·þÎñÆ÷¡¢´æ´¢¡¢ÍøÂç²úÆ·¹ºÖÃÈÈÏߣº400-860-6708 ERP¡¢¹ÜÀíÈí¼þ¹ºÖÃÈÈÏߣº400-018-7700ÔÆ·þÎñ²úÆ·ÏúÊÛÈÈÏߣº400-607-6657
Çå¾²Ô¤¾¯ - Éæ¼°K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾²¿·Ö²úÆ·µÄSaltStack RCEµÈÎó²îÇå¾²¸üÐÂ
Ô¤¾¯±àºÅ£ºINSPUR-SA-202005-001
³õʼÐû²¼Ê±¼ä£º2020-05-22 14:18:10
¸üÐÂÐû²¼Ê±¼ä£º2020-05-22 14:18:10
Îó²î¸ÅÊö£º

CVE-2020-11651£ºSaltStackÈÏÖ¤ÈÆ¹ýÎó²î,¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬿ÉÒÔÈÆ¹ýSalt MasterµÄÑéÖ¤Âß¼­£¬Å²ÓÃÏà¹ØÎ´ÊÚȨº¯Êý¹¦Ð§£¬´Ó¶ø¿ÉÒÔÔì³ÉÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£
CVE-2020-11652£ºSalt MasterĿ¼±éÀúÎó²î£¬¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬶ÁÈ¡·þÎñÆ÷ÉÏí§ÒâÎļþ¡£
ÆäËûµÚÈý·½×é¼þÎó²î£º
CVE-2015-5589£ºPHPÔ¶³Ì¾Ü¾ø·þÎñÎó²î
CVE-2016-2554£ºPHP»ùÓÚÕ»µÄ»º³åÇøÒç³öÎó²î
CVE-2018-7584£ºPHPÕ»»º³åÇøÒç³öÎó²î
CVE-2016-7568£ºPHPÕûÊýÒç³öÎó²î
CVE-2019-9023£ºPHP»º³åÇø¹ýʧÎó²î
CVE-2017-12933£ºPHP¶Ñ»º³åÇøÒç³öÎó²î

ÒÑÍê³ÉÐÞ¸´µÄ²úÆ·°æ±¾£º
²úÆ·Ãû³Æ ÊÜÓ°Ïì²úÆ·°æ±¾ ÐÞ¸´²¹¶¡°ü/Éý¼¶°ü°æ±¾
AS13000 3.6.3.9 Salt-2015.8-AS13000--3.6.3.9-update.zip
php-5.6.40-AS13000-3.6.3.9-update.zip
AS13000 3.6.3.9-SP1
AS13000 3.6.3.9-SP2
AS13000 3.6.3.9-SP3
AS13000 3.6.3.9-SP4
AS13000 3.6.3.9-SP5

Ó°ÏìЧ¹û£º

ÀÖ³ÉʹÓÃÉÏÊöÎó²î¿ÉʵÏÖÔ¶³Ì´úÂëÖ´Ðлòµ¼ÖÂPHP¾Ü¾ø·þÎñ¡£

Îó²îµÃ·Ö£º
CVE V3.1 Vector(Base) Base Score V3.1 Vector(Temporal Score) Temporal Score
CVE-2020-11651 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 E:F/RL:O/RC:C 9.1
CVE-2020-11652 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 6.5 E:F/RL:O/RC:C 6
CVE-2015-5589 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 E:U/RL:O/RC:C 8.5
CVE-2016-2554 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 E:P/RL:O/RC:C 8.8
CVE-2018-7584 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 E:P/RL:O/RC:C 8.8
CVE-2016-7568 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 E:U/RL:O/RC:C 8.5
CVE-2019-9023 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 E:P/RL:O/RC:C 8.8
CVE-2017-12933 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 E:U/RL:O/RC:C 8.5

