Apache Seata·´ÐòÁл¯·ì϶À´Ï®£¬£¬£¬OG¶«·½ÌüÌṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2024-09-23Apache Seata ÊÇÒ»¿î¿ªÔ´µÄÉ¢²¼Ê½ÊÂÎñ½â¾ö¹æ»®£¬£¬£¬ÖÂÁ¦ÓÚÔÚ΢·þÎñ¼Ü¹¹ÏÂÌṩ¸ß»úÄܺ͵¥Ò»Ò×ÓõÄÉ¢²¼Ê½ÊÂÎñ·þÎñ¡£¡£¡£
2024Äê9Ô£¬£¬£¬OG¶«·½Ìü¼à¿Øµ½Apache Seata ¹Ù·½°ä²¼ÁËCVE-2024-22399 Apache Seata Hessian·´ÐòÁл¯·ì϶¡£¡£¡£¸Ã·ì϶CVSS3.1ĿǰÆÀ·ÖΪ9.8·Ö£¬£¬£¬²¢ÇÒÆä×ÛºÏÆÀ¼¶Îª¡°³¬Î£¡±¡£¡£¡£
¾×êÑÐÈ·¶¨£¬£¬£¬Apache Seata ÓÃÓÚ·þÎñ¶ËÓë¿Í»§¶ËͨѶµÄRPC ºÍ̸£¨Ä¬È϶˿ÚΪ8091£©ÒÔ¼°×Ô2.0.0 °æ±¾ÆðʵÏÖµÄRaft ºÍ̸ÐÂÎÅ£¬£¬£¬¾ùÖ§³ÖѡȡHessian ½øÐÐÊý¾ÝµÄÐòÁл¯Óë·´ÐòÁл¯²Ù×÷¡£¡£¡£ÔÚ2.1.0 ¼°1.8.1 °æ±¾Ö®Ç°£¬£¬£¬SeataÔÚ´¦ÖÃRPC ÒªÇóʱ£¬£¬£¬¶ÔRPC ÐÂÎÅÌåÖеÄÐòÁл¯Êý¾ÝУÑé»úÖÆ²»¹»Ñϸñ¡£¡£¡£ÕâÒ»Çé¿öÒÔÖÁ¹¥»÷Õß¿ÉÄÜ»ú¹ØÔ̺¬¶ñÒâHessian ÐòÁл¯Êý¾ÝµÄÐÂÎÅÌ壬£¬£¬²¢·¢ËͶñÒâRPC ÒªÇ󣬣¬£¬×îÖÕ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£Èô³É¹¦ÀûÓô˷ì϶£¬£¬£¬¹¥»÷ÕßÔòÓпÉÄÜÆëÈ«ÕÆ¿ØÊÜÓ°ÏìµÄϵͳ£¬£¬£¬ÆäÖÐÔ̺¬»ñÈ¡Ãô¸ÐÊý¾ÝµÄ½Ó¼ûȨÏÞ¡¢Ö´ÐÐËÁÒâÖ¸Á£¬£¬»òÕßÌáÒé½øÒ»²½µÄÍøÂç¹¥»÷ÐÐΪ¡£¡£¡£ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì²ÉÈ¡·À»¤´ëÊ©¡£¡£¡£

