Puppet EnterpriseĬÈÏÃÜÂë·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-05

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10694£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.4£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ºÏÓÃÓÚPuppet Enterprise 2019.0.3֮ǰ°æ±¾¡£


·ì϶¸ÅÊö


PuppetÊÇ¿ªÔ´µÄ»ùÓÚRubyµÄϵͳÅäÖÃÖÎÀí¹¤¾ß£¬»ùÓÚC/SµÄ²¿Êð¼Ü¹¹¡£ÊÇÒ»¸öΪʵÏÖÊý¾ÝÖÐÐÄ×Ô¶¯»¯ÖÎÀí¶øÉè¼ÆµÄÅäÖÃÖÎÀíÈí¼þ£¬ËüʹÓÃ¿çÆ½Ì¨Ëµ»°¹æ·¶£¬ÖÎÀíÅäÖÃÎļþ¡¢Óû§¡¢Èí¼þ°ü¡¢ÏµÍ³·þÎñµÈ¡ £¿Í»§¶ËĬÈÏÿ¸ô°ëÓ×ʱ»áºÍ·þÎñÆ÷ͨѶһ´Î£¬È·ÈÏÊÇ·ñÓиüС£µ±È»Ò²Äܹ»ÅäÖÃ×Ô¶¯´¥·¢À´Ç¿Ôì¿Í»§¶Ë¸üС£ÕâÑù¾Í°ÑÈÕ³£µÄϵͳÖÎÀí¹¤×÷´úÂ뻯ÁË£¬´úÂ뻯µÄÒæ´¦ÊÇÄܹ»·ÖÏí£¬±£Áô£¬Ô¤·À³Á¸´ÀͶ¯£¬Ò²Äܹ»¼±¾ç¸´Ô­ÒÔ¼°¼±¾çµÄ´ó¹æÄ£²¿Êð·þÎñÆ÷¡£Puppet EnterpriseÊÇPuppetµÄÆóÒµ°æ¡£


Puppet Enterprise 2019.0.3֮ǰ°æ±¾ÖдæÔÚĬÈÏÃÜÂë·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÈÆ¹ýÏÞ¶È£¬ÌáÉýȨÏÞ¡£


¾Ýͳ¼Æ£¬Öйú¶³öÔÚ¹«ÍøÉϵÄPuppet´ï3000¶à¸ö£¬¾ßÌåÉ¢²¼Çé¿öÈçÏ£º

 

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://puppet.com/security/cve/CVE-2019-10694


²Î¿¼Á´½Ó


https://puppet.com/security/cve/CVE-2019-10694