¡¾Îó²îͨ¸æ¡¿SplunkÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-20229)
Ðû²¼Ê±¼ä 2025-03-27Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | SplunkÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-20229 | ||
Îó²îÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-27 |
Îó²îÆÀ·Ö | 8.0 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Splunk EnterpriseÊÇÒ»¿îǿʢµÄÊý¾ÝÆÊÎöƽ̨£¬£¬×¨×¢ÓÚ»úеÊý¾ÝµÄÍøÂç¡¢¼à¿ØºÍÆÊÎö£¬£¬ÆÕ±éÓ¦ÓÃÓÚÈÕÖ¾ÖÎÀí¡¢Çå¾²ÐÅÏ¢ÊÂÎñÖÎÀí£¨SIEM£©ºÍITÔËά£¬£¬Äܹ»×ÊÖú×é֯ʵʱ»ñÈ¡²Ù×÷Êý¾Ý¡¢¼ì²âÒì³£¡¢ÆÊÎöÇ÷ÊÆ£¬£¬²¢Ìṩ¿ÉÊÓ»¯±¨±íºÍ¾¯±¨¹¦Ð§¡£¡£Splunk Cloud PlatformÊÇSplunkµÄÔÆ°æ±¾£¬£¬ÌṩÓëEnterpriseÏàͬµÄÊý¾ÝÆÊÎö¹¦Ð§£¬£¬µ«ÒÔSaaSÐÎʽÔËÐУ¬£¬Óû§ÎÞÐè×ÔÐÐÖÎÀí»ù´¡ÉèÊ©¡£¡£ËüÊÊÓÃÓÚÐèÒª¸ß¶È¿ÉÀ©Õ¹ÐÔºÍÎÞаÐÔµÄÆóÒµ£¬£¬Ö§³Ö¿çƽ̨¡¢¿çÇéÐεÄÊý¾ÝÆÊÎöºÍÖÎÀí£¬£¬×ÊÖú×éÖ¯¸ßЧ´¦Öóͷ£´óÊý¾Ý£¬£¬²¢ÊµÏÖÉîÈëµÄÖÇÄܶ´²ì¡£¡£
2025Äê3ÔÂ27ÈÕ£¬£¬¿Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½SplunkÐû²¼µÄÇ徲ͨ¸æ£¬£¬Í¨¸æÖ¸³öSplunk EnterpriseºÍSplunk Cloud Platform±£´æÒ»¸ö¸ßΣÎó²î¡£¡£ÔÚÌØ¶¨°æ±¾ÖУ¬£¬µÍȨÏÞÓû§£¨Î´³ÖÓÐ"admin"»ò"power"½ÇÉ«£©ÓÉÓÚȱ·¦ÐëÒªµÄÊÚȨ¼ì²é£¬£¬¿ÉÄÜͨ¹ý½«ÎļþÉÏ´«ÖÁ¡°$SPLUNK_HOME/var/run/splunk/apptemp¡±Ä¿Â¼£¬£¬´Ó¶øÖ´ÐÐÔ¶³Ì´úÂ루RCE£©¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì¸üС£¡£
ÏÂÔØÁ´½Ó£ºhttps://www.splunk.com/en_us/download.html/
3.2 ÔÝʱ²½·¥
3.3 ͨÓý¨Òé
3.4 ²Î¿¼Á´½Ó
https://advisory.splunk.com/advisories/SVD-2025-0301