¡¾Îó²îͨ¸æ¡¿SplunkÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-20229)
Ðû²¼Ê±¼ä 2025-03-27Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | SplunkÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-20229 | ||
Îó²îÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-27 |
Îó²îÆÀ·Ö | 8.0 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Splunk EnterpriseÊÇÒ»¿îǿʢµÄÊý¾ÝÆÊÎöƽ̨£¬£¬£¬£¬£¬£¬£¬×¨×¢ÓÚ»úеÊý¾ÝµÄÍøÂç¡¢¼à¿ØºÍÆÊÎö£¬£¬£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÈÕÖ¾ÖÎÀí¡¢Çå¾²ÐÅÏ¢ÊÂÎñÖÎÀí£¨SIEM£©ºÍITÔËά£¬£¬£¬£¬£¬£¬£¬Äܹ»×ÊÖú×é֯ʵʱ»ñÈ¡²Ù×÷Êý¾Ý¡¢¼ì²âÒì³£¡¢ÆÊÎöÇ÷ÊÆ£¬£¬£¬£¬£¬£¬£¬²¢Ìṩ¿ÉÊÓ»¯±¨±íºÍ¾¯±¨¹¦Ð§¡£¡£¡£Splunk Cloud PlatformÊÇSplunkµÄÔÆ°æ±¾£¬£¬£¬£¬£¬£¬£¬ÌṩÓëEnterpriseÏàͬµÄÊý¾ÝÆÊÎö¹¦Ð§£¬£¬£¬£¬£¬£¬£¬µ«ÒÔSaaSÐÎʽÔËÐУ¬£¬£¬£¬£¬£¬£¬Óû§ÎÞÐè×ÔÐÐÖÎÀí»ù´¡ÉèÊ©¡£¡£¡£ËüÊÊÓÃÓÚÐèÒª¸ß¶È¿ÉÀ©Õ¹ÐÔºÍÎÞаÐÔµÄÆóÒµ£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¿çƽ̨¡¢¿çÇéÐεÄÊý¾ÝÆÊÎöºÍÖÎÀí£¬£¬£¬£¬£¬£¬£¬×ÊÖú×éÖ¯¸ßЧ´¦Öóͷ£´óÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢ÊµÏÖÉîÈëµÄÖÇÄܶ´²ì¡£¡£¡£
2025Äê3ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½SplunkÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬Í¨¸æÖ¸³öSplunk EnterpriseºÍSplunk Cloud Platform±£´æÒ»¸ö¸ßΣÎó²î¡£¡£¡£ÔÚÌØ¶¨°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬µÍȨÏÞÓû§£¨Î´³ÖÓÐ"admin"»ò"power"½ÇÉ«£©ÓÉÓÚȱ·¦ÐëÒªµÄÊÚȨ¼ì²é£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜͨ¹ý½«ÎļþÉÏ´«ÖÁ¡°$SPLUNK_HOME/var/run/splunk/apptemp¡±Ä¿Â¼£¬£¬£¬£¬£¬£¬£¬´Ó¶øÖ´ÐÐÔ¶³Ì´úÂ루RCE£©¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì¸üС£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://www.splunk.com/en_us/download.html/
3.2 ÔÝʱ²½·¥
3.3 ͨÓý¨Òé
3.4 ²Î¿¼Á´½Ó
https://advisory.splunk.com/advisories/SVD-2025-0301