Apache HertzBeat SnakeYaml·´ÐòÁл¯Îó²îÀ´Ï®£¬£¬£¬£¬£¬£¬ £¬Z6×ðÁú¿­Ê±Ìṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2024-09-28

Apache HertzBeat ÊÇ¿ªÔ´µÄʵʱ¼à¿Ø¹¤¾ß£¬£¬£¬£¬£¬£¬ £¬ÊÜÓ°Ïì°æ±¾ÖÐδ¶ÔÓû§¿É¿ØµÄ yaml ÎļþÓÐÓùýÂË£¬£¬£¬£¬£¬£¬ £¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õ߿ɽṹ¶ñÒâµÄ yaml ÎļþÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£


2024Äê9Ô£¬£¬£¬£¬£¬£¬ £¬Z6×ðÁú¿­Ê±¼à¿Øµ½Apache HertzBeat¹Ù·½Ðû²¼ÁËCVE-2024-42323 £¬£¬£¬£¬£¬£¬ £¬snakeYaml µÄ RCE ¼ÓÔØ¶ñÒâ yamlÊý¾Ý¡£ ¡£¡£¡£¡£¡£¡£¸ÃÎó²îCVSS3.1ÏÖÔÚÆÀ·ÖΪ8.8·Ö£¬£¬£¬£¬£¬£¬ £¬²¢ÇÒÆä×ÛºÏÆÀ¼¶Îª¡°¸ßΣ¡±¡£ ¡£¡£¡£¡£¡£¡£


ͼƬ1.png


Îó²î¸´ÏÖ


ͼƬ2.png


ͼƬ3.png


Ó°Ïì°æ±¾


Apache Hertbeat < 1.6.0


½â¾ö¼Æ»®


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®


ÏÖÔÚ¹Ù·½ÒÑÓпɸüа汾£¬£¬£¬£¬£¬£¬ £¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾:

Apache Hertbeat >= 1.6.0

¹Ù·½ÏÂÔØµØµã£º

https://hertzbeat.apache.org/zh-cn/docs/download/


¶þ¡¢Z6×ðÁú¿­Ê±½â¾ö¼Æ»®


1¡¢Z6×ðÁú¿­Ê±¼ì²âÀà²úÆ·¼Æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEBÇå¾²Ó¦ÓÃÍø¹Ø£¨WAF£©Éý¼¶µ½20240927°æ±¾ÊÂÎñ¿â£¬£¬£¬£¬£¬£¬ £¬ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½×îа汾ÊÂÎñ¿â£¬£¬£¬£¬£¬£¬ £¬¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦¡£ ¡£¡£¡£¡£¡£¡£ÊÂÎñ¿âÏÂÔØµØµã£º

https://venustech.download.venuscloud.cn/


2¡¢Z6×ðÁú¿­Ê±Öն˲úÆ·¼Æ»®


Ìì«‘ÖÕ¶ËÇå¾²Ò»Ì廯£¨EDR£©ÌṩÎó²îµÄרÏîÑéÖ¤¼ì²éÄÜÁ¦¿É¶ÔÎó²îפÁôÖն˾ÙÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬£¬£¬£¬£¬£¬ £¬Í¬Ê±ÊµÊ±¼à¿Ø²¢¸æ¾¯Òì³£×Ó¸¸Àú³Ì¡¢¼à¿ØÖ÷»úÒì³£ÍâÁ¬¼ì²â£¬£¬£¬£¬£¬£¬ £¬Ô¤·ÀÎó²î¹¥»÷Σº¦¡£ ¡£¡£¡£¡£¡£¡£


ͼƬ4.jpg


3¡¢Z6×ðÁú¿­Ê±Â©É¨²úÆ·¼Æ»®


£¨1£©¡°Z6×ðÁú¿­Ê±Îó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£ ¡£¡£¡£¡£¡£¡£


ͼƬ5.png


£¨2£©Z6×ðÁú¿­Ê±Îó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£ ¡£¡£¡£¡£¡£¡£


ͼƬ6.png


4¡¢Z6×ðÁú¿­Ê±×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¼Æ»®


Z6×ðÁú¿­Ê±×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬¶ÔÈë¿â×ʲúÎó²îApache HertzBeat SnakeYaml·´ÐòÁл¯Îó²î£¨CVE-2024-42323£©¾ÙÐÐÖÎÀí¡£ ¡£¡£¡£¡£¡£¡£


ͼƬ7.png


5¡¢Z6×ðÁú¿­Ê±Çå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬£¬£¬£¬£¬ £¬¾ÙÐйØÁªÕ½ÂÔÉèÖ㬣¬£¬£¬£¬£¬ £¬Á¬ÏµÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬£¬£¬£¬£¬£¬ £¬´Ó¶ø·¢Ã÷¡°Apache HertzBeat SnakeYaml·´ÐòÁл¯Îó²î£¨CVE-2024-42323£©¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£ ¡£¡£¡£¡£¡£¡£


£¨1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬£¬£¬£¬£¬ £¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Apache HertzBeat SnakeYaml·´ÐòÁл¯Îó²î£¨CVE-2024-42323£©¡±Îó²îɨÃèʹÃü£¬£¬£¬£¬£¬£¬ £¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú¡£ ¡£¡£¡£¡£¡£¡£


ͼƬ8.png


£¨2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿£¿£¿£¿£¿£¿éÖУ¬£¬£¬£¬£¬£¬ £¬Ìí¼Ó¡°L2_Apache HertzBeat SnakeYaml·´ÐòÁл¯Îó²î¡±£¬£¬£¬£¬£¬£¬ £¬Í¨¹ýZ6×ðÁú¿­Ê±¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬£¬£¬£¬£¬£¬ £¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ¡£ ¡£¡£¡£¡£¡£¡£


ͼƬ9.png


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_Apache HertzBeat SnakeYaml·´ÐòÁл¯Îó²î"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬£¬£¬£¬£¬£¬ £¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓᣠ¡£¡£¡£¡£¡£¡£


£¨3£©Ìí¼Ó¡°L3_Apache HertzBeat SnakeYaml·´ÐòÁл¯Îó²î¡±£¬£¬£¬£¬£¬£¬ £¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_Apache HertzBeat SnakeYaml·´ÐòÁл¯Îó²î¡±£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬£¬£¬£¬£¬£¬ £¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬£¬£¬£¬£¬£¬ £¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£ ¡£¡£¡£¡£¡£¡£


ͼƬ10.png