¡¾·ì϶¹«¸æ¡¿SplunkÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-20229)
°ä²¼¹¦·ò 2025-03-27Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | SplunkÔ¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-20229 | ||
·ì϶ÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-03-27 |
·ì϶ÆÀ·Ö | 8.0 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Splunk EnterpriseÊÇÒ»¿î׳´óµÄÊý¾Ý·ÖÎöƽ̨£¬×¨Ò»ÓÚ»úеÊý¾ÝµÄÍøÂç¡¢¼à¿ØºÍ·ÖÎö£¬¿í·ºÀûÓÃÓÚÈÕÖ¾ÖÎÀí¡¢°²È«ÐÅÏ¢ÊÂÎñÖÎÀí£¨SIEM£©ºÍITÔËά£¬¿ÉÄÜÔ®ÊÖ×é֯ʵʱ»ñÈ¡²Ù×÷Êý¾Ý¡¢¼ì²âÒì³£¡¢·ÖÎöÇ÷Ïò£¬²¢Ìṩ¿ÉÊÓ»¯±¨±íºÍ¾¯±¨Ö°ÄÜ¡£Splunk Cloud PlatformÊÇSplunkµÄÔÆ°æ±¾£¬ÌṩÓëEnterpriseÒ»ÑùµÄÊý¾Ý·ÖÎöÖ°ÄÜ£¬µ«ÒÔSaaS´ó¾ÖÔËÐУ¬Óû§ÎÞÐè×ÔÐÐÖÎÀí»ù´¡ÉèÊ©¡£ËüºÏÓÃÓÚ±ØÒª¸ß¶È¿ÉÀ©´óÐԺͽýÝÐÔµÄÆóÒµ£¬Ö§³Ö¿çƽ̨¡¢¿ç»·¾³µÄÊý¾Ý·ÖÎöºÍÖÎÀí£¬Ô®ÊÖ×éÖ¯¸ßЧ´¦ÖôóÊý¾Ý£¬²¢ÊµÏÖÉî¿ÌµÄÖÇÄܶ´²ì¡£
2025Äê3ÔÂ27ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Splunk°ä²¼µÄ°²È«²¼¸æ£¬²¼¸æÖ¸³öSplunk EnterpriseºÍSplunk Cloud Platform´æÔÚÒ»¸ö¸ßΣ·ì϶¡£ÔÚÌØ¶¨°æ±¾ÖУ¬µÍȨÏÞÓû§£¨Î´³ÖÓÐ"admin"»ò"power"½ÇÉ«£©ÓÉÓÚ²»×ã±ØÒªµÄÊÚȨ²é³£¬¿ÉÄÜͨ¹ý½«ÎļþÉÏ´«ÖÁ¡°$SPLUNK_HOME/var/run/splunk/apptemp¡±Ä¿Â¼£¬´Ó¶øÖ´ÐÐÔ¶³Ì´úÂ루RCE£©¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒѰ䲼½¨¸´°æ±¾£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì¸üС£
ÏÂÔØÁ´½Ó£ºhttps://www.splunk.com/en_us/download.html/
3.2 һʱ´ëÊ©
3.3 ͨÓý¨Òé
3.4 ²Î¿¼Á´½Ó
https://advisory.splunk.com/advisories/SVD-2025-0301


¾©¹«Íø°²±¸11010802024551ºÅ