Apache Seata·´ÐòÁл¯Îó²îÀ´Ï®£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2024-09-23

Apache Seata ÊÇÒ»¿î¿ªÔ´µÄÂþÑÜʽÊÂÎñ½â¾ö¼Æ»®£¬ÖÂÁ¦ÓÚÔÚ΢·þÎñ¼Ü¹¹ÏÂÌṩ¸ßÐÔÄܺͼòÆÓÒ×ÓõÄÂþÑÜʽÊÂÎñ·þÎñ¡£


2024Äê9Ô£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼à¿Øµ½Apache Seata ¹Ù·½Ðû²¼ÁËCVE-2024-22399 Apache Seata Hessian·´ÐòÁл¯Îó²î¡£¸ÃÎó²îCVSS3.1ÏÖÔÚÆÀ·ÖΪ9.8·Ö£¬²¢ÇÒÆä×ÛºÏÆÀ¼¶Îª¡°³¬Î£¡±¡£


¾­Ñо¿È·¶¨£¬Apache Seata ÓÃÓÚ·þÎñ¶ËÓë¿Í»§¶ËͨѶµÄRPC ЭÒ飨ĬÈ϶˿ÚΪ8091£©ÒÔ¼°×Ô2.0.0 °æ±¾ÆðʵÏÖµÄRaft ЭÒéÐÂÎÅ£¬¾ùÖ§³Ö½ÓÄÉHessian ¾ÙÐÐÊý¾ÝµÄÐòÁл¯Óë·´ÐòÁл¯²Ù×÷¡£ÔÚ2.1.0 ¼°1.8.1 °æ±¾Ö®Ç°£¬SeataÔÚ´¦Öóͷ£RPC ÇëÇóʱ£¬¶ÔRPC ÐÂÎÅÌåÖеÄÐòÁл¯Êý¾ÝУÑé»úÖƲ»·óÑÏ¿á¡£ÕâÒ»ÇéÐÎÖÂʹ¹¥»÷ÕßÄܹ»½á¹¹°üÀ¨¶ñÒâHessian ÐòÁл¯Êý¾ÝµÄÐÂÎÅÌ壬²¢·¢ËͶñÒâRPC ÇëÇó£¬×îÖÕ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÈôÀÖ³ÉʹÓôËÎó²î£¬¹¥»÷ÕßÔòÓпÉÄÜÍêÈ«ÕÆ¿ØÊÜÓ°ÏìµÄϵͳ£¬ÆäÖаüÀ¨»ñÈ¡Ãô¸ÐÊý¾ÝµÄ»á¼ûȨÏÞ¡¢Ö´ÐÐí§ÒâÖ¸Á»òÕßÌᳫ½øÒ»²½µÄÍøÂç¹¥»÷ÐÐΪ¡£ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì½ÓÄÉ·À»¤²½·¥¡£


ͼƬ1.png


Îó²î¸´ÏÖ


ͼƬ2.jpg


Ó°Ïì°æ±¾


Apache Seata 2.0.0 °æ±¾

Apache Seata 1.0.0 ÖÁ 1.8.0 °æ±¾


½â¾ö¼Æ»®


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®


ÏÖÔÚ¹Ù·½ÒÑÓпɸüа汾£¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾:

Apache Seata 2.1.0/1.8.1

¹Ù·½ÏÂÔصص㣺

https://github.com/apache/incubator-seata/releases/tag/v2.1.0


¶þ¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½â¾ö¼Æ»®


1¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖն˲úÆ·¼Æ»®


Ìì«‘ÖÕ¶ËÇå¾²Ò»Ì廯£¨EDR£©ÌṩÎó²îµÄרÏîÑéÖ¤¼ì²éÄÜÁ¦¶ÔÎó²îפÁôÖն˾ÙÐÐÈ«Íøͬ²½ÑéÖ¤£¬Í¬Ê±Ìṩʵʱ¸æ¾¯Òì³£×Ó¸¸Àú³Ì£¬¼à¿ØÖ÷»úÒì³£ÍâÁ¬¼ì²â»ò·ÀÓùÄÜÁ¦£¬µÖÓùÎó²î¹¥»÷Σº¦¡£


ͼƬ3.jpg


2¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ì²âÀà²úÆ·¼Æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½Ä¿½ñ×îа汾ÊÂÎñ¿â¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦£¬ÊÂÎñ¿âÏÂÔصص㣺

https://venustech.download.venuscloud.cn/


3¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø©ɨ²úÆ·¼Æ»®


£¨1£©¡°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÎó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£


ͼƬ4.png


£¨2£©ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÎó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£


ͼƬ5.png


4¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø×ʲúÓëųÈõÐÔÖÎÀíƽ̨£¨ASM£©²úÆ·¼Æ»®


ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø×ʲúÓëųÈõÐÔÖÎÀíƽ̨ʵʱÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬¶ÔÈë¿â×ʲúÎó²îApache Seata ·´ÐòÁл¯Îó²î£¨CVE-2024-22399£©¾ÙÐÐÖÎÀí¡£


ͼƬ6.png


5¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²ÖÎÀíºÍ̬ÊƸÐ֪ƽ̨²úÆ·¼Æ»®


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍ̬ÊƸÐ֪ƽ̨£¬¾ÙÐйØÁªÕ½ÂÔÉèÖã¬ÍŽáÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬´Ó¶ø·¢Ã÷¡°Apache Seata ·´ÐòÁл¯Îó²î£¨CVE-2024-22399£©¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£


£¨1£© ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Apache Seata ·´ÐòÁл¯Îó²î£¨CVE-2024-22399£©¡±Îó²îɨÃèʹÃü£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú¡£


ͼƬ7.png


£¨2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿éÖУ¬Ìí¼Ó¡°L2_Apache Seata ·´ÐòÁл¯Îó²î¡±£¬Í¨¹ýÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ¡£


ͼƬ8.png


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_Apache Seata·´ÐòÁл¯Îó²î"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓá£


£¨3£© Ìí¼Ó¡°L3_Apache Seata·´ÐòÁл¯Îó²î¡±£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_Apache Seata ·´ÐòÁл¯Îó²î¡±£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£


ͼƬ9.png


£¨4£©ATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé


ƾ֤¶ÔCVE-2024-22399Îó²îµÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒս׶Σ¬ÁýÕÖµÄTTP°üÀ¨£º


TA0001³õʼ»á¼û£ºT1190ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò

TA0002Ö´ÐУºT1059ÏÂÁîºÍ¾ç±¾Ú¹ÊÍÆ÷

TA0004ÌáȨ£º T1068ʹÓÃÎó²îÌáÉýȨÏÞ

TA0009Êý¾ÝÍøÂ磺 T1005´ÓÍâµØϵͳÍøÂçÊý¾Ý


ͼƬ10.png


ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍ̬ÊƸÐ֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦£¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾£¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£