Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Kibana ÔÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2025-25015 |
Îó²îÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-07 |
Îó²îÆÀ·Ö | 9.9 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
KibanaÊÇElastic Stack£¨ELK£©µÄ¿ÉÊÓ»¯ºÍÆÊÎö¹¤¾ß£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÈÕÖ¾ºÍÖ¸±êÊý¾ÝµÄչʾ¡£¡£¡£¡£¡£ËüÖ§³ÖÊý¾Ý̽Ë÷¡¢ÒDZí°å½¨Éè¡¢»úеѧϰÆÊÎö¡¢¾¯±¨ÖÎÀíµÈ¹¦Ð§£¬£¬£¬£¬£¬£¬³£ÓëElasticsearch´îÅäʹÓ㬣¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÈÕÖ¾ÆÊÎö¡¢Çå¾²¼à¿ØºÍÓªÒµÊý¾Ý¿ÉÊÓ»¯¡£¡£¡£¡£¡£
2025Äê3ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·VSRC¼à²âµ½elasticÐû²¼ÁËCVE-2025-25015Ïà¹ØÇ徲ͨ¸æ¡£¡£¡£¡£¡£Í¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬Kibana±£´æÔÐÍÎÛȾ£¨Prototype Pollution£©Îó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÖÆÎļþºÍ·¢ËÍÈ«ÐĽṹµÄHTTPÇëÇ󣬣¬£¬£¬£¬£¬ÊµÏÖí§Òâ´úÂëÖ´ÐУ¨Arbitrary Code Execution£©¡£¡£¡£¡£¡£ÔÚKibana°æ±¾¡Ý8.15.0ÇÒ<8.17.1ÖУ¬£¬£¬£¬£¬£¬¸ÃÎó²î¿É±»Viewer½ÇÉ«µÄÓû§Ê¹Óᣡ£¡£¡£¡£ÔÚKibana 8.17.1ºÍ8.17.2°æ±¾ÖУ¬£¬£¬£¬£¬£¬Îó²îʹÓùæÄ£Êܵ½ÏÞÖÆ£¬£¬£¬£¬£¬£¬½ö¾ß±¸ÒÔÏÂËùÓÐȨÏÞµÄÓû§¿É´¥·¢¸ÃÎó²î£ºfleet-all¡¢integrations-all¡¢actions:execute-advanced-connectors¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
8.15.0 ¡Ü Kibana < 8.17.3
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
elastic¹Ù·½ÒÑÔÚÈçϰ汾ÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£¡£½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶£¬£¬£¬£¬£¬£¬ÒÔ½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://www.elastic.co/cn/downloads/kibana/
3.2 ÔÝʱ²½·¥
ÎÞ·¨Éý¼¶µÄÓû§¿ÉÔÚKibanaÉèÖÃÎļþÖÐÌí¼ÓÒÔÏÂÉèÖÃÒÔ»º½âΣº¦xpack.integration_assistant.enabled: false¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441https://nvd.nist.gov/vuln/detail/CVE-2025-25015