ZABBIX SQL×¢ÈëÎó²îÀ´Ï®£¬£¬£¬£¬¼øºÚµ£±£ÍøÌṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2024-05-23

ZabbixÊÇÒ»¸ö»ùÓÚWEB½çÃæµÄÆóÒµ¼¶¿ªÔ´½â¾ö¼Æ»®£¬£¬£¬£¬ÓÃÓÚÌṩÂþÑÜʽϵͳ¼àÊÓºÍÍøÂç¼àÊÓ¹¦Ð§£¬£¬£¬£¬°ü¹ÜЧÀÍÆ÷ϵͳµÄÇå¾²ÔËÓª£¬£¬£¬£¬±ãÓÚϵͳÖÎÀíÔ±¿ìËÙ¶¨Î»Ï¢Õù¾ö±£´æµÄÖÖÖÖÎÊÌâ¡£¡£¡£¡£


ÆäÖ÷ÒªÓÉÁ½¸öÖ÷Òª×é¼þ×é³É£ºZabbix serverºÍ¿ÉÑ¡µÄZabbix agent¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬Zabbix serverÄܹ»Í¨¹ýSNMP¡¢Zabbix agent¡¢ping¡¢¶Ë¿Ú¼àÊÓµÈÒªÁì¶ÔÔ¶³ÌЧÀÍÆ÷ºÍÍøÂç״̬¾ÙÐмàÊÓºÍÊý¾ÝÍøÂ磬£¬£¬£¬¿ÉÔÚLinux¡¢Solaris¡¢HP-UX¡¢AIX¡¢Free BSD¡¢Open BSD¡¢OS XµÈ¶àÖÖÆ½Ì¨ÉÏÔËÐС£¡£¡£¡£


Îó²îÏêÇé


2024Äê5ÔÂ21ÈÕ£¬£¬£¬£¬¼øºÚµ£±£Íø½ð¾¦Çå¾²Ñо¿ÍÅ¶Ó¼à¿Øµ½Zabbix SQL×¢ÈëÎó²î£¨CVE-2024-22120£©Ç鱨¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚaudit.cµÄzbx_auditlog_global_scriptº¯ÊýÖУ¬£¬£¬£¬ÓÉÓÚclientip×Ö¶Îδ¾­ÕûÀí£¬£¬£¬£¬¿ÉÄܵ¼ÖÂSQLʱ¼ääע¹¥»÷¡£¡£¡£¡£¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²î´ÓÊý¾Ý¿âÖлñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬²¢¿É½«È¨ÏÞÌáÉýΪÖÎÀíÔ±»òÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Îó²î¸´ÏÖ½ØÍ¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ʹÓÃÖÎÀíÔ±session¼°key½ÓÊÜÖÎÀíÔ±ÕË»§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÙÐÐcookieÌæ»»ºóË¢ÐÂÒ³Ãæ¼´¿É½ÓÊÜzabbixÖÎÀíÔ±


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó°Ïì°æ±¾


6.0.0 <= Zabbix <= 6.0.27

6.4.0 <= Zabbix <= 6.4.12

7.0.0alpha1 <= Zabbix <= 7.0.0beta1


ÐÞ¸´½¨Òé


1¡¢¹Ù·½ÐÞ¸´¼Æ»®


¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬£¬£¬ZabbixÍŶÓÐû²¼Á˲¹¶¡ÒÔ½â¾ö°æ±¾6.0.28rc1¡¢6.4.13rc1ºÍ7.0.0beta2ÖеÄÎó²î¡£¡£¡£¡£

µØµã£ºhttps://www.zabbix.com/download


2¡¢¼øºÚµ£±£Íø¼Æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¡¢ÌìÇåWebÓ¦ÓÃÇå¾²Íø¹Ø£¨WAF£©Éý¼¶µ½20240523°æ±¾¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦¡£¡£¡£¡£