¡¾·ì϶¹«¸æ¡¿Kubernetes ingress-nginx½ÚÔìÆ÷ËÁÒâ´úÂëÖ´Ðзì϶(CVE-2025-1974)
°ä²¼¹¦·ò 2025-03-28Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Kubernetes ingress-nginx½ÚÔìÆ÷ËÁÒâ´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-1974 | ||
·ì϶ÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-03-28 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
ingress-nginx½ÚÔìÆ÷ÊÇKubernetesÖеÄÒ»¸ö¹Ø¼ü×é¼þ£¬ÓÃÓÚÖÎÀí¼¯ÈºÄÚ²¿ºÍ±í²¿Á÷Á¿µÄ½Ó¼û½ÚÔì¡£Ëüͨ¹ý½ç˵Ingress×ÊÔ´À´ÅäÖÃHTTPºÍHTTPS·ÓÉ£¬ÊµÏÖ¸ºÔØÆ½ºâ¡¢SSLÖÕÖ¹¡¢·´Ïò´úÀíµÈÖ°ÄÜ¡£¸Ã½ÚÔìÆ÷»ùÓÚNGINX£¬Ö§³Ö½Ã½ÝµÄÁ÷Á¿ÖÎÀíÕ½ÊõºÍ¸ß¿ÉÀ©´óÐÔ¡£
2025Äê3ÔÂ28ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Kubernetes°ä²¼µÄ°²È«²¼¸æ£¬Ö¸³öÔÚKubernetesÖз¢ÏÖÁËÒ»¸öÑϳÁµÄ°²È«·ì϶£¬¸Ã·ì϶ӰÏìingress-nginx½ÚÔìÆ÷¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½öÐè½Ó¼ûPodÍøÂ磬±ã¿ÉÔÚingress-nginx½ÚÔìÆ÷¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬½ø¶øÐ¹Â¶½ÚÔìÆ÷¿É½Ó¼ûµÄSecrets¡£Ä¬ÈÏÇé¿öÏ£¬ingress-nginx½ÚÔìÆ÷ÓµÓнӼûÕû¸ö¼¯ÈºËùÓÐSecretsµÄȨÏÞ¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8·Ö£¬·ì϶µÈ¼¶ÑϳÁ¡£
¶þ¡¢Ó°ÏìÁìÓò
ingress-nginx < v1.11.0
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/kubernetes/ingress-nginx/releases/


¾©¹«Íø°²±¸11010802024551ºÅ