¡¾Â©¶´Í¨¸æ¡¿GitLabÖØÖÃÃÜÂë©¶´£¨CVE-2023-7028£©
Ðû²¼Ê±¼ä 2024-01-12Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | GitLabÖØÖÃÃÜÂë©¶´ | ||
CVE ID | CVE-2023-7028 | ||
©¶´ÀàÐÍ | ÃÜÂëÖØÖà | ·¢ÏÖʱ¼ä | 2024-01-12 |
©¶´ÆÀ·Ö | 10.0 | ©¶´Æ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | δ֪ |
GitLabÊÇÒ»¸öÓÃÓÚ¶ÑÕ»¹ÜÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬ÆäʹÓÃGit×÷Ϊ´úÂë¹ÜÀí¹¤¾ß£¬¿Éͨ¹ýWeb½çÃæ·ÃÎʹûÈ»»ò˽ÈËÏîÄ¿¡£
2024Äê1ÔÂ12ÈÕ£¬¶«Éƽ̨VSRC¼à²âµ½GitLabÉçÇø°æ£¨CE£©ºÍÆóÒµ°æ£¨EE£©ÖÐÐÞ¸´ÁËÒ»¸öÖØÖÃÃÜÂë©¶´£¨CVE-2023-7028£©£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ10.0¡£
GitLab CE/EEÖÐÖ§³ÖÓû§Í¨¹ý¸¨Öúµç×ÓÓʼþµØÖ·ÖØÖÃÃÜÂë¡£GitLab CE/EE¶à¸öÊÜÓ°Ïì°æ±¾ÖУ¬ÓÉÓÚµç×ÓÓʼþÑéÖ¤¹ý³ÌÖдæÔÚ´íÎó£¬Óû§ÕÊ»§ÃÜÂëÖØÖõç×ÓÓʼþ¿ÉÒÔ·¢Ë͵½Î´¾ÑéÖ¤µÄµç×ÓÓʼþµØÖ·£¬¿ÉÄܵ¼ÖÂÔÚÎÞÐèÓû§½»»¥µÄÇé¿öÏÂͨ¹ýÃÜÂëÖØÖýøÐÐÕÊ»§½Ó¹Ü¡£
´ËÍ⣬GitLab CE/EE¶à¸öÊÜÓ°Ïì°æ±¾Öл¹ÐÞ¸´ÁËÒ»¸öÊÚȨ¼ì²é²»Íש¶´£¨CVE-2023-5356£¬CVSSv3ÆÀ·Ö9.6£©£¬¿ÉÄܵ¼ÖÂÓû§ÀÄÓÃSlack/Mattermost¼¯³ÉÒÔÆäËûÓû§µÄÉí·ÝÖ´ÐÐб¸ÜÃüÁî¡£
¶þ¡¢Ó°Ï췶Χ
CVE-2023-7028
GitLab CE/EE 16.1 < 16.1.5
GitLab CE/EE 16.2 < 16.2.8
GitLab CE/EE 16.3 < 16.3.6
GitLab CE/EE 16.4 < 16.4.4
GitLab CE/EE 16.5 < 16.5.6
GitLab CE/EE 16.6 < 16.6.4
GitLab CE/EE 16.7 < 16.7.2
CVE-2023-5356
8.13<= GitLab CE/EE°æ±¾ < 16.5.6
GitLab CE/EE 16.6 < 16.6.4
GitLab CE/EE 16.7 < 16.7.2
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
ĿǰÕâЩ©¶´ÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½GitLab CE/EE °æ±¾16.5.6¡¢16.6.4 ºÍ 16.7.2¡£´ËÍ⣬CVE-2023-7028µÄÄþ¾²ÐÞ¸´·¨Ê½ÒÑÏòºóÒÆÖ²µ½GitLab°æ±¾16.1.6¡¢16.2.9¡¢16.3.7ºÍ16.4.5¡£
ÏÂÔØÁ´½Ó£º
https://about.gitlab.com/
×¢£ºÕë¶ÔCVE-2023-7028£¬SSO Óû§£¨ÀýÈç SAML£©»áÊܵ½Ó°Ï죬µ« LDAP Óû§²»»áÊܵ½Ó°Ï죬ÒòΪûÓÐÍü¼Ç/ÖØÖÃÃÜÂëÑ¡Ïî¡£´ËÍ⣬ÆôÓÃÁËË«ÒòËØÉí·ÝÑéÖ¤µÄÓû§ºÜÈÝÒ×Êܵ½ÃÜÂëÖØÖõÄÓ°Ï죬µ«ÕÊ»§²»»á±»½Ó¹Ü£¬ÒòΪÐèÒªµÚ¶þ¸öÉí·ÝÑéÖ¤ÒòËØ²ÅÆøµÇ¼¡£
3.2 ÁÙʱ´ëÊ©
Õë¶ÔCVE-2023-7028£º
½¨ÒéÉý¼¶µ½µ±Ç°×îÐÂÐÞ¸´°æ±¾£¬ÈçÎÞ·¨Á¢¼´Éý¼¶£¬¿ÉΪËùÓÐ GitLab ÕÊ»§ÆôÓÃË«ÒòËØÉí·ÝÑéÖ¤(2FA)£¬ÓÈÆäÊǾßÓи߼¶È¨ÏÞµÄÓû§£¨ÀýÈç¹ÜÀíÔ±ÕÊ»§£©£»Èç¹ûÒѾÆôÓÃÁË2FA£¬ÍþвÕß½«ÎÞ·¨½Ó¹Ü¸ÃÕÊ»§£¬µ«Æä¿ÉÄÜÈÔÈ»Äܹ»ÖØÖÃÃÜÂ룬µ«ÎÞ·¨·ÃÎʵڶþÒòËØÉí·ÝÑéÖ¤ÒªÁì¡£
Óû§¿ÉÒÔ¼ì²ìÈÕÖ¾ÒÔ¼ì²éÊÇ·ñ´æÔÚ¿ÉÄܵÄ©¶´ÀûÓÃʵÑ飺
l ¼ì²é gitlab-rails/production_json.log£¬ÒÔ¼ì²ìÊÇ·ñ´æÔÚÖ¸Ïò /users/password ·¾¶µÄ HTTP ÇëÇ󣬯äÖаüÂÞparams.value.email£¬ÓɾßÓжà¸öµç×ÓÓʼþµØÖ·µÄjsonÊý×é×é³É¡£
l ¼ì²é gitlab-rails/audit_json.log£¬ÒÔ²éÕÒ°üÂÞmeta.caller.idµÄPasswordsController#createºÍtarget_detailsµÄÌõÄ¿£¬ÕâЩÌõÄ¿ÓɾßÓжà¸öµç×ÓÓʼþµØÖ·µÄjsonÊý×é×é³É¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/
https://nvd.nist.gov/vuln/detail/CVE-2023-7028
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-01-12 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º