FixVibe
Covered by FixVibecritical

Ntunye iwu OS dị mkpa na LibreNMS (CVE-2024-51092)

Ụdị LibreNMS ruo 24.9.1 nwere os dị oke egwu adịghị ike ịgbanye iwu (CVE-2024-51092). Ndị na-awakpo akwadoro nwere ike mebie iwu aka ike na sistemu nnabata, nwere ike bute mmebi mkpokọta akụrụngwa nlekota.

CVE-2024-51092GHSA-x645-6pf9-xwxwCWE-78

Mmetụta

Ụdị LibreNMS 24.9.1 na nke mbụ nwere adịghị ike nke na-enye ndị ọrụ akwadoro aka ịrụ ntụtụ iwu OS [S2]. Mgbugbu na-aga nke ọma na-enyere aka imezu iwu aka ike site na ohere nke onye ọrụ sava weebụ [S1]. Nke a nwere ike iduga nbibi sistemu zuru oke, ịnweta data nleba anya na-enweghị ikike, yana mmegharị mpụta n'ime akụrụngwa netwọkụ nke LibreNMS [S2] na-achịkwa.

Ihe kpatara ya

Ọdịmma ahụ gbanyere mkpọrọgwụ na nnọpụiche na-ezighi ezi nke ntinye aka onye ọrụ tupu etinye ya na iwu sistemụ arụmọrụ [S1]. Nkewa ntụpọ a dị ka CWE-78 [S1]. N'ụdị emetụtara, njedebe njedebe akọwapụtara anaghị akwado nke ọma ma ọ bụ mee ka paramita dị ọcha tupu ịgafe ha na ọrụ mmezu nke usoro [S2].

Mgbanwe

Ndị ọrụ kwesịrị ịkwalite nrụnye LibreNMS ha na ụdị 24.10.0 ma ọ bụ mgbe e mesịrị iji dozie okwu a [S2]. Dịka omume kachasị mma maka nchekwa, ohere ịnweta interface nhazi LibreNMS kwesịrị ịbụ naanị na mpaghara netwọk ntụkwasị obi site na iji firewalls ma ọ bụ ndepụta njikwa (ACLs) [S1].

Kedu ka FixVibe si nwalee ya

FixVibe gụnyere nke a na nyocha GitHub repo. Nlele ahụ na-agụ naanị faịlụ ndabere nchekwa ikike, gụnyere composer.lock na composer.json. Ọ na-egosi ụdị ekpochi librenms/librenms ma ọ bụ ihe mgbochi dabara na mpaghara emetụtara <=24.9.1, wee kọọ faịlụ dabere, nọmba ahịrị, NJ ndụmọdụ, oke emetụtara na ụdị edoziri.

Nke a bụ nlele repo naanị agụghị. Ọ naghị eme koodu ndị ahịa na ọ naghị ezipu ibu akwụ ụgwọ nrigbu.