ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208) À´Ï®£¬£¬OG¶«·½ÌüÌṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2025-03-31

Vite ÊÇÒ»¿îÏÖ´ú»¯µÄǰ¶Ë¿ª·¢¹¹½¨¹¤¾ß£¬£¬ËüÌṩÁ˼±¾çµÄ¿ª·¢·þÎñÆ÷ºÍ¸ßЧµÄ¹¹½¨ÄÜÁ¦£¬£¬¿í·ºÀûÓÃÓÚ Vue.js ÏîÖ÷ÕÅ¿ª·¢¹ý³ÌÖС£


2025Äê3Ô£¬£¬OG¶«·½Ìü¼à¿Øµ½ViteËÁÒâÎļþ¶ÁÈ¡·ì϶µý±¨(CVE-2025-30208)£¬£¬¸Ã·ì϶ԴÓÚ Vite ¿ª·¢·þÎñÆ÷ÔÚ´¦ÖÃÌØ¶¨ URL ÒªÇóʱ£¬£¬Ã»ÓжÔÒªÇóµÄõè¾¶½øÐÐÑϸñµÄ°²È«²é³­ºÍÏÞ¶È£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Èƹý±£»£»¤»úÖÆ£¬£¬·¸·¨½Ó¼ûÏîÄ¿¸ùĿ¼ÍâµÄÃô¸ÐÎļþ¡£


±í1.png


·ì϶¸´ÏÖ½ØÍ¼

 

ͼ1.png


Ó°Ïì°æ±¾


6.2.0 <= Vite <= 6.2.2

6.1.0 <= Vite <= 6.1.1

6.0.0 <= Vite <= 6.0.11

5.0.0 <= Vite <= 5.4.14

Vite <= 4.5.9


ÐÞ¸´½¨Òé


Ò»¡¢¹Ù·½ÐÞ¸´¹æ»®£º£º


ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾½øÐзÀ»¤£¬£¬ÏÂÔØÁ´½Ó£º£ºhttps://github.com/vitejs/vite/releases


¶þ¡¢OG¶«·½Ìü¹æ»®£º£º


1¡¢OG¶«·½Ìü¼ì²âÀà²úÆ·¹æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEB°²È«ÀûÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬£¬Éý¼¶µ½×îа汾¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ¡£


ÊÂÎñ¿âÏÂÔØµØÖ·£º£ºhttps://venustech.download.venuscloud.cn/


2¡¢OG¶«·½Ìü©ɨ²úÆ·¹æ»®


£¨1£©¡°OG¶«·½Ìü·ì϶ɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè

 

ͼ2.png


£¨2£©OG¶«·½Ìü·ì϶ɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè


ͼ3.png

 

3¡¢OG¶«·½ÌüÖն˲úÆ·¹æ»®


Ìì«‘Öն˰²È«Ò»Ì廯£¨EDR£©Ìṩ·ì϶µÄרÏîÑéÖ¤²é³­ÄÜÁ¦¿É¶Ô·ì϶פÁôÖն˽øÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬£¬Æ¥Åä·ì϶×ʲú£¬£¬Ô¤·À·ì϶¹¥»÷·çÏÕ¡£

 

ͼ4.png


4¡¢OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®


OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬£¬¶ÔÈë¿â×ʲúViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)½øÐÐÖÎÀí¡£


ͼ5.png


5¡¢OG¶«·½Ìü°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®


Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬½øÐйØÁªÕ½ÊõÅäÖ㬣¬½áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬£¬´Ó¶ø·¢ÏÖ¡°ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£


1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±·ì϶ɨÃ蹤×÷£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄÖØÒª×ʲú£»£»

 

ͼ6.png


2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿£¿£¿éÖУ¬£¬Ôö³¤¡°L2_ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±£¬£¬Í¨¹ýOG¶«·½Ìü¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ£º£º


ͼ7.png

 

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬£¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓ㻣»


3£©Ôö³¤¡°L3_ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±£¬£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÈÓÚ»òÔ̺¬¡°L2_ViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)¡±£¬£¬¹¥»÷Á˾ֵÈÓÚ»òÊôÓÚ¡°¹¥»÷³É¹¦¡±£¬£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶÈ¡£


ͼ8.png

 

4£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé


ƾ¾Ý¶ÔViteËÁÒâÎļþ¶ÁÈ¡·ì϶ (CVE-2025-30208)µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬£¬¸²¸ÇµÄTTPÔ̺¬£º£º


TA0001-³õʼ½Ó¼û£º£ºT1190-ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½

TA0010-Êý¾Ýй¶£º£ºT1041-ͨ¹ýC2ͨµÀÇÔÈ¡

±í2.jpg

ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬½øÐÐ×Ô¶¯»¯´ëÖá£