Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Redis Êä³ö»º³åÇøÎÞÏÞÔöÌíÎó²î |
CVE ID | CVE-2025-21605 |
Îó²îÀàÐÍ | ×ÊÔ´ºÄ¾¡ | ·¢Ã÷ʱ¼ä | 2025-04-24 |
Îó²îÆÀ·Ö | 7.5 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
RedisÊÇÒ»¸ö¿ªÔ´µÄÄÚ´æÊý¾Ý½á¹¹´æ´¢ÏµÍ³£¬£¬ÆÕ±éÓ¦ÓÃÓÚ»º´æ¡¢ÐÂÎÅÐÐÁС¢ÊµÊ±ÆÊÎöµÈ³¡¾°¡£¡£¡£¡£¡£ËüÖ§³Ö¶àÖÖÊý¾Ý½á¹¹£¬£¬Èç×Ö·û´®¡¢¹þÏ£¡¢ÁÐ±í¡¢ÜöÝÍ¡¢ÓÐÐòÜöÝ͵ȣ¬£¬²¢Ìṩ¸»ºñµÄ²Ù×÷ÏÂÁî¡£¡£¡£¡£¡£Redis¾ßÓиßÐÔÄÜ¡¢ÎÞаÐԺͳ¤ÆÚ»¯ÄÜÁ¦£¬£¬Êý¾Ý¿ÉÒÔÉúÑÄÔÚÄÚ´æÖУ¬£¬°´ÆÚ»òƾ֤ÐèÇóͬ²½µ½´ÅÅÌ¡£¡£¡£¡£¡£ËüÖ§³ÖÖ÷´Ó¸´ÖÆ¡¢·ÖÇøºÍ¸ß¿ÉÓÃÐÔÉèÖ㬣¬³£ÓÃÓÚÌá¸ßϵͳÏìÓ¦ËÙÂʺͿÉÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£ÓÉÓÚÆä¸ßЧµÄ¶ÁÈ¡ºÍдÈëÐÔÄÜ£¬£¬Redis³ÉΪÏÖ´úÂþÑÜʽϵͳÖв»¿É»òȱµÄ×é¼þÖ®Ò»¡£¡£¡£¡£¡£
2025Äê4ÔÂ24ÈÕ£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½Redis¹Ù·½Ðû²¼µÄÇ徲ͨ¸æ£¬£¬ÔÚ7.4.3 > Redis >= 2.6°æ±¾ÖУ¬£¬Î´ÈÏÖ¤µÄ¿Í»§¶Ë¿ÉÒÔµ¼ÖÂÊä³ö»º³åÇøÎÞÏÞÔöÌí£¬£¬Ö±µ½Ð§ÀÍÆ÷ÄÚ´æºÄ¾¡»òÀú³Ì±»ÖÕÖ¹¡£¡£¡£¡£¡£Ä¬ÈÏÉèÖÃÏ£¬£¬Redis²»ÏÞÖÆÍ¨Ë׿ͻ§¶ËµÄÊä³ö»º³åÇø£¬£¬ÔÊÐíÆäÎÞÏÞÔöÌí£¬£¬µ¼ÖÂЧÀͱÀÀ£»£»£»£»£»òÄÚ´æ²»¿ÉÓᣡ£¡£¡£¡£×ÝÈ»ÆôÓÃÁËÃÜÂëÈÏÖ¤£¬£¬µ«Î´ÌṩÃÜÂ룬£¬¿Í»§¶ËÈÔ¿Éͨ¹ý"NOAUTH"ÏìÓ¦µ¼Ö»º³åÇøÔöÌí£¬£¬×îÖպľ¡ÏµÍ³ÄÚ´æ¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
7.4.3 > Redis >= 2.6
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ÖÁRedis 7.4.3°æ±¾¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/redis/redis/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ïÔÌϵͳÎó²î£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://github.com/redis/redis/releases/tag/7.4.3https://github.com/redis/redis/security/advisories/GHSA-r67f-p999-2gff