CVE-2020-11710| Kong Admin Rest APIδÊÚȨ½Ó¼û·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-160x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-11710 |
ʱ ¼ä |
2020-04-16 |
|
Àà ÐÍ |
UA |
µÈ ¼¶ |
ÑϳÁ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Kong <= 2.0.3 |
0x01 ·ì϶ÏêÇé
docker-kongÊÇÒ»¿îʹÓÃÔÚDockerÀûÓÃÈÝÆ÷ÒýÇæÖеÄAPI3Íø¹Ø²úÆ·¡£Kong APIÍø¹ØÊÇĿǰ×îÊÜÓ½ÓµÄÔÆÔÉúAPIÍø¹ØÖ®Ò»£¬Í¨¹ý²å¼þµÄ´ó¾ÖÌṩ¸ºÔØÆ½ºâµÈ¶à³ÁÖ°ÄÜ¡£
Kong APIÍø¹ØÔÚĬÈÏDocker²¿ÊðµÄÇé¿öÏ´æÔÚδÊÚȨ½Ó¼û·ì϶£¬CVSSÆÀ·Ö9.8¡£ÔÚʹÓÃDockerÈÝÆ÷µÄ·½Ê½´î½¨Kong APIÍø¹ØÊ±£¬Ä¬ÈÏÅäÖûὫδ¾¼øÈ¨µÄAdmin Rest API¶³öÔÚ¹«Íø£¬µ¼Ö¹¥»÷ÕßÄܹ»Î´ÊÚȨ½Ó¼ûAdmin Rest API£¬½øÒ»²½½ÚÔìKong APIÍø¹Ø¡£
0x02 ´ëÖý¨Òé
Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º
https://github.com/Kong/docker-kong/commit/dfa095cadf7e8309155be51982d8720daf32e31c
һʱ´ëÊ©£º
? ½«Kong Admin APIĬÈϼàÌý¶Ë¿Ú£¨Ä¬ÈÏ8001ºÍ8444£©ÉèΪ²»ÈݶԹ«ÍøÊ¢¿ª£¬»ò½ö¶Ô¿ÉÐŶÔÏóÊ¢¿ª£»
? Åú¸Ä docker-compose.yaml ÖеÄÄÚÈݽ«¶Ë¿ÚÓ³ÉäÏÞ¶ÈΪ 127.0.0.1¡£
0x03 ÓйØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-11710
0x04 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2020-11710
https://github.com/Kong/kong
0x05 ¹¦·òÏß
2020-03-31 Kong½¨¸´¸Ã·ì϶
2020-04-12 CVE °ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