¡¾Îó²îͨ¸æ¡¿Apache Kafka Connect LDAPÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-27818)
Ðû²¼Ê±¼ä 2025-06-10Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Apache Kafka Connect LDAPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-27818 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-06-10 |
Îó²îÆÀ·Ö | ÔÝÎÞ | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache KafkaÊÇÒ»¸ö¿ªÔ´µÄÂþÑÜʽÁ÷´¦Öóͷ£Æ½Ì¨£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚ¸ßÍÌÍ¡¢¿ÉÀ©Õ¹µÄÐÂÎÅÐû²¼Óë¶©ÔÄ¡£¡£¡£¡£¡£¡£ËüÖ§³ÖʵʱÊý¾Ý´«Ê䣬£¬£¬£¬£¬¿ÉÆÕ±éÓ¦ÓÃÓÚÈÕÖ¾ÍøÂç¡¢ÊÂÎñ¼à¿Ø¡¢Á÷ʽÅÌËãµÈ³¡¾°¡£¡£¡£¡£¡£¡£Kafka ͨ¹ýProducer¡¢BrokerºÍConsumer¹¹½¨ÐÂÎŹܵÀ£¬£¬£¬£¬£¬¾ß±¸³¤ÆÚ»¯¡¢¸ß¿ÉÓúÍÈÝ´íÄÜÁ¦£¬£¬£¬£¬£¬ÆÕ±éÓÃÓÚ´óÊý¾ÝºÍ΢ЧÀͼܹ¹ÖС£¡£¡£¡£¡£¡£
2025Äê6ÔÂ10ÈÕ£¬£¬£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½ApacheÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬Åû¶Apache Kafka±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¨CVE-2025-27818£©¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýKafka ConnectÉèÖÃÖеÄsasl.jaas.config²ÎÊý£¬£¬£¬£¬£¬½«Kafka¿Í»§¶ËÖ¸Ïò¶ñÒâLDAPЧÀÍÆ÷£¬£¬£¬£¬£¬ÓÕµ¼Ð§ÀÍÆ÷·´ÐòÁл¯²»¿ÉÐÅÊý¾Ý£¬£¬£¬£¬£¬´Ó¶øÊµÏÖí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìʹÓÃSASL JAASÉèÖõÄKafka Connect¼¯Èº£¬£¬£¬£¬£¬ÌØÊâÊÇÔÚδ¶ÔµÇ¼ģ¿£¿£¿£¿£¿é¾ÙÐÐÏÞÖÆÉèÖõÄÇéÐÎÖС£¡£¡£¡£¡£¡£×ÔKafka 3.9.1/4.0.0Æð£¬£¬£¬£¬£¬¹Ù·½ÒÑĬÈϽûÓÃÏà¹Ø¸ßΣº¦µÇ¼ģ¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬²¢ÌṩϵͳÊôÐÔÓÃÓÚϸ»¯¿ØÖÆ¡£¡£¡£¡£¡£¡£½¨ÒéÓû§ÊµÊ±Éý¼¶ÊÜÓ°Ïì°æ±¾£¬£¬£¬£¬£¬Ç¿»¯ÉèÖÃÉ󼯣¬£¬£¬£¬£¬½µµÍΣº¦¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://kafka.apache.org/downloads/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£