ืคื’ื™ืขื•ืช ื‘ืžืžืฉืง ื ื™ื˜ื•ืจ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ Icinga

ื™ืฆื ืœืื•ืจ ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ื”ื—ื‘ื™ืœื” Icinga Web 2.6.4, 2.7.4 ื•-v2.8.2, ื”ืžืกืคืง ืžืžืฉืง ืื™ื ื˜ืจื ื˜ ืœืžืขืจื›ืช ื”ื ื™ื˜ื•ืจ ืื™ืกื™ื ื’ื”. ื”ืขื“ื›ื•ื ื™ื ื”ืžื•ืฆืขื™ื ืžื‘ื˜ืœื™ื ืงืจื™ื˜ื™ ืคื’ื™ืขื•ืช (CVE-2020-24368), ืžืืคืฉืจ ืœืชื•ืงืฃ ืœื ืžืื•ืžืช ืœื’ืฉืช ืœืงื‘ืฆื™ื ื‘ืฉืจืช ืขื ื”ืจืฉืื•ืช ืฉืœ ืชื”ืœื™ืš Icinga Web (ื‘ื“ืจืš ื›ืœืœ ื”ืžืฉืชืžืฉ ืฉืชื—ืชื™ื• ืคื•ืขืœ ืฉืจืช http ืื• fpm).

ื”ืชืงืคื” ืžื•ืฆืœื—ืช ื“ื•ืจืฉืช ื ื•ื›ื—ื•ืช ืฉืœ ืื—ื“ ืžื”ืžื•ื“ื•ืœื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืฉืžื’ื™ืขื™ื ืขื ืชืžื•ื ื•ืช ืื• ืื™ื™ืงื•ื ื™ื. ื‘ื™ืŸ ืžื•ื“ื•ืœื™ื ื›ืืœื” ื ื™ืชืŸ ืœืžืฆื•ื ืืช Icinga Business Process Modeling, Icinga ืžื ื”ืœ,
Icinga Reporting, Maps Module ื•ืžื•ื“ื•ืœ Globe. ืžื•ื“ื•ืœื™ื ืืœื• ืขืฆืžื ืื™ื ื ืžื›ื™ืœื™ื ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ืืš ื”ื ื’ื•ืจืžื™ื ื”ืžืืคืฉืจื™ื ืœืืจื’ืŸ ื”ืชืงืคื” ืขืœ Icinga Web.

ื”ื”ืชืงืคื” ืžืชื‘ืฆืขืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช HTTP GET ืื• POST ืœืžื˜ืคืœ ื”ืžืฉืจืช ืชืžื•ื ื•ืช, ืฉื”ื’ื™ืฉื” ืืœื™ื” ืื™ื ื” ืžืฆืจื™ื›ื” ื—ืฉื‘ื•ืŸ. ืœื“ื•ื’ืžื”, ืื Icinga Web 2 ื–ืžื™ืŸ ื‘ืชื•ืจ "/icingaweb2" ื•ืœืžืขืจื›ืช ืžื•ืชืงืŸ ืžื•ื“ื•ืœ businessprocess ื‘ืกืคืจื™ื™ืช /usr/share/icingaweb2/modules, ืืชื” ื™ื›ื•ืœ ืœืฉืœื•ื— ื‘ืงืฉื” "GET /icingaweb2/static" ื›ื“ื™ ืœืงืจื•ื ืืช ื”ืชื•ื›ืŸ ืฉืœ /etc/os-release file /img?module_name=businessprocess&file=../../../../../../../etc/os-release."

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”