Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Apache Kyuubi Ŀ¼»á¼û¿ØÖÆÈƹýÎó²î |
CVE ID | CVE-2025-66518 |
Îó²îÀàÐÍ | »á¼û¿ØÖƲ»µ± | ·¢Ã÷ʱ¼ä | 2026-1-7 |
Îó²îÆÀ·Ö | 8.8 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache KyuubiÊÇApache»ù½ð»áÆìϵÄÂþÑÜʽSQLÍø¹ØÓë¶à×â»§ÅÌËãЧÀÍÆ½Ì¨£¬£¬Ö÷ÒªÃæÏòApache Spark¡¢FlinkµÈ´óÊý¾ÝÅÌËãÒýÇæ¡£¡£¡£¡£Kyuubiͨ¹ýͳһµÄЧÀͲã¶ÔÍâÌṩJDBC/RESTµÈ»á¼û½Ó¿Ú£¬£¬ÊµÏֻỰ¸ôÀ롢ȨÏÞ¿ØÖÆ¡¢×ÊÔ´ÖÎÀíÓëÉó¼ÆÄÜÁ¦£¬£¬½µµÍ¶àÓû§¹²Ïí´óÊý¾Ý¼¯ÈºµÄÔËάÓëÇå¾²ÖØÆ¯ºó£¬£¬ÆÕ±éÓ¦ÓÃÓÚÆóÒµ¼¶Êý¾ÝÆÊÎöÓëÊý¾ÝÖÎÀí³¡¾°¡£¡£¡£¡£
2026Äê1ÔÂ7ÈÕ£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½Apache Kyuubi ServerÖб£´æÄ¿Â¼»á¼û¿ØÖÆÈƹýÎó²î¡£¡£¡£¡£ÓÉÓÚЧÀÍÆ÷¶ËÔÚ´¦Öóͷ£ÍâµØÂ·¾¶Ê±È±·¦ÐëÒªµÄ·¾¶¹æ·¶»¯Ð£Ñ飬£¬¹¥»÷ÕßÖ»ÒªÄܹ»Í¨¹ýKyuubiǰ¶ËÐÒé»á¼ûЧÀÍ£¬£¬¼´¿ÉÈÆ¹ýkyuubi.session.local.dir.allow.listÉèÖÃÏÞÖÆ£¬£¬»á¼û»òʹÓÃδ±»ÔÊÐíÁбí°üÀ¨µÄÍâµØÎļþ×ÊÔ´¡£¡£¡£¡£¸ÃÎÊÌâ¿ÉÄܵ¼ÖÂÍâµØÃô¸ÐÊý¾Ý±»²»·¨¶ÁÈ¡£¬£¬ÆÆËðϵͳÔÓеĻá¼û¿ØÖƽçÏߣ¬£¬ÔöÌíÊý¾Ýй¶ÓëºÏ¹æÎ£º¦¡£¡£¡£¡£Îó²îÆÀ·Ö8.8·Ö£¬£¬Îó²î¼¶±ð¸ßΣ¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
1.6.0 <= Apache Kyuubi <= 1.10.2
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/apache/kyuubi/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ïÔÌϵͳÎó²î£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://lists.apache.org/thread/xp460bwbyzdhho34ljd4nchyt2fmhodl/https://nvd.nist.gov/vuln/detail/CVE-2025-66518