·ì϶¸´ÏÖ

Ó°Ïì°æ±¾
Apache Seata 2.0.0 °æ±¾
Apache Seata 1.0.0 ÖÁ 1.8.0 °æ±¾
½â¾ö¹æ»®
Ò»¡¢¹Ù·½ÐÞ¸´¹æ»®
Ŀǰ¹Ù·½ÒÑÓпɸüа汾£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾:
Apache Seata 2.1.0/1.8.1
¹Ù·½ÏÂÔØµØÖ·£º£º£º
https://github.com/apache/incubator-seata/releases/tag/v2.1.0
¶þ¡¢OG¶«·½Ìü½â¾ö¹æ»®
1¡¢OG¶«·½ÌüÖն˲úÆ·¹æ»®
Ìì«‘Öն˰²È«Ò»Ì廯£¨EDR£©Ìṩ·ì϶µÄרÏîÑéÖ¤²é³ÄÜÁ¦¶Ô·ì϶פÁôÖն˽øÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬£¬£¬Í¬Ê±Ìṩʵʱ¸æ¾¯Òì³£×Ó¸¸¹ý³Ì£¬£¬£¬¼à¿ØÖ÷»úÒì³£ÍâÁ¬¼ì²â»ò·ÀÓùÄÜÁ¦£¬£¬£¬Õмܷì϶¹¥»÷·çÏÕ¡£¡£¡£

2¡¢OG¶«·½Ìü¼ì²âÀà²úÆ·¹æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½µ±Ç°×îа汾ÊÂÎñ¿â¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ£¬£¬£¬ÊÂÎñ¿âÏÂÔØµØÖ·£º£º£º
https://venustech.download.venuscloud.cn/
3¡¢OG¶«·½Ìü©ɨ²úÆ·¹æ»®
£¨1£©¡°OG¶«·½Ìü·ì϶ɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè¡£¡£¡£

£¨2£©OG¶«·½Ìü·ì϶ɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè¡£¡£¡£

4¡¢OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨£¨ASM£©²úÆ·¹æ»®
OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬£¬£¬¶ÔÈë¿â×ʲú·ì϶Apache Seata ·´ÐòÁл¯·ì϶£¨CVE-2024-22399£©½øÐÐÖÎÀí¡£¡£¡£

5¡¢OG¶«·½Ìü°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®
Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬£¬½øÐйØÁªÕ½ÊõÅäÖ㬣¬£¬½áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬£¬£¬´Ó¶ø·¢ÏÖ¡°Apache Seata ·´ÐòÁл¯·ì϶£¨CVE-2024-22399£©¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£¡£¡£
£¨1£© ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬£¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°Apache Seata ·´ÐòÁл¯·ì϶£¨CVE-2024-22399£©¡±·ì϶ɨÃ蹤×÷£¬£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄÖØÒª×ʲú¡£¡£¡£

£¨2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿£¿£¿éÖУ¬£¬£¬Ôö³¤¡°L2_Apache Seata ·´ÐòÁл¯·ì϶¡±£¬£¬£¬Í¨¹ýOG¶«·½Ìü¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬£¬£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ¡£¡£¡£

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_Apache Seata·´ÐòÁл¯·ì϶"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬£¬£¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓᣡ£¡£
£¨3£© Ôö³¤¡°L3_Apache Seata·´ÐòÁл¯·ì϶¡±£¬£¬£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÈÓÚ»òÔ̺¬¡°L2_Apache Seata ·´ÐòÁл¯·ì϶¡±£¬£¬£¬¹¥»÷Á˾ֵÈÓÚ¡°¹¥»÷³É¹¦¡±£¬£¬£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬£¬£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶȡ£¡£¡£

£¨4£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé
ƾ¾Ý¶ÔCVE-2024-22399·ì϶µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬£¬£¬¸²¸ÇµÄTTPÔ̺¬£º£º£º
TA0001³õʼ½Ó¼û£º£º£ºT1190ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½
TA0002Ö´ÐУº£º£ºT1059ºÅÁîºÍ¾ç±¾Ú¹ÊÍÆ÷
TA0004ÌáȨ£º£º£º T1068ÀûÓ÷ì϶ÌáÉýȨÏÞ
TA0009Êý¾ÝÍøÂ磺£º£º T1005´Ó±¾µØÏµÍ³ÍøÂçÊý¾Ý

ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬£¬£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬£¬½øÐÐ×Ô¶¯»¯´ëÖᣡ£¡£


¾©¹«Íø°²±¸11010802024551ºÅ