{"id":2837,"date":"2023-05-11T16:35:07","date_gmt":"2023-05-11T08:35:07","guid":{"rendered":"http:\/\/www.gzwangan.com\/?p=2837"},"modified":"2023-05-11T16:50:49","modified_gmt":"2023-05-11T08:50:49","slug":"gitlab%e4%bb%a3%e7%a0%81%e6%89%a7%e8%a1%8c%e6%bc%8f%e6%b4%9e","status":"publish","type":"post","link":"http:\/\/www.gzwangan.com\/?p=2837","title":{"rendered":"GitLab\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"2837\" class=\"elementor elementor-2837\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-8e918bf elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"8e918bf\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-161dc63\" data-id=\"161dc63\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-34723854 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"34723854\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-516ade9f\" data-id=\"516ade9f\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6e18114a elementor-widget elementor-widget-heading\" data-id=\"6e18114a\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">GitLab\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-637242b8 elementor-section-content-middle elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"637242b8\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-28ae9bf\" data-id=\"28ae9bf\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6507484d elementor-widget elementor-widget-text-editor\" data-id=\"6507484d\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u6f0f\u6d1e\u7f16\u53f7<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-6867ddfc\" data-id=\"6867ddfc\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-67a47dfa elementor-widget elementor-widget-text-editor\" data-id=\"67a47dfa\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>CVE-2023-2478<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7c36f233 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7c36f233\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-18479ec4\" data-id=\"18479ec4\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3f9c8c47 elementor-widget elementor-widget-text-editor\" data-id=\"3f9c8c47\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u6f0f\u6d1e\u7c7b\u578b<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-35de3221\" data-id=\"35de3221\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2a116f elementor-widget elementor-widget-text-editor\" data-id=\"2a116f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c(RCE)<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-261278a2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"261278a2\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-2eaad13c\" data-id=\"2eaad13c\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-102b422e elementor-widget elementor-widget-text-editor\" data-id=\"102b422e\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u6f0f\u6d1e\u7b49\u7ea7<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-720b12cd\" data-id=\"720b12cd\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6ce9ce23 elementor-widget elementor-widget-text-editor\" data-id=\"6ce9ce23\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u4e25\u91cd<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-57a130d4 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"57a130d4\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-30273984\" data-id=\"30273984\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-549b5834 elementor-widget elementor-widget-text-editor\" data-id=\"549b5834\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u53d1\u5e03\u65f6\u95f4<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-3c9f3c53\" data-id=\"3c9f3c53\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-65cef8d5 elementor-widget elementor-widget-text-editor\" data-id=\"65cef8d5\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>2023-05-08<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4d4ed6c8 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4d4ed6c8\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-25203aff\" data-id=\"25203aff\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3c868a7b elementor-widget elementor-widget-text-editor\" data-id=\"3c868a7b\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<h4 style=\"text-align: center;\">\u6f0f\u6d1e\u63cf\u8ff0<\/h4><p>GitLab\u662f\u4e00\u4e2a\u7528\u4e8e\u4ed3\u5e93\u7ba1\u7406\u7cfb\u7edf\u7684\u5f00\u6e90\u9879\u76ee\uff0c\u5176\u4f7f\u7528Git\u4f5c\u4e3a\u4ee3\u7801\u7ba1\u7406\u5de5\u5177\uff0c\u53ef\u901a\u8fc7Web\u754c\u9762\u8bbf\u95ee\u516c\u5f00\u6216\u79c1\u4eba\u9879\u76ee\u3002<\/p><p>2023\u5e745\u67086\u65e5\uff0cGitLab\u5b98\u65b9\u53d1\u5e03\u66f4\u65b0\u516c\u544a\uff0c\u4fee\u590d\u4e86GitLab \u793e\u533a\u7248 \uff08CE\uff09\u548c\u4f01\u4e1a\u7248\uff08EE\uff09\u4e2d\u7684\u4e00\u4e2a\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e\uff0c\u6f0f\u6d1e\u7f16\u53f7\uff1aCVE-2023-2478\uff0c\u6f0f\u6d1e\u5371\u5bb3\u7b49\u7ea7\uff1a\u4e25\u91cd\u3002<\/p><p>GitLab CE\/EE\u591a\u4e2a\u53d7\u5f71\u54cd\u7248\u672c\u4e2d\uff0c\u67d0\u4e9b\u60c5\u51b5\u4e0b\u5b9e\u4f8b\u4e0a\u7ecf\u8fc7\u8eab\u4efd\u9a8c\u8bc1\u7684\u4efb\u4f55GitLab \u7528\u6237\u90fd\u53ef\u4ee5\u5229\u7528\u8be5\u6f0f\u6d1e\uff0c\u4f7f\u7528GraphQL\u7aef\u70b9\u5c06\u6076\u610f\u8fd0\u884c\u7a0b\u5e8f\u9644\u52a0\u5230\u5b9e\u4f8b\u4e0a\u7684\u4efb\u610f\u9879\u76ee\uff0c\u6210\u529f\u5229\u7528\u53ef\u80fd\u5bfc\u81f4\u654f\u611f\u4fe1\u606f\u6cc4\u9732\u6216\u4ee3\u7801\u6267\u884c\u7b49\u3002<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-57c04e65 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"57c04e65\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-40a7b1e\" data-id=\"40a7b1e\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-231ab650 elementor-widget elementor-widget-text-editor\" data-id=\"231ab650\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<h4 style=\"text-align: center;\">\u5f71\u54cd\u7248\u672c<\/h4><div class=\"effect-version-item\" data-v-27da897c=\"\"><p class=\"effect-version-item-type effect-version-item-product\" style=\"text-align: center;\" data-v-27da897c=\"\">15.4&lt;=GitLab CE&lt;15.9.7<\/p><\/div><div class=\"effect-version-item\" style=\"text-align: center;\" data-v-27da897c=\"\"><p class=\"effect-version-item-type effect-version-item-product\" data-v-27da897c=\"\">15.10&lt;=GitLab CE&lt;15.10.6<\/p><\/div><div class=\"effect-version-item\" style=\"text-align: center;\" data-v-27da897c=\"\"><p class=\"effect-version-item-type effect-version-item-product\" data-v-27da897c=\"\">15.11&lt;=GitLab CE&lt;15.11.2<\/p><\/div><div class=\"effect-version-item\" style=\"text-align: center;\" data-v-27da897c=\"\"><p class=\"effect-version-item-type effect-version-item-product\" data-v-27da897c=\"\">15.4&lt;=GitLab EE&lt;15.9.7<\/p><\/div><div class=\"effect-version-item\" data-v-27da897c=\"\"><p class=\"effect-version-item-type effect-version-item-product\" style=\"text-align: center;\" data-v-27da897c=\"\">15.10&lt;=GitLab EE&lt;15.10.6<\/p><\/div><div class=\"effect-version-item\" data-v-27da897c=\"\"><p class=\"effect-version-item-type effect-version-item-product\" style=\"text-align: center;\" data-v-27da897c=\"\">15.11&lt;=GitLab EE&lt;15.11.2<\/p><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-35392fc1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"35392fc1\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-53d849d8\" data-id=\"53d849d8\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2a885b84 elementor-widget elementor-widget-text-editor\" data-id=\"2a885b84\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<h4 style=\"text-align: center;\">\u4fee\u590d\u5efa\u8bae<\/h4><p>\u76ee\u524d\u8be5\u6f0f\u6d1e\u5df2\u7ecf\u4fee\u590d\uff0c\u53d7\u5f71\u54cd\u7528\u6237\u53ef\u5347\u7ea7\u5230\u4ee5\u4e0b\u7248\u672c\uff1a<br \/>GitLab CE\/EE\u7248\u672c\uff1a&gt;= 15.9.7<br \/>GitLab CE\/EE\u7248\u672c\uff1a&gt;= 15.10.6<br \/>GitLab CE\/EE\u7248\u672c\uff1a&gt;= 15.11.2<br \/>\u4e0b\u8f7d\u94fe\u63a5\uff1a<br \/><a href=\"https:\/\/about.gitlab.com\/update\/\" target=\"_blank\" rel=\"noopener\">https:\/\/about.gitlab.com\/update\/<\/a><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>GitLab\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e \u6f0f\u6d1e\u7f16\u53f7 CVE-2023-2478 \u6f0f\u6d1e\u7c7b\u578b \u8fdc\u7a0b\u4ee3\u7801\u6267\u884c(RCE) \u6f0f\u6d1e\u7b49\u7ea7 \u4e25&hellip; <a class=\"more-link\" href=\"http:\/\/www.gzwangan.com\/?p=2837\">\u7ee7\u7eed\u9605\u8bfb<span class=\"screen-reader-text\">GitLab\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"elementor_header_footer","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-2837","post","type-post","status-publish","format-standard","hentry","category-security","entry"],"_links":{"self":[{"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/posts\/2837","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2837"}],"version-history":[{"count":5,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/posts\/2837\/revisions"}],"predecessor-version":[{"id":2842,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/posts\/2837\/revisions\/2842"}],"wp:attachment":[{"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2837"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2837"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}