¡¾Îó²îͨ¸æ¡¿Kubernetes ingress-nginx¿ØÖÆÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î(CVE-2025-1974)
Ðû²¼Ê±¼ä 2025-03-28Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Kubernetes ingress-nginx¿ØÖÆÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-1974 | ||
Îó²îÀàÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-28 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
ingress-nginx¿ØÖÆÆ÷ÊÇKubernetesÖеÄÒ»¸öÒªº¦×é¼þ£¬ÓÃÓÚÖÎÀí¼¯ÈºÄÚ²¿ºÍÍⲿÁ÷Á¿µÄ»á¼û¿ØÖÆ¡£Ëüͨ¹ý½ç˵Ingress×ÊÔ´À´ÉèÖÃHTTPºÍHTTPS·ÓÉ£¬ÊµÏÖ¸ºÔØÆ½ºâ¡¢SSLÖÕÖ¹¡¢·´ÏòÊðÀíµÈ¹¦Ð§¡£¸Ã¿ØÖÆÆ÷»ùÓÚNGINX£¬Ö§³ÖÎÞаµÄÁ÷Á¿ÖÎÀíÕ½ÂԺ͸߿ÉÀ©Õ¹ÐÔ¡£
2025Äê3ÔÂ28ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½KubernetesÐû²¼µÄÇ徲ͨ¸æ£¬Ö¸³öÔÚKubernetesÖз¢Ã÷ÁËÒ»¸öÑÏÖØµÄÇå¾²Îó²î£¬¸ÃÎó²îÓ°Ïìingress-nginx¿ØÖÆÆ÷¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½öÐè»á¼ûPodÍøÂ磬±ã¿ÉÔÚingress-nginx¿ØÖÆÆ÷ÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬½ø¶øÐ¹Â¶¿ØÖÆÆ÷¿É»á¼ûµÄSecrets¡£Ä¬ÈÏÇéÐÎÏ£¬ingress-nginx¿ØÖÆÓþßÓлá¼ûÕû¸ö¼¯ÈºËùÓÐSecretsµÄȨÏÞ¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8·Ö£¬Îó²îÆ·¼¶ÑÏÖØ¡£
¶þ¡¢Ó°Ïì¹æÄ£
ingress-nginx < v1.11.0
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/kubernetes/ingress-nginx/releases/


¾©¹«Íø°²±¸11010802024551ºÅ