Harbor¶à¸öÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-12-04Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-19029£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19026£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19025£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-3990£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19023£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-16919£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-16097£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Harbor 1.7.*
Harbor 1.8.*<1.8.6
Harbor 1.9.*<1.9.3
Îó²î¸ÅÊö
HarborÊÇÒ»¸öÓÃÓÚ´æ´¢ºÍ·Ö·¢Docker¾µÏñµÄÆóÒµ¼¶RegistryЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Í¨¹ýÌí¼ÓһЩÆóÒµ±ØÐèµÄ¹¦Ð§ÌØÕ÷£¬£¬£¬£¬£¬£¬ÀýÈçÇå¾²¡¢±êʶºÍÖÎÀíµÈ£¬£¬£¬£¬£¬£¬À©Õ¹ÁË¿ªÔ´Docker Distribution¡£¡£¡£¡£¡£×÷Ϊһ¸öÆóÒµ¼¶Ë½ÓÐRegistryЧÀÍÆ÷£¬£¬£¬£¬£¬£¬HarborÌṩÁ˸üºÃµÄÐÔÄܺÍÇå¾²¡£¡£¡£¡£¡£ÌáÉýÓû§Ê¹ÓÃRegistry¹¹½¨ºÍÔËÐÐÇéÐδ«Êä¾µÏñµÄЧÂÊ¡£¡£¡£¡£¡£HarborÖ§³Ö×°ÖÃÔÚ¶à¸öRegistry½ÚµãµÄ¾µÏñ×ÊÔ´¸´ÖÆ£¬£¬£¬£¬£¬£¬¾µÏñËùÓÐÉúÑÄÔÚ˽ÓÐRegistryÖУ¬£¬£¬£¬£¬£¬È·±£Êý¾ÝºÍ֪ʶ²úȨÔÚ¹«Ë¾ÄÚ²¿ÍøÂçÖйܿء£¡£¡£¡£¡£ÁíÍ⣬£¬£¬£¬£¬£¬HarborÒ²ÌṩÁ˸߼¶µÄÇå¾²ÌØÕ÷£¬£¬£¬£¬£¬£¬ÖîÈçÓû§ÖÎÀí£¬£¬£¬£¬£¬£¬»á¼û¿ØÖƺͻÉó¼ÆµÈ¡£¡£¡£¡£¡£
ƾ֤Harbor¹Ù·½Ç徲ͨ¸æ, Harbor±£´æÒÔÏÂÇå¾²ÎÊÌ⣺
CVE-2019-19026¡¢CVE-2019-19029Îó²î£ºHarbor±£´æSQLÅÌÎÊÓï¾ä¹ýÂ˲»Ñϵ¼ÖÂSQL×¢È룻£»£»£»£»£»
CVE-2019-19023Îó²î£ºHarborÔÚŲÓÃAPIʱδ¶ÔAPIÇëÇó¾ÙÐÐÑÏ¿áÏÞÖÆ£¬£¬£¬£¬£¬£¬±£´æÍ¨Ë×Óû§¿ÉÒÔͨ¹ýŲÓÃAPIÐÞ¸ÄÌØ¶¨Óû§µÄµç×ÓÓʼþµØµã£¬£¬£¬£¬£¬£¬´Ó¶ø»ñµÃÖÎÀíÔ±ÕÊ»§È¨ÏÞ£¬£¬£¬£¬£¬£¬±ã¿ÉÖØÖøõç×ÓÓʼþµØµãµÄÃÜÂë²¢»ñµÃ¶Ô¸ÃÕÊ»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£
CVE-2019-3990Îó²î£ºHarborÔÚʹÓÃapi/users/searchʱδ¾ÙÐкÏÀíÉí·ÝУÑ飬£¬£¬£¬£¬£¬±£´æÈƹýÖÎÀíÔ±ÏÞÖÆ¾ÙÐÐÓû§Ãûö¾Ù¡£¡£¡£¡£¡£
CVE-2019-19025Îó²î£ºHarborÔÚWeb½çÃæÔÚʹÓÃÖУ¬£¬£¬£¬£¬£¬±£´æÉí·Ý¶þ´ÎУÑé²»ÑϵÄÇéÐΣ¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂCSRFµÈÎó²î¡£¡£¡£¡£¡£
CVE-2019-16919Îó²î£ºÈ¨ÏÞÌáÉýÎó²î¡£¡£¡£¡£¡£
CVE-2019-16097Îó²î£ºÔÊÐí·ÇÖÎÀíÔ±Óû§Í¨¹ýPOST / api / users API½¨ÉèÖÎÀíÔ±ÕÊ»§¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
¹Ù·½ÒѾÐû²¼¸üв¹¶¡£¬£¬£¬£¬£¬£¬½¨Òé¸üе½1.9.3ºÍ1.8.6ÒÔÉϰ汾£º
https://github.com/goharbor/harbor/releases/tag/v1.9.3
https://github.com/goharbor/harbor/releases/tag/v1.8.6
²Î¿¼Á´½Ó
https://github.com/goharbor/harbor/security/advisories


¾©¹«Íø°²±¸11010802024551ºÅ