Apache Seata·´ÐòÁл¯Îó²îÀ´Ï®£¬£¬¿Ðý¹ú¼ÊÓÎÏ·Ìṩ½â¾ö¼Æ»®
Ðû²¼Ê±¼ä 2024-09-23Apache Seata ÊÇÒ»¿î¿ªÔ´µÄÂþÑÜʽÊÂÎñ½â¾ö¼Æ»®£¬£¬ÖÂÁ¦ÓÚÔÚ΢ЧÀͼܹ¹ÏÂÌṩ¸ßÐÔÄܺͼòÆÓÒ×ÓõÄÂþÑÜʽÊÂÎñЧÀÍ¡£¡£
2024Äê9Ô£¬£¬¿Ðý¹ú¼ÊÓÎÏ·¼à¿Øµ½Apache Seata ¹Ù·½Ðû²¼ÁËCVE-2024-22399 Apache Seata Hessian·´ÐòÁл¯Îó²î¡£¡£¸ÃÎó²îCVSS3.1ÏÖÔÚÆÀ·ÖΪ9.8·Ö£¬£¬²¢ÇÒÆä×ÛºÏÆÀ¼¶Îª¡°³¬Î£¡±¡£¡£
¾Ñо¿È·¶¨£¬£¬Apache Seata ÓÃÓÚЧÀͶËÓë¿Í»§¶ËͨѶµÄRPC ÐÒ飨ĬÈ϶˿ÚΪ8091£©ÒÔ¼°×Ô2.0.0 °æ±¾ÆðʵÏÖµÄRaft ÐÒéÐÂÎÅ£¬£¬¾ùÖ§³Ö½ÓÄÉHessian ¾ÙÐÐÊý¾ÝµÄÐòÁл¯Óë·´ÐòÁл¯²Ù×÷¡£¡£ÔÚ2.1.0 ¼°1.8.1 °æ±¾Ö®Ç°£¬£¬SeataÔÚ´¦Öóͷ£RPC ÇëÇóʱ£¬£¬¶ÔRPC ÐÂÎÅÌåÖеÄÐòÁл¯Êý¾ÝУÑé»úÖÆ²»·óÑϿᡣ¡£ÕâÒ»ÇéÐÎÖÂʹ¹¥»÷ÕßÄܹ»½á¹¹°üÀ¨¶ñÒâHessian ÐòÁл¯Êý¾ÝµÄÐÂÎÅÌ壬£¬²¢·¢ËͶñÒâRPC ÇëÇ󣬣¬×îÖÕ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£ÈôÀÖ³ÉʹÓôËÎó²î£¬£¬¹¥»÷ÕßÔòÓпÉÄÜÍêÈ«ÕÆ¿ØÊÜÓ°ÏìµÄϵͳ£¬£¬ÆäÖаüÀ¨»ñÈ¡Ãô¸ÐÊý¾ÝµÄ»á¼ûȨÏÞ¡¢Ö´ÐÐí§ÒâÖ¸Á£¬»òÕßÌᳫ½øÒ»²½µÄÍøÂç¹¥»÷ÐÐΪ¡£¡£ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì½ÓÄÉ·À»¤²½·¥¡£¡£
Îó²î¸´ÏÖ
Ó°Ïì°æ±¾
Apache Seata 2.0.0 °æ±¾
Apache Seata 1.0.0 ÖÁ 1.8.0 °æ±¾
½â¾ö¼Æ»®
Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®
ÏÖÔÚ¹Ù·½ÒÑÓпɸüа汾£¬£¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾:
Apache Seata 2.1.0/1.8.1
¹Ù·½ÏÂÔØµØµã£º
https://github.com/apache/incubator-seata/releases/tag/v2.1.0
¶þ¡¢¿Ðý¹ú¼ÊÓÎÏ·½â¾ö¼Æ»®
1¡¢¿Ðý¹ú¼ÊÓÎÏ·Öն˲úÆ·¼Æ»®
Ìì«‘ÖÕ¶ËÇå¾²Ò»Ì廯£¨EDR£©ÌṩÎó²îµÄרÏîÑéÖ¤¼ì²éÄÜÁ¦¶ÔÎó²îפÁôÖն˾ÙÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬£¬Í¬Ê±Ìṩʵʱ¸æ¾¯Òì³£×Ó¸¸Àú³Ì£¬£¬¼à¿ØÖ÷»úÒì³£ÍâÁ¬¼ì²â»ò·ÀÓùÄÜÁ¦£¬£¬µÖÓùÎó²î¹¥»÷Σº¦¡£¡£
2¡¢¿Ðý¹ú¼ÊÓÎÏ·¼ì²âÀà²úÆ·¼Æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½Ä¿½ñ×îа汾ÊÂÎñ¿â¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦£¬£¬ÊÂÎñ¿âÏÂÔØµØµã£º
https://venustech.download.venuscloud.cn/
3¡¢¿Ðý¹ú¼ÊÓÎϷ©ɨ²úÆ·¼Æ»®
£¨1£©¡°¿Ðý¹ú¼ÊÓÎÏ·Îó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£¡£

£¨2£©¿Ðý¹ú¼ÊÓÎÏ·Îó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£¡£

4¡¢¿Ðý¹ú¼ÊÓÎÏ·×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨£¨ASM£©²úÆ·¼Æ»®
¿Ðý¹ú¼ÊÓÎÏ·×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬£¬¶ÔÈë¿â×ʲúÎó²îApache Seata ·´ÐòÁл¯Îó²î£¨CVE-2024-22399£©¾ÙÐÐÖÎÀí¡£¡£

5¡¢¿Ðý¹ú¼ÊÓÎÏ·Çå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®
Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬¾ÙÐйØÁªÕ½ÂÔÉèÖ㬣¬Á¬ÏµÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬£¬´Ó¶ø·¢Ã÷¡°Apache Seata ·´ÐòÁл¯Îó²î£¨CVE-2024-22399£©¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£¡£
£¨1£© ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Apache Seata ·´ÐòÁл¯Îó²î£¨CVE-2024-22399£©¡±Îó²îɨÃèʹÃü£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú¡£¡£

£¨2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿£¿£¿£¿£¿éÖУ¬£¬Ìí¼Ó¡°L2_Apache Seata ·´ÐòÁл¯Îó²î¡±£¬£¬Í¨¹ý¿Ðý¹ú¼ÊÓÎÏ·¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ¡£¡£

̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_Apache Seata·´ÐòÁл¯Îó²î"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬£¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓᣡ£
£¨3£© Ìí¼Ó¡°L3_Apache Seata·´ÐòÁл¯Îó²î¡±£¬£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_Apache Seata ·´ÐòÁл¯Îó²î¡±£¬£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶȡ£¡£
£¨4£©ATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé
ƾ֤¶ÔCVE-2024-22399Îó²îµÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒս׶Σ¬£¬ÁýÕÖµÄTTP°üÀ¨£º
TA0001³õʼ»á¼û£ºT1190ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò
TA0002Ö´ÐУºT1059ÏÂÁîºÍ¾ç±¾Ú¹ÊÍÆ÷
TA0004ÌáȨ£º T1068ʹÓÃÎó²îÌáÉýȨÏÞ
TA0009Êý¾ÝÍøÂ磺 T1005´ÓÍâµØÏµÍ³ÍøÂçÊý¾Ý
ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦£¬£¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£¡£