Harborí§ÒâÖÎÀíÔ±×¢²áÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-19¡ñÎó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-16097£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º6.5
¡ñÓ°Ïì°æ±¾
Harbor 1.7.0°æ±¾ÖÁ1.8.2°æ±¾
¡ñÎó²î¸ÅÊö
HarborÊÇÒ»¸öÓÃÓÚ´æ´¢ºÍ·Ö·¢Docker¾µÏñµÄÆóÒµ¼¶RegistryЧÀÍÆ÷£¬£¬£¬£¬£¬Í¨¹ýÌí¼ÓһЩÆóÒµ±ØÐèµÄ¹¦Ð§ÌØÕ÷£¬£¬£¬£¬£¬ÀýÈçÇå¾²¡¢±êʶºÍÖÎÀíµÈ£¬£¬£¬£¬£¬À©Õ¹ÁË¿ªÔ´Docker Distribution¡£¡£¡£¡£¡£¡£×÷Ϊһ¸öÆóÒµ¼¶Ë½ÓÐRegistryЧÀÍÆ÷£¬£¬£¬£¬£¬HarborÌṩÁ˸üºÃµÄÐÔÄܺÍÇå¾²¡£¡£¡£¡£¡£¡£ÌáÉýÓû§Ê¹ÓÃRegistry¹¹½¨ºÍÔËÐÐÇéÐδ«Êä¾µÏñµÄЧÂÊ¡£¡£¡£¡£¡£¡£HarborÖ§³Ö×°ÖÃÔÚ¶à¸öRegistry½ÚµãµÄ¾µÏñ×ÊÔ´¸´ÖÆ£¬£¬£¬£¬£¬¾µÏñËùÓÐÉúÑÄÔÚ˽ÓÐRegistryÖУ¬£¬£¬£¬£¬ È·±£Êý¾ÝºÍ֪ʶ²úȨÔÚ¹«Ë¾ÄÚ²¿ÍøÂçÖйܿء£¡£¡£¡£¡£¡£ÁíÍ⣬£¬£¬£¬£¬HarborÒ²ÌṩÁ˸߼¶µÄÇå¾²ÌØÕ÷£¬£¬£¬£¬£¬ÖîÈçÓû§ÖÎÀí£¬£¬£¬£¬£¬»á¼û¿ØÖƺͻÉó¼ÆµÈ¡£¡£¡£¡£¡£¡£
¿ËÈÕHarborÆØ³öÒ»¸ö±ÊֱԽȨÎó²î£¬£¬£¬£¬£¬Òò×¢²áÄ£¿£¿£¿£¿£¿£¿£¿é¶Ô²ÎÊýУÑé²»ÑϿᣬ£¬£¬£¬£¬¿Éµ¼ÖÂí§ÒâÖÎÀíÔ±×¢²á¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý×¢²áÖÎÀíÔ±Õ˺ÅÀ´½ÓÊÜHarbor¾µÏñ¿ÍÕ»£¬£¬£¬£¬£¬´Ó¶øÐ´Èë¶ñÒâ¾µÏñ£¬£¬£¬£¬£¬×îÖÕ¿ÉÒÔѬȾʹÓô˿ÍÕ»µÄ¿Í»§¶Ë¡£¡£¡£¡£¡£¡£
ÏÖÔÚº£ÄÚ̻¶ÔÚ¹«ÍøµÄÔÚÏßʵÀýÓÐ2034¸ö£¬£¬£¬£¬£¬ÈçÏÂͼ£º
HarborÔÚÒÑÍùËÄÄêÖÐÖð½¥ÆÕ¼°£¬£¬£¬£¬£¬ÔÚÆä½ÓÄÉÕßÒ³ÃæÖаüÀ¨Ðí¶àÖøÃûµÄÔÞÖúÉ̺͹«Ë¾£º
¡ñÎó²îÑéÖ¤
POCÊÓÆµ£ºhttps://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/£¬£¬£¬£¬£¬Ê¹ÓÃÀÖ³ÉÈçÏÂͼ£º
¡ñÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://github.com/goharbor/harbor/pull/8917¡£¡£¡£¡£¡£¡£
¡ñ²Î¿¼Á´½Ó
https://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/