Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Kibana ÔÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2025-25015 |
Îó²îÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-07 |
Îó²îÆÀ·Ö | 9.9 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
KibanaÊÇElastic Stack£¨ELK£©µÄ¿ÉÊÓ»¯ºÍÆÊÎö¹¤¾ß£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÈÕÖ¾ºÍÖ¸±êÊý¾ÝµÄչʾ¡£¡£¡£¡£ËüÖ§³ÖÊý¾Ý̽Ë÷¡¢ÒDZí°å½¨Éè¡¢»úеѧϰÆÊÎö¡¢¾¯±¨ÖÎÀíµÈ¹¦Ð§£¬£¬£¬£¬³£ÓëElasticsearch´îÅäʹÓ㬣¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÈÕÖ¾ÆÊÎö¡¢Çå¾²¼à¿ØºÍÓªÒµÊý¾Ý¿ÉÊÓ»¯¡£¡£¡£¡£
2025Äê3ÔÂ7ÈÕ£¬£¬£¬£¬Z6×ðÁú¿Ê±VSRC¼à²âµ½elasticÐû²¼ÁËCVE-2025-25015Ïà¹ØÇ徲ͨ¸æ¡£¡£¡£¡£Í¨¸æÖ¸³ö£¬£¬£¬£¬Kibana±£´æÔÐÍÎÛȾ£¨Prototype Pollution£©Îó²î£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÖÆÎļþºÍ·¢ËÍÈ«ÐĽṹµÄHTTPÇëÇ󣬣¬£¬£¬ÊµÏÖí§Òâ´úÂëÖ´ÐУ¨Arbitrary Code Execution£©¡£¡£¡£¡£ÔÚKibana°æ±¾¡Ý8.15.0ÇÒ<8.17.1ÖУ¬£¬£¬£¬¸ÃÎó²î¿É±»Viewer½ÇÉ«µÄÓû§Ê¹Óᣡ£¡£¡£ÔÚKibana 8.17.1ºÍ8.17.2°æ±¾ÖУ¬£¬£¬£¬Îó²îʹÓùæÄ£Êܵ½ÏÞÖÆ£¬£¬£¬£¬½ö¾ß±¸ÒÔÏÂËùÓÐȨÏÞµÄÓû§¿É´¥·¢¸ÃÎó²î£ºfleet-all¡¢integrations-all¡¢actions:execute-advanced-connectors¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
8.15.0 ¡Ü Kibana < 8.17.3
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
elastic¹Ù·½ÒÑÔÚÈçϰ汾ÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶£¬£¬£¬£¬ÒÔ½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://www.elastic.co/cn/downloads/kibana/
3.2 ÔÝʱ²½·¥
ÎÞ·¨Éý¼¶µÄÓû§¿ÉÔÚKibanaÉèÖÃÎļþÖÐÌí¼ÓÒÔÏÂÉèÖÃÒÔ»º½âΣº¦xpack.integration_assistant.enabled: false¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441https://nvd.nist.gov/vuln/detail/CVE-2025-25015