HarborËÁÒâÖÎÀíÔ±×¢²á·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-19¡ñ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-16097£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º6.5
¡ñÓ°Ïì°æ±¾
Harbor 1.7.0°æ±¾ÖÁ1.8.2°æ±¾
¡ñ·ì϶¸ÅÊö
HarborÊÇÒ»¸öÓÃÓÚ´æ´¢ºÍ·Ö·¢Docker¾µÏñµÄÆóÒµ¼¶Registry·þÎñÆ÷£¬Í¨¹ýÔö³¤Ò»Ð©ÆóÒµ±ØÐëµÄÖ°ÄܸöÐÔ£¬ÀýÈ簲ȫ¡¢±êʶºÍÖÎÀíµÈ£¬À©´óÁË¿ªÔ´Docker Distribution¡£×÷Ϊһ¸öÆóÒµ¼¶Ë½ÓÐRegistry·þÎñÆ÷£¬HarborÌṩÁ˸üºÃµÄ»úÄܺͰ²È«¡£ÌáÉýÓû§Ê¹ÓÃRegistry¹¹½¨ºÍÔËÐл·¾³´«Êä¾µÏñµÄЧÄÜ¡£HarborÖ§³Ö×°ÖÃÔÚ¶à¸öRegistry½ÚµãµÄ¾µÏñ×ÊÔ´¸´Ô죬¾µÏñÈ«Êý±£ÁôÔÚ˽ÓÐRegistryÖУ¬ È·±£Êý¾ÝºÍ֪ʶ²úȨÔÚ¹«Ë¾ÄÚ²¿ÍøÂçÖйܿء£Áí±í£¬HarborÒ²ÌṩÁ˸߼¶µÄ°²È«¸öÐÔ£¬ÖîÈçÓû§ÖÎÀí£¬½Ó¼û½ÚÔìºÍ»î¶¯Éó¼ÆµÈ¡£
½üÈÕHarborÆØ³öÒ»¸ö´¹Ö±Ô½È¨·ì϶£¬Òò×¢²áÄ£¿é¶Ô²ÎÊýУÑé²»Ñϸñ£¬¿Éµ¼ÖÂËÁÒâÖÎÀíÔ±×¢²á¡£¹¥»÷ÕßÄܹ»Í¨¹ý×¢²áÖÎÀíÔ¹ØËºÅÀ´ÊÕÊÜHarbor¾µÏñ²Ö¿â£¬´Ó¶øÐ´Èë¶ñÒâ¾µÏñ£¬×îÖÕÄܹ»Ï°È¾Ê¹Óô˲ֿâµÄ¿Í»§¶Ë¡£
Ŀǰ¹úÄÚ¶³öÔÚ¹«ÍøµÄÔÚÏßÊ·ýÓÐ2034¸ö£¬ÈçÏÂͼ£º
HarborÔÚ´ÓǰËÄÄêÖÐÖ𲽱鼰£¬ÔÚÆäѡȡÕßÒ³ÃæÖÐÔ̺¬ºÜ¶à³ÛÃûµÄÔÞÖúÉ̺͹«Ë¾£º
¡ñ·ì϶ÑéÖ¤
POCÊÓÆµ£ºhttps://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/£¬ÀûÓóɹ¦ÈçÏÂͼ£º

¡ñ½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://github.com/goharbor/harbor/pull/8917¡£
¡ñ²Î¿¼Á´½Ó
https://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/


¾©¹«Íø°²±¸11010802024551ºÅ