HarborËÁÒâÖÎÀíÔ±×¢²á·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-19

¡ñ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-16097£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º6.5


¡ñÓ°Ïì°æ±¾


Harbor 1.7.0°æ±¾ÖÁ1.8.2°æ±¾


¡ñ·ì϶¸ÅÊö


HarborÊÇÒ»¸öÓÃÓÚ´æ´¢ºÍ·Ö·¢Docker¾µÏñµÄÆóÒµ¼¶Registry·þÎñÆ÷£¬£¬£¬£¬£¬£¬Í¨¹ýÔö³¤Ò»Ð©ÆóÒµ±ØÐëµÄÖ°ÄܸöÐÔ£¬£¬£¬£¬£¬£¬ÀýÈ簲ȫ¡¢±êʶºÍÖÎÀíµÈ£¬£¬£¬£¬£¬£¬À©´óÁË¿ªÔ´Docker Distribution¡£¡£¡£ ¡£¡£×÷Ϊһ¸öÆóÒµ¼¶Ë½ÓÐRegistry·þÎñÆ÷£¬£¬£¬£¬£¬£¬HarborÌṩÁ˸üºÃµÄ»úÄܺͰ²È«¡£¡£¡£ ¡£¡£ÌáÉýÓû§Ê¹ÓÃRegistry¹¹½¨ºÍÔËÐл·¾³´«Êä¾µÏñµÄЧÄÜ¡£¡£¡£ ¡£¡£HarborÖ§³Ö×°ÖÃÔÚ¶à¸öRegistry½ÚµãµÄ¾µÏñ×ÊÔ´¸´Ô죬£¬£¬£¬£¬£¬¾µÏñÈ«Êý±£ÁôÔÚ˽ÓÐRegistryÖУ¬£¬£¬£¬£¬£¬ È·±£Êý¾ÝºÍ֪ʶ²úȨÔÚ¹«Ë¾ÄÚ²¿ÍøÂçÖйܿØ¡£¡£¡£ ¡£¡£Áí±í£¬£¬£¬£¬£¬£¬HarborÒ²ÌṩÁ˸߼¶µÄ°²È«¸öÐÔ£¬£¬£¬£¬£¬£¬ÖîÈçÓû§ÖÎÀí£¬£¬£¬£¬£¬£¬½Ó¼û½ÚÔìºÍ»î¶¯É󼯵È¡£¡£¡£ ¡£¡£


½üÈÕHarborÆØ³öÒ»¸ö´¹Ö±Ô½È¨·ì϶£¬£¬£¬£¬£¬£¬Òò×¢²áÄ£¿£¿£¿£¿£¿£¿£¿£¿é¶Ô²ÎÊýУÑé²»Ñϸñ£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËÁÒâÖÎÀíÔ±×¢²á¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý×¢²áÖÎÀíÔ¹ØËºÅÀ´ÊÕÊÜHarbor¾µÏñ²Ö¿â£¬£¬£¬£¬£¬£¬´Ó¶øÐ´Èë¶ñÒâ¾µÏñ£¬£¬£¬£¬£¬£¬×îÖÕÄܹ»Ï°È¾Ê¹Óô˲ֿâµÄ¿Í»§¶Ë¡£¡£¡£ ¡£¡£


Ŀǰ¹úÄÚ¶³öÔÚ¹«ÍøµÄÔÚÏßÊ·ýÓÐ2034¸ö£¬£¬£¬£¬£¬£¬ÈçÏÂͼ£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website




8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


HarborÔÚ´ÓǰËÄÄêÖÐÖ𲽱鼰£¬£¬£¬£¬£¬£¬ÔÚÆäѡȡÕßÒ³ÃæÖÐÔ̺¬ºÜ¶à³ÛÃûµÄÔÞÖúÉ̺͹«Ë¾£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



¡ñ·ì϶ÑéÖ¤


POCÊÓÆµ£ºhttps://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/£¬£¬£¬£¬£¬£¬ÀûÓóɹ¦ÈçÏÂͼ£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website





8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¡ñ½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://github.com/goharbor/harbor/pull/8917¡£¡£¡£ ¡£¡£


¡ñ²Î¿¼Á´½Ó


https://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/