¡¾·ì϶¹«¸æ¡¿GitLab Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-2185£©

°ä²¼¹¦·ò 2022-07-01
 

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2022-2185

·¢ÏÖ¹¦·ò

2022-07-01

Àà    ÐÍ

´úÂëÖ´ÐÐ

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

GitLabÊÇÒ»¸öÓÃÓÚ²Ö¿âÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬ £¬£¬£¬£¬£¬ÆäʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬ £¬£¬£¬£¬£¬¿Éͨ¹ýWeb½çÃæ½Ó¼û¹«¿ª»ò¸öÈËÏîÄ¿¡£¡£¡£¡£¡£

7ÔÂ1ÈÕ£¬ £¬£¬£¬£¬£¬GitLab°ä²¼°²È«²¼¸æ£¬ £¬£¬£¬£¬£¬½¨¸´ÁËGitLabÉçÇø°æ£¨CE£©ºÍÆóÒµ°æ£¨EE£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-2185£©£¬ £¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.9£¬ £¬£¬£¬£¬£¬Ê¹µÃÊÚȨÓû§Äܹ»Í¨¹ýµ¼Èë¶ñÒâÔì×÷µÄÏîĿʵÏÖÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£

´Ë±í£¬ £¬£¬£¬£¬£¬GitLab»¹½¨¸´ÁËGitLab EEÖеĿçÕ¾¾ç±¾·ì϶£¨CVE-2022-2235£¬ £¬£¬£¬£¬£¬CVSSÆÀ·Ö8.7£©ºÍGitLab CE/EE ÏîÄ¿ÉèÖÃÒ³ÃæÖеĴ洢ÐÍ¿çÕ¾¾ç±¾·ì϶£¨CVE-2022-2230£¬ £¬£¬£¬£¬£¬CVSSÆÀ·Ö8.1£©£¬ £¬£¬£¬£¬£¬Ç°Õß¿ÉÄܵ¼ÖÂÔÚ´¥·¢Ê±Ö´ÐжñÒâ²Ù×÷£¬ £¬£¬£¬£¬£¬ºóÕß¿ÉÄܵ¼ÖÂÒÔÊܺ¦ÕßµÄÃûÒåÔÚGitLabÖÐÖ´ÐÐËÁÒâJavaScript´úÂë¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

CVE-2022-2185£º

GitLab CE/EE 14.0°æ±¾£º< 14.10.5

GitLab CE/EE 15.0°æ±¾£º< 15.0.4

GitLab CE/EE 15.1°æ±¾£º< 15.1.1

CVE-2022-2235£º

GitLab EE 14.5°æ±¾£º< 14.10.5

GitLab EE 15.0°æ±¾£º< 15.0.4

GitLab EE 15.1°æ±¾£º< 15.1.1

CVE-2022-2230£º

GitLab CE/EE 14.4°æ±¾£º< 14.10.5

GitLab CE/EE 15.0°æ±¾£º< 15.0.4

GitLab CE/EE 15.1°æ±¾£º< 15.1.1

 

0x02 °²È«½¨Òé

ĿǰÉÏÊö·ì϶ÒѾ­½¨¸´£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§Äܹ»Éý¼¶µ½ÒÔϰ汾£º

GitLab CE/EE 14.10.5

GitLab CE/EE 15.0.4

GitLab CE/EE 15.1.1

ÏÂÔØÁ´½Ó£º

https://about.gitlab.com/update/

 

0x03 ²Î¿¼Á´½Ó

https://about.gitlab.com/releases/2022/06/30/critical-security-release-gitlab-15-1-1-released/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2185

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2022-07-01

³õ´Î°ä²¼

 

0x05 ¸½Â¼

8827Ì«Ñô¼¯Íżò½é

8827Ì«Ñô¼¯ÍųÉÁ¢ÓÚ1996Ä꣬ £¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°8827Ì«Ñô¼¯ÍÅ´óÏ㬠£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬ £¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ £¬£¬£¬£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÀö½­ÖÐÓ×°å¹ÒÅÆÉÏÊÓ×£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬ £¬£¬£¬£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬ £¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£¡£¡£¡£

 

¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬ £¬£¬£¬£¬£¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png