¡¾Îó²îͨ¸æ¡¿SplunkÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-20229)

Ðû²¼Ê±¼ä 2025-03-27

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

SplunkÔ¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-20229

Îó²îÀàÐÍ

Ô¶³Ì´úÂëÖ´ÐÐ

·¢Ã÷ʱ¼ä

2025-03-27

Îó²îÆÀ·Ö

8.0

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Splunk EnterpriseÊÇÒ»¿îǿʢµÄÊý¾ÝÆÊÎöƽ̨£¬ £¬£¬£¬×¨×¢ÓÚ»úеÊý¾ÝµÄÍøÂç¡¢¼à¿ØºÍÆÊÎö£¬ £¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÈÕÖ¾ÖÎÀí¡¢Çå¾²ÐÅÏ¢ÊÂÎñÖÎÀí£¨SIEM£©ºÍITÔËά£¬ £¬£¬£¬Äܹ»×ÊÖú×é֯ʵʱ»ñÈ¡²Ù×÷Êý¾Ý¡¢¼ì²âÒì³£¡¢ÆÊÎöÇ÷ÊÆ£¬ £¬£¬£¬²¢Ìṩ¿ÉÊÓ»¯±¨±íºÍ¾¯±¨¹¦Ð§¡£¡£¡£¡£Splunk Cloud PlatformÊÇSplunkµÄÔÆ°æ±¾£¬ £¬£¬£¬ÌṩÓëEnterpriseÏàͬµÄÊý¾ÝÆÊÎö¹¦Ð§£¬ £¬£¬£¬µ«ÒÔSaaSÐÎʽÔËÐУ¬ £¬£¬£¬Óû§ÎÞÐè×ÔÐÐÖÎÀí»ù´¡ÉèÊ©¡£¡£¡£¡£ËüÊÊÓÃÓÚÐèÒª¸ß¶È¿ÉÀ©Õ¹ÐÔºÍÎÞаÐÔµÄÆóÒµ£¬ £¬£¬£¬Ö§³Ö¿çƽ̨¡¢¿çÇéÐεÄÊý¾ÝÆÊÎöºÍÖÎÀí£¬ £¬£¬£¬×ÊÖú×éÖ¯¸ßЧ´¦Öóͷ£´óÊý¾Ý£¬ £¬£¬£¬²¢ÊµÏÖÉîÈëµÄÖÇÄܶ´²ì¡£¡£¡£¡£


2025Äê3ÔÂ27ÈÕ£¬ £¬£¬£¬Z6×ðÁú¿­Ê±¼¯ÍÅVSRC¼à²âµ½SplunkÐû²¼µÄÇ徲ͨ¸æ£¬ £¬£¬£¬Í¨¸æÖ¸³öSplunk EnterpriseºÍSplunk Cloud Platform±£´æÒ»¸ö¸ßΣÎó²î¡£¡£¡£¡£ÔÚÌØ¶¨°æ±¾ÖУ¬ £¬£¬£¬µÍȨÏÞÓû§£¨Î´³ÖÓÐ"admin"»ò"power"½ÇÉ«£©ÓÉÓÚȱ·¦ÐëÒªµÄÊÚȨ¼ì²é£¬ £¬£¬£¬¿ÉÄÜͨ¹ý½«ÎļþÉÏ´«ÖÁ¡°$SPLUNK_HOME/var/run/splunk/apptemp¡±Ä¿Â¼£¬ £¬£¬£¬´Ó¶øÖ´ÐÐÔ¶³Ì´úÂ루RCE£©¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


9.3.2408.100 <= Splunk Cloud Platform <= 9.3.2408.103
9.2.2406.100 <= Splunk Cloud Platform <= 9.2.2406.107
Splunk Cloud Platform < 9.2.2403.113
Splunk Cloud Platform < 9.1.2312.207
9.3.0 <= Splunk Enterprise <= 9.3.2
9.2.0 <= Splunk Enterprise 9.2.4
9.1.0 <= Splunk Enterprise 9.1.7


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾£¬ £¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì¸üС£¡£¡£¡£


Splunk Enterprise 9.4Éý¼¶µ½9.4.0
Splunk Enterprise 9.3ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.3.3
Splunk Enterprise 9.2ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.2.5
Splunk Enterprise 9.1ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.1.8
Splunk Cloud Platform 9.3.2408ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.3.2408.104
Splunk Cloud Platform 9.2.2406ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.2.2406.108
Splunk Cloud Platform 9.2.2403ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.2.2403.114
Splunk Cloud Platform 9.1.2312ÊÜÓ°Ïì°æ±¾Éý¼¶µ½9.1.2312.208


ÏÂÔØÁ´½Ó£ºhttps://www.splunk.com/en_us/download.html/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://advisory.splunk.com/advisories/SVD-2025-0301