CVE-2020-11710| Kong Admin Rest APIδÊÚȨ½Ó¼û·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-16

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-11710

ʱ    ¼ä

2020-04-16

Àà    ÐÍ

UA

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Kong <= 2.0.3


0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



docker-kongÊÇÒ»¿îʹÓÃÔÚDockerÀûÓÃÈÝÆ÷ÒýÇæÖеÄAPI3Íø¹Ø²úÆ·¡£¡£¡£¡£ ¡£¡£¡£Kong APIÍø¹ØÊÇĿǰ×îÊÜ»¶Ó­µÄÔÆÔ­ÉúAPIÍø¹ØÖ®Ò»£¬£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý²å¼þµÄ´ó¾ÖÌṩ¸ºÔØÆ½ºâµÈ¶à³ÁÖ°ÄÜ¡£¡£¡£¡£ ¡£¡£¡£


Kong APIÍø¹ØÔÚĬÈÏDocker²¿ÊðµÄÇé¿öÏ´æÔÚδÊÚȨ½Ó¼û·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8¡£¡£¡£¡£ ¡£¡£¡£ÔÚʹÓÃDockerÈÝÆ÷µÄ·½Ê½´î½¨Kong APIÍø¹ØÊ±£¬£¬£¬ £¬£¬£¬£¬£¬Ä¬ÈÏÅäÖûὫδ¾­¼øÈ¨µÄAdmin Rest API¶³öÔÚ¹«Íø£¬£¬£¬ £¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Î´ÊÚȨ½Ó¼ûAdmin Rest API£¬£¬£¬ £¬£¬£¬£¬£¬½øÒ»²½½ÚÔìKong APIÍø¹Ø¡£¡£¡£¡£ ¡£¡£¡£


0x02 ´ëÖý¨Òé


Éý¼¶²¹¶¡£¬£¬£¬ £¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º

https://github.com/Kong/docker-kong/commit/dfa095cadf7e8309155be51982d8720daf32e31c

һʱ´ëÊ©£º

? ½«Kong Admin APIĬÈϼàÌý¶Ë¿Ú£¨Ä¬ÈÏ8001ºÍ8444£©ÉèΪ²»ÈݶԹ«ÍøÊ¢¿ª£¬£¬£¬ £¬£¬£¬£¬£¬»ò½ö¶Ô¿ÉÐŶÔÏóÊ¢¿ª£»£»£»£» £»

? Åú¸Ä docker-compose.yaml ÖеÄÄÚÈݽ«¶Ë¿ÚÓ³ÉäÏÞ¶ÈΪ 127.0.0.1¡£¡£¡£¡£ ¡£¡£¡£


0x03 ÓйØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-11710


0x04 ²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2020-11710

https://github.com/Kong/kong


0x05 ¹¦·òÏß


2020-03-31 Kong½¨¸´¸Ã·ì϶

2020-04-12 CVE °ä²¼¸Ã·ì϶