¡¾Îó²îͨ¸æ¡¿SonarQubeδÊÚȨ»á¼ûÎó²î£¨CNVD-2021-84502£©

Ðû²¼Ê±¼ä 2021-11-24

0x00 Îó²î¸ÅÊö

2021Äê11ÔÂ5ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨CNVD£©ÊÕ¼ÁËSonarQubeϵͳδÊÚȨ»á¼ûÎó²î£¨CNVD-2021-84502£©¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚδÊÚȨµÄÇéÐÎÏ»ñÈ¡Ãô¸Ð´úÂëÊý¾Ý¡£¡£¡£¡£¡£¡£ÏÖÔÚSonarQube¹«Ë¾ÒѾ­Ðû²¼ÁË´ËÎó²îµÄ²¹¶¡£¬£¬£¬£¬£¬ £¬£¬£¬µ«Îó²îµÄʹÓÃϸ½ÚÒѹûÕæ¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

SonarQubeÊÇÒ»¸ö¿ªÔ´´úÂëÖÊÁ¿ÖÎÀíºÍÆÊÎöÉ󼯯½Ì¨£¬£¬£¬£¬£¬ £¬£¬£¬Ö§³Ö°üÀ¨Java£¬£¬£¬£¬£¬ £¬£¬£¬C#£¬£¬£¬£¬£¬ £¬£¬£¬C/C++£¬£¬£¬£¬£¬ £¬£¬£¬PL/SQL£¬£¬£¬£¬£¬ £¬£¬£¬Cobol£¬£¬£¬£¬£¬ £¬£¬£¬JavaScript£¬£¬£¬£¬£¬ £¬£¬£¬GroovyµÈ¶þÊ®¶àÖÖ±à³ÌÓïÑԵĴúÂëÖÊÁ¿ÖÎÀí£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÒÔ¶ÔÏîÄ¿ÖеÄÖØ¸´´úÂë¡¢³ÌÐò¹ýʧ¡¢±àд¹æ·¶¡¢Çå¾²Îó²îµÈÎÊÌâ¾ÙÐмì²â£¬£¬£¬£¬£¬ £¬£¬£¬²¢½«Ð§¹ûͨ¹ýSonarQube Web½çÃæ¾ÙÐзºÆð¡£¡£¡£¡£¡£¡£

SonarQube ϵͳÔÚĬÈÏÉèÖÃÏ£¬£¬£¬£¬£¬ £¬£¬£¬»á½«Í¨¹ýÉ󼯵ÄÔ´´úÂëÉÏ´«ÖÁSonarQubeƽ̨¡£¡£¡£¡£¡£¡£ÓÉÓÚSonarQubeȱÉÙ¶ÔAPI½Ó¿Ú»á¼ûµÄ¼øÈ¨¿ØÖÆ£¬£¬£¬£¬£¬ £¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ý»á¼ûÉÏÊöAPI½Ó¿Ú£¬£¬£¬£¬£¬ £¬£¬£¬»ñÈ¡SonarQubeƽ̨ÉϵijÌÐòÔ´´úÂ룬£¬£¬£¬£¬ £¬£¬£¬Ôì³ÉÏîĿԴ´úÂëÊý¾Ýй¶Σº¦¡£¡£¡£¡£¡£¡£

2021Äê10ÔÂÒÔÀ´£¬£¬£¬£¬£¬ £¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍø¼à²âµ½¾³ÍâºÚ¿Í×éÖ¯AgainstTheWest£¨¼ò³Æ¡°ATW¡±£©Õë¶ÔSonarQubeƽ̨¾ÙÐй¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬ÇÔÈ¡ÁËÎÒ¹ú¶à¼ÒÕþÆó»ú¹¹µÄÐÅϢϵͳԴ´úÂ룬£¬£¬£¬£¬ £¬£¬£¬²¢ÔÚÍâÑóºÚ¿ÍÂÛ̳RaidForumsÉϾÙÐв»·¨ÊÛÂô¡£¡£¡£¡£¡£¡£

ÔçÔÚ2020Äê4Ô£¬£¬£¬£¬£¬ £¬£¬£¬Áª°îÊÓ²ì¾Ö£¨FBI£©¾Í·¢Ã÷ºÚ¿ÍʹÓÃSonarQube´ÓÃÀ¹ú¸÷¸öÐÐÒµºÍÕþ¸®»ú¹¹ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

SonarQube < 8.6

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚSonarQube¹«Ë¾ÒѾ­ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬ £¬£¬£¬½¨ÒéÉý¼¶¸üе½SonarQube 8.6»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£

»º½â²½·¥£º

l  ¸ü¸ÄSonarQube ĬÈÏÉèÖ㬣¬£¬£¬£¬ £¬£¬£¬°üÀ¨¸ü¸ÄĬÈÏÖÎÀíÔ±Óû§Ãû¡¢ÃÜÂëºÍ¶Ë¿Ú(9000)¡£¡£¡£¡£¡£¡£

l  ÉèÖÿªÆôÈÏÖ¤¹¦Ð§£¬£¬£¬£¬£¬ £¬£¬£¬¹¹½¨Ë«ÒòËØÈÏÖ¤£¬£¬£¬£¬£¬ £¬£¬£¬²¢¼ì²éδ¾­ÊÚȨµÄÓû§ÊÇ·ñ»á¼ûÁ˸ÃʵÀý¡£¡£¡£¡£¡£¡£

l  ÈôÊÇ¿ÉÐУ¬£¬£¬£¬£¬ £¬£¬£¬×÷·Ï¶ÔÔÚ SonarQube ʵÀýÖйûÕæµÄÈκÎÓ¦ÓóÌÐò±à³Ì½Ó¿ÚÃÜÔ¿»òÆäËûƾ֤µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£

l  ½«SonarQube ʵÀýÉèÖÃΪ×éÖ¯µÄ·À»ðǽºÍÆäËûÍâΧ·ÀÓùÖ®ºó£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔ±ÜÃâδ¾­Éí·ÝÑéÖ¤µÄ»á¼û¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://mp.weixin.qq.com/s/BSnfaLJX7cuIt3ZfuxpKTA

https://mp.weixin.qq.com/s/mcYlZVGnm9Ubty1qWx3sCQ

https://docs.sonarqube.org/latest/setup/get-started-2-minutes/

https://www.bleepingcomputer.com/news/security/fbi-hackers-stole-government-source-code-via-sonarqube-instances/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-11-24

Ê×´ÎÐû²¼

 

0x05 ¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø

ÍòÀû¹ú¼Ê¹ÙÍø¼ò½é

ÍòÀû¹ú¼Ê¹ÙÍø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ £¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬ £¬£¬£¬ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·ºÍÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬ £¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬ £¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ£»£»£»£»²¢ÔÚ»ª±±¡¢»ª¶«¡¢Î÷ÄϺͻªÄϽṹËÄ´óÑз¢ÖÐÐÄ£¬£¬£¬£¬£¬ £¬£¬£¬»®·ÖΪ±±¾©Ñз¢×ܲ¿¡¢ÉϺ£Ñз¢ÖÐÐÄ¡¢³É¶¼Ñз¢ÖÐÐĺ͹ãÖÝÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£

¶àÄêÀ´£¬£¬£¬£¬£¬ £¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬ £¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬ £¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£

 

¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø

ÍòÀû¹ú¼Ê¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬ £¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png