Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Kibana ÔÐÍÎÛȾµ¼ÖÂÈÎÒâ´úÂëÖ´ÐЩ¶´ |
CVE ID | CVE-2025-25015 |
©¶´ÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢ÏÖʱ¼ä | 2025-03-07 |
©¶´ÆÀ·Ö | 9.9 | ©¶´Æ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
KibanaÊÇElastic Stack£¨ELK£©µÄ¿ÉÊÓ»¯ºÍ·ÖÎö¹¤¾ß£¬Ö÷ÒªÓÃÓÚÈÕÖ¾ºÍÖ¸±êÊý¾ÝµÄչʾ¡£ËüÖ§³ÖÊý¾Ý̽Ë÷¡¢ÒDZí°å´´½¨¡¢»úÆ÷ѧϰ·ÖÎö¡¢¾¯±¨¹ÜÀíµÈ¹¦Ð§£¬³£ÓëElasticsearch´îÅäʹÓ㬹㷺ӦÓÃÓÚÈÕÖ¾·ÖÎö¡¢Äþ¾²¼à¿ØºÍÒµÎñÊý¾Ý¿ÉÊÓ»¯¡£
2025Äê3ÔÂ7ÈÕ£¬¶«Éƽ̨VSRC¼à²âµ½elasticÐû²¼ÁËCVE-2025-25015Ïà¹ØÄþ¾²Í¨¸æ¡£Í¨¸æÖ¸³ö£¬Kibana´æÔÚÔÐÍÎÛȾ£¨Prototype Pollution£©Â©¶´£¬¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÖÆÎļþºÍ·¢Ë;«ÐĽṹµÄHTTPÇëÇó£¬ÊµÏÖÈÎÒâ´úÂëÖ´ÐУ¨Arbitrary Code Execution£©¡£ÔÚKibana°æ±¾¡Ý8.15.0ÇÒ<8.17.1ÖУ¬¸Ã©¶´¿É±»Viewer½ÇÉ«µÄÓû§ÀûÓá£ÔÚKibana 8.17.1ºÍ8.17.2°æ±¾ÖУ¬Â©¶´ÀûÓ÷¶Î§Êܵ½ÏÞÖÆ£¬½ö¾ß±¸ÒÔÏÂËùÓÐȨÏÞµÄÓû§¿É´¥·¢¸Ã©¶´£ºfleet-all¡¢integrations-all¡¢actions:execute-advanced-connectors¡£
¶þ¡¢Ó°Ï췶Χ
8.15.0 ¡Ü Kibana < 8.17.3
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
elastic¹Ù·½ÒÑÔÚÈçϰ汾ÖÐÐÞ¸´ÁË´Ë©¶´¡£½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶£¬ÒÔ½â¾ö¸ÃÎÊÌâ¡£
ÏÂÔØÁ´½Ó£ºhttps://www.elastic.co/cn/downloads/kibana/
3.2 ÁÙʱ´ëÊ©
ÎÞ·¨Éý¼¶µÄÓû§¿ÉÔÚKibanaÅäÖÃÎļþÖÐÌí¼ÓÒÔÏÂÉèÖÃÒÔ»º½â·çÏÕxpack.integration_assistant.enabled: false¡£
3.3 ͨÓý¨Òé
? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£? ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£? ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£? ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£? ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441https://nvd.nist.gov/vuln/detail/CVE-2025-25015