ZABBIX SQL×¢Èë·ì϶À´Ï®£¬GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2024-05-23

ZabbixÊÇÒ»¸ö»ùÓÚWEB½çÃæµÄÆóÒµ¼¶¿ªÔ´½â¾ö¹æ»®£¬ÓÃÓÚÌṩɢ²¼Ê½ÏµÍ³¼à¶½ºÍÍøÂç¼à¶½Ö°ÄÜ£¬±£ÕÏ·þÎñÆ÷ϵͳµÄ°²È«ÔËÓª£¬±ãÓÚϵͳÖÎÀíÔ±¼±¾ç¶¨Î»ºÍ½â¾ö´æÔڵĸ÷ÀàÎÊÌâ¡£


ÆäÖØÒªÓÉÁ½¸öÖØÒª×é¼þ×é³É£ºZabbix serverºÍ¿ÉÑ¡µÄZabbix agent¡£ÆäÖУ¬Zabbix server¿ÉÄÜͨ¹ýSNMP¡¢Zabbix agent¡¢ping¡¢¶Ë¿Ú¼à¶½µÈ²½Öè¶ÔÔ¶³Ì·þÎñÆ÷ºÍÍøÂç״̬½øÐмලºÍÊý¾ÝÍøÂ磬¿ÉÔÚLinux¡¢Solaris¡¢HP-UX¡¢AIX¡¢Free BSD¡¢Open BSD¡¢OS XµÈ¶àÖÔì½Ì¨ÉÏÔËÐС£


·ì϶ÏêÇé


2024Äê5ÔÂ21ÈÕ£¬GA»Æ½ð¼×½ð¾¦°²È«×êÑÐÍÅ¶Ó¼à¿Øµ½Zabbix SQL×¢Èë·ì϶£¨CVE-2024-22120£©µý±¨¡£¸Ã·ì϶´æÔÚÓÚaudit.cµÄzbx_auditlog_global_scriptº¯ÊýÖУ¬ÓÉÓÚclientip×Ö¶Îδ¾­ËãÕÊ£¬¿ÉÄܵ¼ÖÂSQL¹¦·òäע¹¥»÷¡£¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶´ÓÊý¾Ý¿âÖлñÈ¡Ãô¸ÐÐÅÏ¢£¬²¢¿É½«È¨ÏÞÌáÉýΪÖÎÀíÔ±»òÔ¶³ÌÖ´ÐдúÂë¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶¸´ÏÖ½ØÍ¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀûÓÃÖÎÀíÔ±session¼°keyÊÕÊÜÖÎÀíÔ¹ØË»§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½øÐÐcookie´úÌæºóË¢ÐÂÒ³Ãæ¼´¿ÉÊÕÊÜzabbixÖÎÀíÔ±


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó°Ïì°æ±¾


6.0.0 <= Zabbix <= 6.0.27

6.4.0 <= Zabbix <= 6.4.12

7.0.0alpha1 <= Zabbix <= 7.0.0beta1


½¨¸´½¨Òé


1¡¢¹Ù·½½¨¸´¹æ»®


¹Ù·½ÒѰ䲼°²È«¸üУ¬ZabbixÍŶӰ䲼Á˲¹¶¡ÒÔ½â¾ö°æ±¾6.0.28rc1¡¢6.4.13rc1ºÍ7.0.0beta2Öеķì϶¡£

µØÖ·£ºhttps://www.zabbix.com/download


2¡¢GA»Æ½ð¼×¹æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¡¢ÌìÇåWebÀûÓð²È«Íø¹Ø£¨WAF£©Éý¼¶µ½20240523°æ±¾¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ¡£