¡¾Íþвͨ¸æ¡¿GitLab?Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î (CVE-2021-22205)
2021-10-28
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼¼à²âµ½ÓÐÑо¿Ö°Ô±Åû¶ÁËGitLab Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2021-22205)µÄʹÓóÌÐò£¬ÇÒ·¢Ã÷ÓÉÓÚGitLab±£´æÎ´ÊÚȨµÄ¶Ëµã£¬µ¼Ö¸ÃÎó²îÔÚÎÞÐè¾ÙÐÐÉí·ÝÑéÖ¤µÄÇéÐÎϼ´¿É¾ÙÐÐʹÓã¬ÉçÇø°æ(CE)ºÍÆóÒµ°æ(EE)½ÔÊÜÓ°Ïì¡£4ÔÂ15ÈÕ£¬GitLab¹Ù·½Ðû²¼Çå¾²¸üÐÂÐÞ¸´ÁË´ËGitLabÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22205£©£¬ÓÉÓÚGitLabÖеÄExifToolûÓжԴ«ÈëµÄͼÏñÎļþµÄÀ©Õ¹Ãû¾ÙÐÐ׼ȷ´¦Öóͷ££¬¹¥»÷Õßͨ¹ýÉÏ´«ÌØÖƵĶñÒâͼƬ£¬¿ÉÒÔÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£CVSSÆÀ·ÖΪ9.9£¬ÏÖÔÚÒÑ·¢Ã÷ÔÚҰʹÓã¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
GitLab ÊÇÓÉGitLab Inc.¿ª·¢µÄÒ»¸öÓÃÓÚ¿ÍÕ»ÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬Ê¹ÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬¿Éͨ¹ýWeb½çÃæ»á¼û¹ûÕæ»ò˽ÈËÏîÄ¿¡£
²Î¿¼Á´½Ó£º
https://about.gitlab.com/releases/2021/04/14/security-release-gitlab-13-10-3-released/
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
11.9 <= Gitlab CE/EE < 13.8.8
13.9 <= Gitlab CE/EE < 13.9.6
13.10 <= Gitlab CE/EE < 13.10.3
Èý. Îó²î¼ì²â
3.1 °æ±¾¼ì²â
Ïà¹ØÓû§¿Éͨ¹ý°æ±¾¼ì²âµÄÒªÁìÅжÏÄ¿½ñÓ¦ÓÃÊÇ·ñ±£´æÎ£º¦¡£
ʹÓÃÈçÏÂÏÂÁî¿ÉÉó²éÄ¿½ñGitLabµÄ°æ±¾£º
|
cat /opt/gitlab/embedded/service/gitlab-rails/VERSION |
ÈôÄ¿½ñ°æ±¾ÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Ôò¿ÉÄܱ£´æÇ徲Σº¦¡£
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÐû²¼Ð°汾ÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶ÖÁ×îа汾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£ºhttps://about.gitlab.com/update/
4.2 ÔÝʱ·À»¤²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐÐÉý¼¶²Ù×÷£¬¿ÉʹÓð×Ãûµ¥ÏÞÖÆ¶ÔWeb¶Ë¿ÚµÄ»á¼û¡£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ





