Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!´úÂëÇ徲ʵÑéÊÒÑо¿Ô±×ÊÖúRed HatÔÚoVirt-engineÈí¼þÖз¢Ã÷ÁËÁ½¸öÎó²î£¨CVE-2020-14333ºÍCVE-2020-10775£©£¬£¬£¬£¬£¬£¬£¬£¬²¢µÚһʱ¼ä±¨¸æRed Hat£¬£¬£¬£¬£¬£¬£¬£¬ÐÖúÆäÐÞ¸´Îó²î¡£¡£¡£¡£¡£
oVirt ÊÇÒ»¿îÃâ·Ñ¿ªÔ´µÄÂþÑÜʽÐéÄ⻯½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÖÎÀíÕû¸öÆóÒµµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£oVirt ʹÓÃÊÜÐÅÍÐµÄ KVM ÖÎÀí³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬¹¹½¨ÓÚ¶àÖÖÆäËüÉçÇøÏîÄ¿£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ libvirt¡¢Gluster¡¢PatternFly ºÍ Ansible¡£¡£¡£¡£¡£Red HatÊÇoVirt ÉçÇøµÄÆóÒµÓû§£¬£¬£¬£¬£¬£¬£¬£¬ÈÏÕæ½¨oVirt ´úÂë¿â£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÉÌÒµÐéÄ⻯²úÆ·Red Hat VirtualizationµÄÉÏÓΰ汾ÖÐʹÓÃÁË¿ªÔ´×é¼þoVirt-engine¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Red HatÐû²¼Á˲¹¶¡¸üÐÂͨ¸æÒÔ¼°ÖÂлͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÖÂлÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!´úÂëÇ徲ʵÑéÊÒÑо¿Ö°Ô±¡£¡£¡£¡£¡£

ͼ Red Hat ¹Ù·½ÖÂл
CVE-2020-14333 ¨C oVirt XSS Îó²î
oVirt-engine 4.4.2¼°¸üÔç°æ±¾£¨Red Hat Virtualization Engine 4.4 ֮ǰ°æ±¾£©µÄ Web ½Ó¿ÚδÍêÈ«¹ýÂËÓû§¿É¿Ø²ÎÊý£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö·´ÉäÐÍ¿çÕ¾µã¾ç±¾¹¥»÷¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃȱÏÝ·¢¶¯´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Óû§ cookie»òÆäËüÉñÃØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬»òÔÚÓ¦ÓóÌÐòµÄÉÏÏÂÎÄÖÐð³äÓû§¡£¡£¡£¡£¡£
CVE-2020-10775 ¡ª oVirt URL ÖØ¶¨ÏòÎó²î
oVirt-engine °æ±¾4.4.1¼°¸üÔç°æ±¾£¨Red Hat Virtualization Engine 4.4 ֮ǰ°æ±¾£©Öб£´æÒ»¸ö¿ª·ÅÖØ¶¨ÏòÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß½«Óû§Öض¨ÏòÖÁí§Òâ Web Õ¾µã²¢ÊµÑé·¢¶¯´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£Ä¿µÄÔÚä¯ÀÀÆ÷Öз¿ª¶ñÒâ URL ʱ£¬£¬£¬£¬£¬£¬£¬£¬ÎÞ·¨¿´µ½¸Ã URL µÄÒªº¦²¿·Ö¡£¡£¡£¡£¡£¸ÃÎó²î´øÀ´µÄ×î´óÍþвÌåÏÖÔÚÉñÃØÐÔ·½Ãæ¡£¡£¡£¡£¡£
oVirt ÒÑÐû²¼ oVirt-engine Õýʽ°æ±¾4.4.2£¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËCVE-2020-10775£»£»£»£»£»£»²¢½«ÔÚ°æ±¾ 4.4.3 ÖÐÐÞ¸´CVE-2020-14333¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬£¬Red Hat ÒàÐû²¼ Red Hat Virtualization Engine 4.4£¬£¬£¬£¬£¬£¬£¬£¬ÒÑÐÞ¸´ÉÏÊöÁ½¸öÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Óû§Ó¦¾¡¿ìÓèÒÔ¸üд¦Öóͷ£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://access.redhat.com/security/cve/CVE-2020-14333https://access.redhat.com/security/cve/CVE-2020-10775https://gerrit.ovirt.org/#/c/111277/https://github.com/oVirt/ovirt-engine/commit/362a2a8f8eca542b48a1bba7f9c827fbc44bc955https://bugzilla.redhat.com/show_bug.cgi?id=1858184https://bugzilla.redhat.com/show_bug.cgi?id=1866688
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!´úÂëÎÀÊ¿¡±ÊÇÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìÏÂרעÓÚÈí¼þÔ´´úÂëÇå¾²µÄ²úÆ·Ïߣ¬£¬£¬£¬£¬£¬£¬£¬´úÂëÎÀʿϵÁвúÆ·¿ÉÖ§³Ö Windows¡¢Linux¡¢Android¡¢Apple iOS¡¢IBM AIX µÈƽ̨ÉϵÄÔ´´úÂëÇå¾²ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬Ö§³ÖµÄ±à³ÌÓïÑÔº¸Ç C¡¢C++¡¢C#¡¢Objective-C¡¢Java¡¢JSP¡¢JavaScript¡¢PHP¡¢Python¡¢Go¡¢Çø¿éÁ´ÖÇÄܺÏÔ¼ Solidity µÈ¡£¡£¡£¡£¡£ÏÖÔÚ´úÂëÎÀÊ¿ÒÑÓ¦ÓÃÓÚÉϰټҴóÐÍ»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬×ÊÖúÓû§¹¹½¨×ÔÉíµÄ´úÂëÇå¾²°ü¹Üϵͳ£¬£¬£¬£¬£¬£¬£¬£¬Ïû¼õÈí¼þ´úÂëÇå¾²Òþ»¼¡£¡£¡£¡£¡£
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!´úÂëÇ徲ʵÑéÊÒÊÇÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!´úÂëÎÀÊ¿µÄÑо¿ÍŶӣ¬£¬£¬£¬£¬£¬£¬£¬×¨ÃÅ´ÓÊÂÔ´´úÂë¡¢¶þ½øÖÆÎó²îÍÚ¾òºÍÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÑо¿Æ«Ïò°üÀ¨£ºWindows / Linux / MacOS ²Ù×÷ϵͳ¡¢Ó¦ÓÃÈí¼þ¡¢¿ªÔ´Èí¼þ¡¢ÍøÂç×°±¸¡¢IoT×°±¸µÈ¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!´úÂëÇ徲ʵÑéÊÒÒѾ×ÊÖú΢Èí¡¢¹È¸è¡¢Æ»¹û¡¢Cisco¡¢Juiper¡¢VMware¡¢Oracle¡¢LinuxÄÚºË×éÖ¯¡¢Adobe¡¢°¢ÀïÔÆ¡¢»ªÎª¡¢Ê©Ä͵¡¢D-Link¡¢ThinkPHP¡¢ÒÔÌ«·»¡¢ÖÖÖÖ¿ªÔ´×éÖ¯µÈÐÞ¸´ÁË100¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬²¢»ñµÃ¹Ù·½ÖÂл¡£¡£¡£¡£¡£