์„œ๋ฒ„์—์„œ ์ฝ”๋“œ ์‹คํ–‰์œผ๋กœ ์ด์–ด์ง€๋Š” Bitbucket ์„œ๋ฒ„์˜ ์ทจ์•ฝ์ 

์›๊ฒฉ ๊ณต๊ฒฉ์ž๊ฐ€ ์„œ๋ฒ„์—์„œ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ—ˆ์šฉํ•˜๋Š” git ๋ฆฌํฌ์ง€ํ† ๋ฆฌ ์ž‘์—…์„ ์œ„ํ•œ ์›น ์ธํ„ฐํŽ˜์ด์Šค ๋ฐฐํฌ์šฉ ํŒจํ‚ค์ง€์ธ Bitbucket Server์—์„œ ์‹ฌ๊ฐํ•œ ์ทจ์•ฝ์ (CVE-2022-43781)์ด ํ™•์ธ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์„œ๋ฒ„์—์„œ ์ž์ฒด ๋“ฑ๋ก์ด ํ—ˆ์šฉ๋œ ๊ฒฝ์šฐ("๊ณต๊ฐœ ๊ฐ€์ž… ํ—ˆ์šฉ" ์„ค์ •์ด ํ™œ์„ฑํ™”๋จ) ์ธ์ฆ๋˜์ง€ ์•Š์€ ์‚ฌ์šฉ์ž๊ฐ€ ์ทจ์•ฝ์ ์„ ์•…์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ๋ณ€๊ฒฝํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ(์˜ˆ: ADMIN ๋˜๋Š” SYS_ADMIN ๊ถŒํ•œ)์ด ์žˆ๋Š” ์ธ์ฆ๋œ ์‚ฌ์šฉ์ž์— ์˜ํ•ด์„œ๋„ ์ž‘์—…์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ์•„์ง ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์ œ๊ณต๋˜์ง€ ์•Š์•˜์œผ๋ฉฐ ์•Œ๋ ค์ง„ ๊ฒƒ์€ ํ™˜๊ฒฝ ๋ณ€์ˆ˜๋ฅผ ํ†ตํ•œ ๋ช…๋ น ๋Œ€์ฒด ๊ฐ€๋Šฅ์„ฑ์œผ๋กœ ์ธํ•ด ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•œ๋‹ค๋Š” ๊ฒƒ๋ฟ์ž…๋‹ˆ๋‹ค.

์ด ๋ฌธ์ œ๋Š” 7.x ๋ฐ 8.x ๋ถ„๊ธฐ์— ๋‚˜ํƒ€๋‚˜๋ฉฐ Bitbucket Server ๋ฐ Bitbucket Data Center ๋ฆด๋ฆฌ์Šค 8.5.0, 8.4.2, 7.17.12, 7.21.6, 8.0.5, 8.1.5์—์„œ ํ•ด๊ฒฐ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. 8.3.3, 8.2.4. ์ด ์ทจ์•ฝ์ ์€ bitbucket.org ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค์—๋Š” ๋‚˜ํƒ€๋‚˜์ง€ ์•Š์œผ๋ฉฐ ํ•ด๋‹น ์‚ฌ์ดํŠธ์— ์„ค์น˜๋œ ์ œํ’ˆ์—๋งŒ ์˜ํ–ฅ์„ ๋ฏธ์นฉ๋‹ˆ๋‹ค. PostgreSQL DBMS๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๋Š” Bitbucket Server ๋ฐ Data Center ์„œ๋ฒ„์—์„œ๋„ ๋ฌธ์ œ๊ฐ€ ๋‚˜ํƒ€๋‚˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€