔÊÐí·ÇÖÎÀíÔ±Óû§Í¨¹ýPOST / api / users API´´½¨ÖÎÀíÔ¹ØÊ»§¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
¹Ù·½ÒѾ°ä²¼¸üв¹¶¡£¬½¨Òé¸üе½1.9.3ºÍ1.8.6ÒÔÉϰ汾£º
https://github.com/goharbor/harbor/releases/tag/v1.9.3
https://github.com/goharbor/harbor/releases/tag/v1.8.6
²Î¿¼Á´½Ó
https://github.com/goharbor/harbor/security/advisories


¾©¹«Íø°²±¸11010802024551ºÅ