Apache Seata·´ÐòÁл¯Â©¶´À´Ï®£¬¶«É­Æ½Ì¨Ìṩ½â¾ö·½°¸

Ðû²¼Ê±¼ä 2024-09-23

Apache Seata ÊÇÒ»¿î¿ªÔ´µÄÂþÑÜʽÊÂÎñ½â¾ö·½°¸£¬ÖÂÁ¦ÓÚÔÚ΢·þÎñ¼Ü¹¹ÏÂÌṩ¸ßÐÔÄܺͼòµ¥Ò×ÓõÄÂþÑÜʽÊÂÎñ·þÎñ¡£


2024Äê9Ô£¬¶«É­Æ½Ì¨¼à¿Øµ½Apache Seata ¹Ù·½Ðû²¼ÁËCVE-2024-22399 Apache Seata Hessian·´ÐòÁл¯Â©¶´¡£¸Ã©¶´CVSS3.1Ä¿Ç°ÆÀ·ÖΪ9.8·Ö£¬¶øÇÒÆä×ÛºÏÆÀ¼¶Îª¡°³¬Î£¡±¡£


¾­Ñо¿È·¶¨£¬Apache Seata ÓÃÓÚ·þÎñ¶ËÓë¿Í»§¶ËͨÐŵÄRPC ЭÒ飨ĬÈ϶˿ÚΪ8091£©ÒÔ¼°×Ô2.0.0 °æ±¾ÆðʵÏÖµÄRaft ЭÒéÏûÏ¢£¬¾ùÖ§³Ö½ÓÄÉHessian ½øÐÐÊý¾ÝµÄÐòÁл¯Óë·´ÐòÁл¯²Ù×÷¡£ÔÚ2.1.0 ¼°1.8.1 °æ±¾Ö®Ç°£¬SeataÔÚ´¦ÖÃRPC ÇëÇóʱ£¬¶ÔRPC ÏûÏ¢ÌåÖеÄÐòÁл¯Êý¾ÝУÑé»úÖƲ»¹»Ñϸñ¡£ÕâÒ»Çé¿öÖÂʹ¹¥»÷ÕßÄܹ»½á¹¹°üÂÞ¶ñÒâHessian ÐòÁл¯Êý¾ÝµÄÏûÏ¢Ì壬²¢·¢ËͶñÒâRPC ÇëÇó£¬×îÖÕ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÈôÀÖ³ÉÀûÓôË©¶´£¬¹¥»÷ÕßÔòÓпÉÄÜÍêÈ«ÕÆ¿ØÊÜÓ°ÏìµÄϵͳ£¬ÆäÖаüÂÞ»ñÈ¡Ãô¸ÐÊý¾ÝµÄ·ÃÎÊȨÏÞ¡¢Ö´ÐÐÈÎÒâÖ¸Á»òÕßÌᳫ½øÒ»²½µÄÍøÂç¹¥»÷ÐÐΪ¡£ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì½ÓÄÉ·À»¤´ëÊ©¡£


ͼƬ1.png


©¶´¸´ÏÖ


ͼƬ2.jpg


Ó°Ïì°æ±¾


Apache Seata 2.0.0 °æ±¾

Apache Seata 1.0.0 ÖÁ 1.8.0 °æ±¾


½â¾ö·½°¸


Ò»¡¢¹Ù·½ÐÞ¸´·½°¸


Ä¿Ç°¹Ù·½ÒÑÓпɸüа汾£¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾:

Apache Seata 2.1.0/1.8.1

¹Ù·½ÏÂÔصØÖ·£º

https://github.com/apache/incubator-seata/releases/tag/v2.1.0


¶þ¡¢¶«É­Æ½Ì¨½â¾ö·½°¸


1¡¢¶«É­Æ½Ì¨Öն˲úÎï·½°¸


Ìì«‘ÖÕ¶ËÄþ¾²Ò»Ì廯£¨EDR£©Ìṩ©¶´µÄרÏîÑéÖ¤¼ì²éÄÜÁ¦¶Ô©¶´×¤ÁôÖն˽øÐÐÈ«Íøͬ²½ÑéÖ¤£¬Í¬Ê±Ìṩʵʱ¸æ¾¯Òì³£×Ó¸¸½ø³Ì£¬¼à¿ØÖ÷»úÒì³£ÍâÁ¬¼ì²â»ò·ÀÓùÄÜÁ¦£¬µÖÓù©¶´¹¥»÷·çÏÕ¡£


