CVE-2020-11710| Kong Admin Rest APIδÊÚȨ½Ó¼û·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-160x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-11710 |
ʱ ¼ä |
2020-04-16 |
|
Àà ÐÍ |
UA |
µÈ ¼¶ |
ÑϳÁ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Kong <= 2.0.3 |
0x01 ·ì϶ÏêÇé
docker-kongÊÇÒ»¿îʹÓÃÔÚDockerÀûÓÃÈÝÆ÷ÒýÇæÖеÄAPI3Íø¹Ø²úÆ·¡£¡£¡£¡£¡£¡£¡£Kong APIÍø¹ØÊÇĿǰ×îÊÜ»¶ÓµÄÔÆÔÉúAPIÍø¹ØÖ®Ò»£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý²å¼þµÄ´ó¾ÖÌṩ¸ºÔØÆ½ºâµÈ¶à³ÁÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£
Kong APIÍø¹ØÔÚĬÈÏDocker²¿ÊðµÄÇé¿öÏ´æÔÚδÊÚȨ½Ó¼û·ì϶£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£ÔÚʹÓÃDockerÈÝÆ÷µÄ·½Ê½´î½¨Kong APIÍø¹ØÊ±£¬£¬£¬£¬£¬£¬£¬£¬Ä¬ÈÏÅäÖûὫδ¾¼øÈ¨µÄAdmin Rest API¶³öÔÚ¹«Íø£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Î´ÊÚȨ½Ó¼ûAdmin Rest API£¬£¬£¬£¬£¬£¬£¬£¬½øÒ»²½½ÚÔìKong APIÍø¹Ø¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Éý¼¶²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://github.com/Kong/docker-kong/commit/dfa095cadf7e8309155be51982d8720daf32e31c
һʱ´ëÊ©£º
? ½«Kong Admin APIĬÈϼàÌý¶Ë¿Ú£¨Ä¬ÈÏ8001ºÍ8444£©ÉèΪ²»ÈݶԹ«ÍøÊ¢¿ª£¬£¬£¬£¬£¬£¬£¬£¬»ò½ö¶Ô¿ÉÐŶÔÏóÊ¢¿ª£»£»£»£»£»
? Åú¸Ä docker-compose.yaml ÖеÄÄÚÈݽ«¶Ë¿ÚÓ³ÉäÏÞ¶ÈΪ 127.0.0.1¡£¡£¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-11710
0x04 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2020-11710
https://github.com/Kong/kong
0x05 ¹¦·òÏß
2020-03-31 Kong½¨¸´¸Ã·ì϶
2020-04-12 CVE °ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