¡¾·ì϶¹«¸æ¡¿Kubernetes ingress-nginx½ÚÔìÆ÷ËÁÒâ´úÂëÖ´Ðзì϶(CVE-2025-1974)
°ä²¼¹¦·ò 2025-03-28Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Kubernetes ingress-nginx½ÚÔìÆ÷ËÁÒâ´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-1974 | ||
·ì϶ÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-03-28 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
ingress-nginx½ÚÔìÆ÷ÊÇKubernetesÖеÄÒ»¸ö¹Ø¼ü×é¼þ£¬£¬£¬£¬£¬ÓÃÓÚÖÎÀí¼¯ÈºÄÚ²¿ºÍ±í²¿Á÷Á¿µÄ½Ó¼û½ÚÔì¡£¡£¡£¡£¡£¡£¡£Ëüͨ¹ý½ç˵Ingress×ÊÔ´À´ÅäÖÃHTTPºÍHTTPS·ÓÉ£¬£¬£¬£¬£¬ÊµÏÖ¸ºÔØÆ½ºâ¡¢SSLÖÕÖ¹¡¢·´Ïò´úÀíµÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¸Ã½ÚÔìÆ÷»ùÓÚNGINX£¬£¬£¬£¬£¬Ö§³Ö½Ã½ÝµÄÁ÷Á¿ÖÎÀíÕ½ÊõºÍ¸ß¿ÉÀ©´óÐÔ¡£¡£¡£¡£¡£¡£¡£
2025Äê3ÔÂ28ÈÕ£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½Kubernetes°ä²¼µÄ°²È«²¼¸æ£¬£¬£¬£¬£¬Ö¸³öÔÚKubernetesÖз¢ÏÖÁËÒ»¸öÑϳÁµÄ°²È«·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìingress-nginx½ÚÔìÆ÷¡£¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½öÐè½Ó¼ûPodÍøÂ磬£¬£¬£¬£¬±ã¿ÉÔÚingress-nginx½ÚÔìÆ÷¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬½ø¶øÐ¹Â¶½ÚÔìÆ÷¿É½Ó¼ûµÄSecrets¡£¡£¡£¡£¡£¡£¡£Ä¬ÈÏÇé¿öÏ£¬£¬£¬£¬£¬ingress-nginx½ÚÔìÆ÷ÓµÓнӼûÕû¸ö¼¯ÈºËùÓÐSecretsµÄȨÏÞ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬·ì϶µÈ¼¶ÑϳÁ¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°ÏìÁìÓò
ingress-nginx < v1.11.0
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/kubernetes/ingress-nginx/releases/


¾©¹«Íø°²±¸11010802024551ºÅ