ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื™ื ื’ืจืขืกืก-ื ื’ื™ื ืงืก ื•ื•ืึธืก ืœืึธื–ืŸ ืงื•ื‘ืขืจื ืขื˜ืขืก ืงืœืึทืกื˜ืขืจื– ืฆื• ื–ื™ื™ืŸ ืงืึทืžืคึผืจืึทืžื™ื™ื–ื“

ืื™ืŸ ื“ื™ ื™ื ื’ืจืขืกืก-ื ื’ื™ื ืงืก ืงืึทื ื˜ืจืึธื•ืœืขืจ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ื“ื™ Kubernetes ืคึผืจื•ื™ืขืงื˜, ื“ืจื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื•ื•ืึธืก ืœืึธื–ืŸ, ืื™ืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ืึทืงืกืขืก ืฆื• ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ืคื•ืŸ ื“ื™ Ingress ื›ื™ื™ืคืขืฅ, ื•ื•ืึธืก, ืฆื•ื•ื™ืฉืŸ ืื ื“ืขืจืข ื–ืื›ืŸ, ืกื˜ืึธืจื– ืงืจืึทื“ืขื ื˜ืฉืึทืœื– ืคึฟืึทืจ ืึทืงืกืขืก Kubernetes ืกืขืจื•ื•ืขืจืก, ืึทืœืึทื•ื™ื ื’ ืคึผืจื™ื•ื•ืœื™ื“ื–ืฉื“ ืึทืงืกืขืก. ืฆื• ื“ืขืจ ืงื ื•ื™ืœ. ื“ื™ ืคืจืื‘ืœืขืžืขืŸ ื“ืขืจืฉื™ื™ึทื ืขืŸ ื‘ืœื•ื™ื– ืื™ืŸ ื“ื™ ื™ื ื’ืจืขืกืก-ื ื’ื™ื ืงืก ืงืึทื ื˜ืจืึธื•ืœืขืจ ืคึฟื•ืŸ ื“ื™ Kubernetes ืคึผืจื•ื™ืขืงื˜ ืื•ืŸ ื˜ืึธืŸ ื ื™ื˜ ื•ื•ื™ืจืงืŸ ื“ื™ ืงื•ื‘ืขืจื ืขื˜ืขืก-ื™ื ื’ืจืขืกืก ืงืึธื ื˜ืจืึธืœืœืขืจ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ื“ื™ NGINX ื“ืขื•ื•ืขืœืึธืคึผืขืจืก.

ื“ื™ ื™ื ื’ืจืขืกืก ืงืึธื ื˜ืจืึธืœืœืขืจ ืึทืงื˜ ื•ื•ื™ ืึท ื’ื™ื™ื˜ื•ื•ื™ื™ ืื•ืŸ ืื™ื– ื’ืขื ื™ืฆื˜ ืื™ืŸ Kubernetes ืฆื• ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ืึทืงืกืขืก ืคึฟื•ืŸ ื“ื™ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื ืขืฅ ืฆื• ืกืขืจื•ื•ื™ืกืขืก ืื™ืŸ ื“ืขื ืงื ื•ื™ืœ. ื“ื™ ื™ื ื’ืจืขืกืก-ื ื’ื™ื ืงืก ืงืึธื ื˜ืจืึธืœืœืขืจ ืื™ื– ื“ื™ ืžืขืจืกื˜ ืคืึธืœืงืก ืื•ืŸ ื ื™ืฆื˜ ื“ื™ NGINX ืกืขืจื•ื•ืขืจ ืฆื• ืคืึธืจื•ื™ืก ืจื™ืงื•ื•ืขืก ืฆื• ื“ื™ ืงื ื•ื™ืœ, ืžืึทืจืฉืจื•ื˜ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืจื™ืงื•ื•ืขืก ืื•ืŸ ืžืึทืกืข ื•ื•ืึธื’. ื“ื™ Kubernetes ืคึผืจื•ื™ืขืงื˜ ืคึผืจืึธื•ื•ื™ื“ืขืก ื”ืึทืจืฅ ื™ื ื’ืจืขืกืก ืงืึทื ื˜ืจืึธื•ืœืขืจื– ืคึฟืึทืจ AWS, GCE ืื•ืŸ nginx, ื“ื™ ืœืขืฆื˜ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ื•ื•ืึธืก ืื™ื– ืื™ืŸ ืงื™ื™ืŸ ื•ื•ืขื’ ืฉื™ื™ึทื›ื•ืช ืฆื• ื“ื™ ืงื•ื‘ืขืจื ืขื˜ืขืก ื™ื ื’ืจืขืกืก ืงืึธื ื˜ืจืึธืœืœืขืจ ืžื™ื™ื ื˜ื™ื™ื ื“ ื“ื•ืจืš F5 / NGINX.

ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื™ื ื’ืจืขืกืก-ื ื’ื™ื ืงืก ื•ื•ืึธืก ืœืึธื–ืŸ ืงื•ื‘ืขืจื ืขื˜ืขืก ืงืœืึทืกื˜ืขืจื– ืฆื• ื–ื™ื™ืŸ ืงืึทืžืคึผืจืึทืžื™ื™ื–ื“

ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– CVE-2023-5043 ืื•ืŸ CVE-2023-5044 ืœืึธื–ืŸ ืื™ืจ ืฆื• ื•ื™ืกืคื™ืจืŸ ื“ื™ื™ืŸ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ ืžื™ื˜ ื“ื™ ืจืขื›ื˜ ืคื•ืŸ ื“ื™ ื™ื ื’ืจืขืกืก ืงืึธื ื˜ืจืึธืœืœืขืจ ืคึผืจืึธืฆืขืก, ื ื™ืฆืŸ ื“ื™ "nginx.ingress.kubernetes.io/configuration-snippet" ืื•ืŸ "nginx.ingress" .kubernetes" ืคึผืึทืจืึทืžืขื˜ืขืจืก ืฆื• ืคืึทืจื‘ื™ื™ึทื˜ืŸ ืขืก .io/permanent-redirect." ืฆื•ื•ื™ืฉืŸ ืื ื“ืขืจืข ื–ืื›ืŸ, ื“ื™ ื‘ืืงื•ืžืขืŸ ืึทืงืกืขืก ืจืขื›ื˜ ืœืึธื–ืŸ ืื™ืจ ืฆื•ืจื™ืงืงืจื™ื’ืŸ ืึท ืกื™ืžืขืŸ ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ื™ืฃ ื“ื™ ืงื ื•ื™ืœ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’ ืžื“ืจื’ื”. ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ CVE-2022-4886 ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ื™ื™ืคึผืึทืก ื˜ืขืงืข ื“ืจืš ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ื ื™ืฆืŸ ื“ื™ ืœืึธื’_ืคืึธืจืžืึทื˜ ื“ื™ืจืขืงื˜ื™ื•ื•.

ื“ื™ ืขืจืฉื˜ืข ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื“ืขืจืฉื™ื™ึทื ืขืŸ ื‘ืœื•ื™ื– ืื™ืŸ Ingress-nginx ืจื™ืœื™ืกื™ื– ืื™ื™ื“ืขืจ ื•ื•ืขืจืกื™ืข 1.9.0, ืื•ืŸ ื“ื™ ืœืขืฆื˜ืข - ืื™ื™ื“ืขืจ ื•ื•ืขืจืกื™ืข 1.8.0. ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึทืŸ ืึทื˜ืึทืง, ืึท ืึทื˜ืึทืงืขืจ ืžื•ื–ืŸ ื”ืึธื‘ืŸ ืฆื•ื˜ืจื™ื˜ ืฆื• ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ื™ื ื’ืจืขืกืก ื›ื™ื™ืคืขืฅ, ืœืžืฉืœ, ืื™ืŸ ืžืึทืœื˜ื™-ื˜ืขื ืึทื ื˜ Kubernetes ืงืœืึทืกื˜ืขืจื–, ืื™ืŸ ื•ื•ืึธืก ื“ื™ ื™ื•ื–ืขืจื– ื”ืึธื‘ืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉืึทืคึฟืŸ ืึทื‘ื“ื–ืฉืขืงืฅ ืื™ืŸ ื–ื™ื™ืขืจ ื ืึธืžืขืŸ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’