ÊÖÒÕϸ½Ú£º

Îó²îʹÓÃÌõ¼þ£º
CVE-2020-11651£¬ÒªÇóÄ¿µÄϵͳ¿ªÆôsaltstack·þÎñ£¨Ä¬ÈÏ4506¶Ë¿Ú£©£¬²¢¿ÉÒÔͨ¹ý¹«Íø»á¼û¡£
Îó²îÏêϸÐÎò£º
CVE-2020-11651£¬¸ÃÎó²î¿É±»Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆµÄÇëÇóÔÚminion¶Ë·þÎñÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£

°æ±¾»ñÈ¡Á´½Ó£º

ÇëÓû§Ö±½ÓÁªÏµ¿Í»§·þÎñÖ°Ô±»ò·¢ËÍÓʼþÖÁsun.meng@inspur.com£¬»ñÈ¡²¹¶¡£¬ÒÔ¼°Ïà¹ØµÄÊÖÒÕЭÖú¡£

¹æ±Ü²½·¥£º

ÎÞ

Îó²îȪԴ£º

ÓÉÍâÑóijÇå¾²ÍŶӹûÕæÅû¶

¸üмͼ£º

20200519-V1.0-Initial Release

FAQs£º

ÎÞ

K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Çå¾²Ó¦¼±ÏìÓ¦¶ÔÍâ·þÎñ£º

K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Ò»Ö±Ö÷Õž¡È«Á¦°ü¹Ü²úÆ·Óû§µÄ×îÖÕÀûÒæ£¬×ñÕÕÈÏÕæÈεÄÇå¾²ÊÂÎñÅû¶ԭÔò£¬²¢Í¨¹ý²úÆ·Çå¾²ÎÊÌâ´¦Öóͷ£»úÖÆ´¦Öóͷ£²úÆ·Çå¾²ÎÊÌâ¡£
·´ÏìK8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾²úÆ·Ïà¹ØµÄÇå¾²ÎÊÌâ,ÇëÓʼþÖÁK8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾PSIRTÓÊÏäsec@inspur.com£¬ÏêÇé²Î¿¼£º
/lcjtww/2312126/2432763/index.html

¹ØÓÚK8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾

ÐÂÎÅÓëÔ˶¯

ÔõÑù¹ºÖÃ

̽Ë÷K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾

ͨÓ÷þÎñÆ÷ ´æ´¢ È˹¤ÖÇÄÜ °®¶¼»áÍø K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÔÆ K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÔÆERP

Ö§³ÖÓë·þÎñ

¿ìËÙÁ´½Ó

ºÏ×÷»ï°éÉú̬ µç×ӲɹºÆ½Ì¨ ͶÐÐÏîÄ¿ Ͷ×ÊÕß¹ØÏµ Æ·µÂ×ñ´Ó

ÔÚÉ罻ýÌåÉϹØ×¢ÎÒÃÇ

k8¡¤¿­·¢(Öйú)ÌìÉúÓ®¼Ò¡¤Ò»´¥¼´·¢

?1996 - 2020 INSPUR Co., Ltd. ³ICP±¸05019369ºÅ

³¹«Íø°²±¸ 37010202001184ºÅ

K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾

²¦´ò×Éѯµç»°

  • ·þÎñÆ÷¡¢´æ´¢¡¢ÍøÂç²úÆ·¹ºÖÃÈÈÏߣº

    400-860-6708

  • ERP¡¢¹ÜÀíÈí¼þ¹ºÖÃÈÈÏߣº

    400-018-7700

  • ÔÆ·þÎñ²úÆ·ÏúÊÛÈÈÏߣº

    400-607-6657

  • K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÍøÂçÊÛºóÈÈÏߣº

    400-691-1766

ºô½ÐÔÚÏ߿ͷþ

  • ·þÎñÆ÷´æ´¢ÍøÂç²úÆ·ÏúÊÛ ·þÎñÆ÷´æ´¢ÊÛºó ERPÊÛǰÊÛºó ÔÆ·þÎñ²úÆ·ÏúÊÛ
ÍøÕ¾µØÍ¼