¡¾Îó²îͨ¸æ¡¿Kubernetes ingress-nginx¿ØÖÆÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î(CVE-2025-1974)
Ðû²¼Ê±¼ä 2025-03-28Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Kubernetes ingress-nginx¿ØÖÆÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-1974 | ||
Îó²îÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-28 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
ingress-nginx¿ØÖÆÆ÷ÊÇKubernetesÖеÄÒ»¸öÒªº¦×é¼þ£¬£¬£¬£¬£¬ÓÃÓÚÖÎÀí¼¯ÈºÄÚ²¿ºÍÍⲿÁ÷Á¿µÄ»á¼û¿ØÖÆ¡£¡£¡£¡£¡£Ëüͨ¹ý½ç˵Ingress×ÊÔ´À´ÉèÖÃHTTPºÍHTTPS·ÓÉ£¬£¬£¬£¬£¬ÊµÏÖ¸ºÔØÆ½ºâ¡¢SSLÖÕÖ¹¡¢·´ÏòÊðÀíµÈ¹¦Ð§¡£¡£¡£¡£¡£¸Ã¿ØÖÆÆ÷»ùÓÚNGINX£¬£¬£¬£¬£¬Ö§³ÖÎÞаµÄÁ÷Á¿ÖÎÀíÕ½ÂԺ͸߿ÉÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£
2025Äê3ÔÂ28ÈÕ£¬£¬£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½KubernetesÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬Ö¸³öÔÚKubernetesÖз¢Ã÷ÁËÒ»¸öÑÏÖØµÄÇå¾²Îó²î£¬£¬£¬£¬£¬¸ÃÎó²îÓ°Ïìingress-nginx¿ØÖÆÆ÷¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½öÐè»á¼ûPodÍøÂ磬£¬£¬£¬£¬±ã¿ÉÔÚingress-nginx¿ØÖÆÆ÷ÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬½ø¶øÐ¹Â¶¿ØÖÆÆ÷¿É»á¼ûµÄSecrets¡£¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏ£¬£¬£¬£¬£¬ingress-nginx¿ØÖÆÓþßÓлá¼ûÕû¸ö¼¯ÈºËùÓÐSecretsµÄȨÏÞ¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬Îó²îÆ·¼¶ÑÏÖØ¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
ingress-nginx < v1.11.0
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/kubernetes/ingress-nginx/releases/