ͼƬ3.jpg


2¡¢¶«É­Æ½Ì¨¼ì²âÀà²úÎï·½°¸


ÌìãÙÈëÇÖ¼ì²âÓë¹ÜÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½µ±Ç°×îа汾ʼþ¿â¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã©¶´Ôì³ÉµÄ¹¥»÷·çÏÕ£¬Ê¼þ¿âÏÂÔصØÖ·£º

https://venustech.download.venuscloud.cn/


3¡¢¶«É­Æ½Ì¨Â©É¨²úÎï·½°¸


£¨1£©¡°¶«É­Æ½Ì¨Â©¶´É¨ÃèϵͳV6.0¡±²úÎïÒÑÖ§³Ö¶Ô¸Ã©¶´½øÐÐɨÃè¡£


ͼƬ4.png


£¨2£©¶«É­Æ½Ì¨Â©¶´É¨Ãèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸Ã©¶´½øÐÐɨÃè¡£


ͼƬ5.png


4¡¢¶«É­Æ½Ì¨×ʲúÓë´àÈõÐÔ¹ÜÀíƽ̨£¨ASM£©²úÎï·½°¸


¶«É­Æ½Ì¨×ʲúÓë´àÈõÐÔ¹ÜÀíƽ̨ʵʱÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬¶ÔÈë¿â×ʲú©¶´Apache Seata ·´ÐòÁл¯Â©¶´£¨CVE-2024-22399£©½øÐйÜÀí¡£


ͼƬ6.png


5¡¢¶«É­Æ½Ì¨Äþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨²úÎï·½°¸


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨£¬½øÐйØÁª¼ÆıÅäÖ㬽áºÏʵ¼Ê»·¾³ÖÐϵͳÈÕÖ¾ºÍÄþ¾²É豸µÄ¸æ¾¯ÐÅÏ¢½øÐÐÁ¬Ðø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°Apache Seata ·´ÐòÁл¯Â©¶´£¨CVE-2024-22399£©¡±µÄ©¶´ÀûÓù¥»÷ÐÐΪ¡£


£¨1£© ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ý´àÈõÐÔ·¢ÏÖ¹¦Ð§Õë¶Ô¡°Apache Seata ·´ÐòÁл¯Â©¶´£¨CVE-2024-22399£©¡±Â©¶´É¨ÃèÈÎÎñ£¬ÅŲé¹ÜÀíÍøÂçÖÐÊÜ´Ë©¶´Ó°ÏìµÄÖØÒª×ʲú¡£


ͼƬ7.png


£¨2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬Ìí¼Ó¡°L2_Apache Seata ·´ÐòÁл¯Â©¶´¡±£¬Í¨¹ý¶«É­Æ½Ì¨¼ì²âÉ豸¡¢Ä¿±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ¡£


ͼƬ8.png


ͨ¹ý·ÖÎö¹æÔò×Ô¶¯½«"L2_Apache Seata·´ÐòÁл¯Â©¶´"©¶´ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ìí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ß·çÏÕÁ¬½Ó¡±ÖУ¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓá£


£¨3£© Ìí¼Ó¡°L3_Apache Seata·´ÐòÁл¯Â©¶´¡±£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÂÞ¡°L2_Apache Seata ·´ÐòÁл¯Â©¶´¡±£¬¹¥»÷½á¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬Ä¿µÄµØÖ·ÒýÓÃ×ʲú©¶´»òÔ´µØÖ·Æ¥ÅäÍþвÇ鱨£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£


ͼƬ9.png


£¨4£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´¦Öý¨Òé


ƾ¾Ý¶ÔCVE-2024-22399©¶´µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬ÁýÕÖµÄTTP°üÂÞ£º


TA0001³õʼ·ÃÎÊ£ºT1190ÀûÓÃÃæÏò¹«ÖÚµÄÓ¦Ó÷¨Ê½

TA0002Ö´ÐУºT1059ÃüÁîºÍ½Å±¾½âÊÍÆ÷

TA0004ÌáȨ£º T1068ÀûÓ鶴ÌáÉýȨÏÞ

TA0009Êý¾ÝÊÕ¼¯£º T1005´Óµ±µØϵͳÊÕ¼¯Êý¾Ý


ͼƬ10.png


ͨ¹ýÌ©ºÏÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦ÖÃÄÜÁ¦£¬Õë¶Ô¸Ã©¶´ÀûÓõĸ澯ʼþ±àÅž籾£¬½øÐÐ×Ô¶¯»¯´¦Öá£