Harbor¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-12-04

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-19029£¬ £¬ £¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬ £¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19026£¬ £¬ £¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬ £¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19025£¬ £¬ £¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬ £¬ £¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3990£¬ £¬ £¬£¬ £¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬ £¬ £¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19023£¬ £¬ £¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬ £¬ £¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-16919£¬ £¬ £¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬ £¬ £¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-16097£¬ £¬ £¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬ £¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Harbor 1.7.*

Harbor 1.8.*<1.8.6

Harbor 1.9.*<1.9.3


Îó²î¸ÅÊö


HarborÊÇÒ»¸öÓÃÓÚ´æ´¢ºÍ·Ö·¢Docker¾µÏñµÄÆóÒµ¼¶RegistryЧÀÍÆ÷£¬ £¬ £¬£¬ £¬Í¨¹ýÌí¼ÓһЩÆóÒµ±ØÐèµÄ¹¦Ð§ÌØÕ÷£¬ £¬ £¬£¬ £¬ÀýÈçÇå¾²¡¢±êʶºÍÖÎÀíµÈ£¬ £¬ £¬£¬ £¬À©Õ¹ÁË¿ªÔ´Docker Distribution¡£¡£¡£¡£¡£¡£¡£¡£×÷Ϊһ¸öÆóÒµ¼¶Ë½ÓÐRegistryЧÀÍÆ÷£¬ £¬ £¬£¬ £¬HarborÌṩÁ˸üºÃµÄÐÔÄܺÍÇå¾²¡£¡£¡£¡£¡£¡£¡£¡£ÌáÉýÓû§Ê¹ÓÃRegistry¹¹½¨ºÍÔËÐÐÇéÐδ«Êä¾µÏñµÄЧÂÊ¡£¡£¡£¡£¡£¡£¡£¡£HarborÖ§³Ö×°ÖÃÔÚ¶à¸öRegistry½ÚµãµÄ¾µÏñ×ÊÔ´¸´ÖÆ£¬ £¬ £¬£¬ £¬¾µÏñËùÓÐÉúÑÄÔÚ˽ÓÐRegistryÖУ¬ £¬ £¬£¬ £¬È·±£Êý¾ÝºÍ֪ʶ²úȨÔÚ¹«Ë¾ÄÚ²¿ÍøÂçÖйܿØ¡£¡£¡£¡£¡£¡£¡£¡£ÁíÍ⣬ £¬ £¬£¬ £¬HarborÒ²ÌṩÁ˸߼¶µÄÇå¾²ÌØÕ÷£¬ £¬ £¬£¬ £¬ÖîÈçÓû§ÖÎÀí£¬ £¬ £¬£¬ £¬»á¼û¿ØÖƺͻÉ󼯵È¡£¡£¡£¡£¡£¡£¡£¡£


ƾ֤Harbor¹Ù·½Ç徲ͨ¸æ, Harbor±£´æÒÔÏÂÇå¾²ÎÊÌ⣺


CVE-2019-19026¡¢CVE-2019-19029Îó²î£ºHarbor±£´æSQLÅÌÎÊÓï¾ä¹ýÂ˲»Ñϵ¼ÖÂSQL×¢È룻£»£»£»£»


CVE-2019-19023Îó²î£ºHarborÔÚŲÓÃAPIʱδ¶ÔAPIÇëÇó¾ÙÐÐÑÏ¿áÏÞÖÆ£¬ £¬ £¬£¬ £¬±£´æÍ¨Ë×Óû§¿ÉÒÔͨ¹ýŲÓÃAPIÐÞ¸ÄÌØ¶¨Óû§µÄµç×ÓÓʼþµØµã£¬ £¬ £¬£¬ £¬´Ó¶ø»ñµÃÖÎÀíÔ±ÕÊ»§È¨ÏÞ£¬ £¬ £¬£¬ £¬±ã¿ÉÖØÖøõç×ÓÓʼþµØµãµÄÃÜÂë²¢»ñµÃ¶Ô¸ÃÕÊ»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-3990Îó²î£ºHarborÔÚʹÓÃapi/users/searchʱδ¾ÙÐкÏÀíÉí·ÝУÑ飬 £¬ £¬£¬ £¬±£´æÈƹýÖÎÀíÔ±ÏÞÖÆ¾ÙÐÐÓû§Ãûö¾Ù¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-19025Îó²î£ºHarborÔÚWeb½çÃæÔÚʹÓÃÖУ¬ £¬ £¬£¬ £¬±£´æÉí·Ý¶þ´ÎУÑé²»ÑϵÄÇéÐΣ¬ £¬ £¬£¬ £¬´Ó¶øµ¼ÖÂCSRFµÈÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-16919Îó²î£ºÈ¨ÏÞÌáÉýÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-16097Îó²î£ºÔÊÐí·ÇÖÎÀíÔ±Óû§Í¨¹ýPOST / api / users API½¨ÉèÖÎÀíÔ±ÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


¹Ù·½ÒѾ­Ðû²¼¸üв¹¶¡£¬ £¬ £¬£¬ £¬½¨Òé¸üе½1.9.3ºÍ1.8.6ÒÔÉϰ汾£º


https://github.com/goharbor/harbor/releases/tag/v1.9.3

https://github.com/goharbor/harbor/releases/tag/v1.8.6


²Î¿¼Á´½Ó


https://github.com/goharbor/harbor/security/advisories