Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Kibana ÔÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2025-25015 |
Îó²îÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-07 |
Îó²îÆÀ·Ö | 9.9 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
KibanaÊÇElastic Stack£¨ELK£©µÄ¿ÉÊÓ»¯ºÍÆÊÎö¹¤¾ß£¬£¬£¬Ö÷ÒªÓÃÓÚÈÕÖ¾ºÍÖ¸±êÊý¾ÝµÄչʾ¡£¡£¡£¡£¡£¡£ËüÖ§³ÖÊý¾Ý̽Ë÷¡¢ÒDZí°å½¨Éè¡¢»úеѧϰÆÊÎö¡¢¾¯±¨ÖÎÀíµÈ¹¦Ð§£¬£¬£¬³£ÓëElasticsearch´îÅäʹÓ㬣¬£¬ÆÕ±éÓ¦ÓÃÓÚÈÕÖ¾ÆÊÎö¡¢Çå¾²¼à¿ØºÍÓªÒµÊý¾Ý¿ÉÊÓ»¯¡£¡£¡£¡£¡£¡£
2025Äê3ÔÂ7ÈÕ£¬£¬£¬¼øºÚµ£±£ÍøVSRC¼à²âµ½elasticÐû²¼ÁËCVE-2025-25015Ïà¹ØÇ徲ͨ¸æ¡£¡£¡£¡£¡£¡£Í¨¸æÖ¸³ö£¬£¬£¬Kibana±£´æÔÐÍÎÛȾ£¨Prototype Pollution£©Îó²î£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÖÆÎļþºÍ·¢ËÍÈ«ÐĽṹµÄHTTPÇëÇ󣬣¬£¬ÊµÏÖí§Òâ´úÂëÖ´ÐУ¨Arbitrary Code Execution£©¡£¡£¡£¡£¡£¡£ÔÚKibana°æ±¾¡Ý8.15.0ÇÒ<8.17.1ÖУ¬£¬£¬¸ÃÎó²î¿É±»Viewer½ÇÉ«µÄÓû§Ê¹Óᣡ£¡£¡£¡£¡£ÔÚKibana 8.17.1ºÍ8.17.2°æ±¾ÖУ¬£¬£¬Îó²îʹÓùæÄ£Êܵ½ÏÞÖÆ£¬£¬£¬½ö¾ß±¸ÒÔÏÂËùÓÐȨÏÞµÄÓû§¿É´¥·¢¸ÃÎó²î£ºfleet-all¡¢integrations-all¡¢actions:execute-advanced-connectors¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
8.15.0 ¡Ü Kibana < 8.17.3
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
elastic¹Ù·½ÒÑÔÚÈçϰ汾ÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£¡£¡£½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶£¬£¬£¬ÒÔ½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://www.elastic.co/cn/downloads/kibana/
3.2 ÔÝʱ²½·¥
ÎÞ·¨Éý¼¶µÄÓû§¿ÉÔÚKibanaÉèÖÃÎļþÖÐÌí¼ÓÒÔÏÂÉèÖÃÒÔ»º½âΣº¦xpack.integration_assistant.enabled: false¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441https://nvd.nist.gov/vuln/detail/CVE-2025-25015