Harbor¶à¸ö·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-12-04·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-19029£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19026£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19025£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-3990£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19023£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-16919£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-16097£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Harbor 1.7.*
Harbor 1.8.*<1.8.6
Harbor 1.9.*<1.9.3
·ì϶¸ÅÊö
HarborÊÇÒ»¸öÓÃÓÚ´æ´¢ºÍ·Ö·¢Docker¾µÏñµÄÆóÒµ¼¶Registry·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÔö³¤Ò»Ð©ÆóÒµ±ØÐëµÄÖ°ÄܸöÐÔ£¬£¬£¬£¬£¬£¬£¬ÀýÈ簲ȫ¡¢±êʶºÍÖÎÀíµÈ£¬£¬£¬£¬£¬£¬£¬À©´óÁË¿ªÔ´Docker Distribution¡£¡£¡£¡£¡£¡£¡£¡£×÷Ϊһ¸öÆóÒµ¼¶Ë½ÓÐRegistry·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬HarborÌṩÁ˸üºÃµÄ»úÄܺͰ²È«¡£¡£¡£¡£¡£¡£¡£¡£ÌáÉýÓû§Ê¹ÓÃRegistry¹¹½¨ºÍÔËÐл·¾³´«Êä¾µÏñµÄЧÄÜ¡£¡£¡£¡£¡£¡£¡£¡£HarborÖ§³Ö×°ÖÃÔÚ¶à¸öRegistry½ÚµãµÄ¾µÏñ×ÊÔ´¸´Ô죬£¬£¬£¬£¬£¬£¬¾µÏñÈ«Êý±£ÁôÔÚ˽ÓÐRegistryÖУ¬£¬£¬£¬£¬£¬£¬È·±£Êý¾ÝºÍ֪ʶ²úȨÔÚ¹«Ë¾ÄÚ²¿ÍøÂçÖйܿء£¡£¡£¡£¡£¡£¡£¡£Áí±í£¬£¬£¬£¬£¬£¬£¬HarborÒ²ÌṩÁ˸߼¶µÄ°²È«¸öÐÔ£¬£¬£¬£¬£¬£¬£¬ÖîÈçÓû§ÖÎÀí£¬£¬£¬£¬£¬£¬£¬½Ó¼û½ÚÔìºÍ»î¶¯Éó¼ÆµÈ¡£¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝHarbor¹Ù·½°²È«¹«¸æ, Harbor´æÔÚÒÔϰ²È«ÎÊÌ⣺
CVE-2019-19026¡¢CVE-2019-19029·ì϶£ºHarbor´æÔÚSQL²éÎÊÓï¾ä¹ýÂ˲»Ñϵ¼ÖÂSQL×¢È룻£»£»£»£»£»£»£»
CVE-2019-19023·ì϶£ºHarborÔÚŲÓÃAPIʱδ¶ÔAPIÒªÇó½øÐÐÑϸñÏÞ¶È£¬£¬£¬£¬£¬£¬£¬´æÔÚͨ³£Óû§Äܹ»Í¨¹ýŲÓÃAPIÅú¸ÄÌØ¶¨Óû§µÄµç×ÓÓʼþµØÖ·£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñµÃÖÎÀíÔ¹ØÊ»§È¨ÏÞ£¬£¬£¬£¬£¬£¬£¬±ã¿É³ÁÖøõç×ÓÓʼþµØÖ·µÄÃÜÂë²¢»ñµÃ¶Ô¸ÃÕÊ»§µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2019-3990·ì϶£ºHarborÔÚʹÓÃapi/users/searchʱδ½øÐкÏÀíÉí·ÝУÑ飬£¬£¬£¬£¬£¬£¬´æÔÚÈÆ¹ýÖÎÀíÔ±Ï޶ȽøÐÐÓû§Ãûö¾Ù¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2019-19025·ì϶£ºHarborÔÚWeb½çÃæÔÚʹÓÃÖУ¬£¬£¬£¬£¬£¬£¬´æÔÚÉí·Ý¶þ´ÎУÑé²»ÑϵÄÇé¿ö£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂCSRFµÈ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2019-16919·ì϶£ºÈ¨ÏÞÌáÉý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2019-16097·ì϶£ºÔÊÐí·ÇÖÎÀíÔ±Óû§Í¨¹ýPOST / api / users API´´½¨ÖÎÀíÔ¹ØÊ»§¡£¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
¹Ù·½ÒѾ°ä²¼¸üв¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬½¨Òé¸üе½1.9.3ºÍ1.8.6ÒÔÉϰ汾£º
https://github.com/goharbor/harbor/releases/tag/v1.9.3
https://github.com/goharbor/harbor/releases/tag/v1.8.6
²Î¿¼Á´½Ó
https://github.com/goharbor/harbor/security/advisories


¾©¹«Íø°²±¸11010802024551ºÅ