ZABBIX SQL×¢È멶´À´Ï®£¬¶«É­Æ½Ì¨Ìṩ½â¾ö·½°¸

Ðû²¼Ê±¼ä 2024-05-23

ZabbixÊÇÒ»¸ö»ùÓÚWEB½çÃæµÄÆóÒµ¼¶¿ªÔ´½â¾ö·½°¸£¬ÓÃÓÚÌṩÂþÑÜʽϵͳ¼àÊÓºÍÍøÂç¼àÊÓ¹¦Ð§£¬±£Ö¤·þÎñÆ÷ϵͳµÄÄþ¾²ÔËÓª£¬±ãÓÚϵͳ¹ÜÀíÔ±¿ìËÙ¶¨Î»ºÍ½â¾ö´æÔÚµÄÖÖÖÖÎÊÌâ¡£


ÆäÖ÷ÒªÓÉÁ½¸öÖ÷Òª×é¼þ×é³É£ºZabbix serverºÍ¿ÉÑ¡µÄZabbix agent¡£ÆäÖУ¬Zabbix serverÄܹ»Í¨¹ýSNMP¡¢Zabbix agent¡¢ping¡¢¶Ë¿Ú¼àÊÓµÈÒªÁì¶ÔÔ¶³Ì·þÎñÆ÷ºÍÍøÂç״̬½øÐмàÊÓºÍÊý¾ÝÊÕ¼¯£¬¿ÉÔÚLinux¡¢Solaris¡¢HP-UX¡¢AIX¡¢Free BSD¡¢Open BSD¡¢OS XµÈ¶àÖÖƽ̨ÉÏÔËÐС£


©¶´ÏêÇé


2024Äê5ÔÂ21ÈÕ£¬¶«É­Æ½Ì¨½ð¾¦Äþ¾²Ñо¿ÍŶӼà¿Øµ½Zabbix SQL×¢È멶´£¨CVE-2024-22120£©Ç鱨¡£¸Ã©¶´´æÔÚÓÚaudit.cµÄzbx_auditlog_global_scriptº¯ÊýÖУ¬ÓÉÓÚclientip×Ö¶Îδ¾­ÇåÀí£¬¿ÉÄܵ¼ÖÂSQLʱ¼ääע¹¥»÷¡£¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø鶴´ÓÊý¾Ý¿âÖлñÈ¡Ãô¸ÐÐÅÏ¢£¬²¢¿É½«È¨ÏÞÌáÉýΪ¹ÜÀíÔ±»òÔ¶³ÌÖ´ÐдúÂë¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


©¶´¸´ÏÖ½Øͼ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀûÓùÜÀíÔ±session¼°key½Ó¹Ü¹ÜÀíÔ±ÕË»§


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½øÐÐcookieÌæ»»ºóË¢ÐÂÒ³Ãæ¼´¿É½Ó¹Üzabbix¹ÜÀíÔ±


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó°Ïì°æ±¾


6.0.0 <= Zabbix <= 6.0.27

6.4.0 <= Zabbix <= 6.4.12

7.0.0alpha1 <= Zabbix <= 7.0.0beta1


ÐÞ¸´½¨Òé


1¡¢¹Ù·½ÐÞ¸´·½°¸


¹Ù·½ÒÑÐû²¼Äþ¾²¸üУ¬ZabbixÍŶÓÐû²¼Á˲¹¶¡ÒÔ½â¾ö°æ±¾6.0.28rc1¡¢6.4.13rc1ºÍ7.0.0beta2ÖеÄ©¶´¡£

µØÖ·£ºhttps://www.zabbix.com/download


2¡¢¶«É­Æ½Ì¨·½°¸


ÌìãÙÈëÇÖ¼ì²âÓë¹ÜÀíϵͳ¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¡¢ÌìÇåWebÓ¦ÓÃÄþ¾²Íø¹Ø£¨WAF£©Éý¼¶µ½20240523°æ±¾¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã©¶´Ôì³ÉµÄ¹¥»÷·çÏÕ¡£