Docker×ÊÔ´ÖÎÀíÃýÎó·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-24

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-17150£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Docker < 0.6.3


·ì϶¸ÅÊö


DockerÊÇÃÀ¹úDocker¹«Ë¾µÄÒ»¿î¿ªÔ´µÄÀûÓÃÈÝÆ÷ÒýÇæ¡£¸Ã²úÆ·Ö§³ÖÔÚLinuxϵͳÉÏ´´½¨Ò»¸öÈÝÆ÷£¨ÇáÁ¿¼¶Ðé¹¹»ú£©²¢²¿ÊðºÍÔËÐÐÀûÓ÷¨Ê½£¬ÒÔ¼°Í¨¹ýÅäÖÃÎļþʵÏÖÀûÓ÷¨Ê½µÄ×Ô¶¯°ç×°Öᢲ¿ÊðºÍÉý¼¶¡£


DockerÖеÄdocker-credential-secretservice´æÔÚ×ÊÔ´ÖÎÀíÃýÎó·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½ÔÚ¶Ô¶ÔÏó½øÐпªÊͲÙ×÷֮ǰ£¬Ã»Óв鳭¸Ã¶ÔÏóÊÇ·ñ´æÔÚ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáÉýȨÏÞ²¢Ö´ÐдúÂë¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.docker.com/¡£


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/ZDI-19-1030/