Harborí§ÒâÖÎÀíÔ±×¢²áÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-19

¡ñÎó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-16097£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º6.5


¡ñÓ°Ïì°æ±¾


Harbor 1.7.0°æ±¾ÖÁ1.8.2°æ±¾


¡ñÎó²î¸ÅÊö


HarborÊÇÒ»¸öÓÃÓÚ´æ´¢ºÍ·Ö·¢Docker¾µÏñµÄÆóÒµ¼¶RegistryЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬Í¨¹ýÌí¼ÓһЩÆóÒµ±ØÐèµÄ¹¦Ð§ÌØÕ÷£¬£¬£¬ £¬£¬£¬ÀýÈçÇå¾²¡¢±êʶºÍÖÎÀíµÈ£¬£¬£¬ £¬£¬£¬À©Õ¹ÁË¿ªÔ´Docker Distribution ¡£¡£¡£¡£¡£¡£×÷Ϊһ¸öÆóÒµ¼¶Ë½ÓÐRegistryЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬HarborÌṩÁ˸üºÃµÄÐÔÄܺÍÇå¾² ¡£¡£¡£¡£¡£¡£ÌáÉýÓû§Ê¹ÓÃRegistry¹¹½¨ºÍÔËÐÐÇéÐδ«Êä¾µÏñµÄЧÂÊ ¡£¡£¡£¡£¡£¡£HarborÖ§³Ö×°ÖÃÔÚ¶à¸öRegistry½ÚµãµÄ¾µÏñ×ÊÔ´¸´ÖÆ£¬£¬£¬ £¬£¬£¬¾µÏñËùÓÐÉúÑÄÔÚ˽ÓÐRegistryÖУ¬£¬£¬ £¬£¬£¬ È·±£Êý¾ÝºÍ֪ʶ²úȨÔÚ¹«Ë¾ÄÚ²¿ÍøÂçÖÐ¹Ü¿Ø ¡£¡£¡£¡£¡£¡£ÁíÍ⣬£¬£¬ £¬£¬£¬HarborÒ²ÌṩÁ˸߼¶µÄÇå¾²ÌØÕ÷£¬£¬£¬ £¬£¬£¬ÖîÈçÓû§ÖÎÀí£¬£¬£¬ £¬£¬£¬»á¼û¿ØÖƺͻÉó¼ÆµÈ ¡£¡£¡£¡£¡£¡£


¿ËÈÕHarborÆØ³öÒ»¸ö±ÊֱԽȨÎó²î£¬£¬£¬ £¬£¬£¬Òò×¢²áÄ£¿£¿£¿é¶Ô²ÎÊýУÑé²»ÑϿᣬ£¬£¬ £¬£¬£¬¿Éµ¼ÖÂí§ÒâÖÎÀíÔ±×¢²á ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý×¢²áÖÎÀíÔ±Õ˺ÅÀ´½ÓÊÜHarbor¾µÏñ¿ÍÕ»£¬£¬£¬ £¬£¬£¬´Ó¶øÐ´Èë¶ñÒâ¾µÏñ£¬£¬£¬ £¬£¬£¬×îÖÕ¿ÉÒÔѬȾʹÓô˿ÍÕ»µÄ¿Í»§¶Ë ¡£¡£¡£¡£¡£¡£


ÏÖÔÚº£ÄÚ̻¶ÔÚ¹«ÍøµÄÔÚÏßʵÀýÓÐ2034¸ö£¬£¬£¬ £¬£¬£¬ÈçÏÂͼ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨




¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


HarborÔÚÒÑÍùËÄÄêÖÐÖð½¥ÆÕ¼°£¬£¬£¬ £¬£¬£¬ÔÚÆä½ÓÄÉÕßÒ³ÃæÖаüÀ¨Ðí¶àÖøÃûµÄÔÞÖúÉ̺͹«Ë¾£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



¡ñÎó²îÑéÖ¤


POCÊÓÆµ£ºhttps://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/£¬£¬£¬ £¬£¬£¬Ê¹ÓÃÀÖ³ÉÈçÏÂͼ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨





¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¡ñÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ £¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://github.com/goharbor/harbor/pull/8917 ¡£¡£¡£¡£¡£¡£


¡ñ²Î¿¼Á´½Ó


https://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/