Strapi ãããã¬ã¹ CMS ã§ããããããé倧ãªè匱æ§: å±éºã«ãããããŠãã䟵害ãããã¢ã«ãŠã³ã
Strapi ãããã¬ã¹ CMS ã® 2 ã€ã®é倧ãªã»ãã¥ãªãã£äžã®æ¬ é¥ãä¿®æ£ãããŸããããã®è匱æ§ã«ãããæ»æè ã¯æš©éã®äœãã¢ã«ãŠã³ãã䜿çšããŠæš©éã®é«ãã¢ã«ãŠã³ãã®ãã¹ã¯ãŒãããªã»ããã§ããããã«ãªãã管çè ã¢ã«ãŠã³ãã䟵害ãããå¯èœæ§ããããŸããã

API éçºçšã«èšèšãããäž»èŠãªãããã¬ã¹ ã³ã³ãã³ã管çã·ã¹ãã (CMS) ã§ããStrapi ã管çã¢ã«ãŠã³ãã®äŸµå®³ã«ã€ãªããå¯èœæ§ã®ãã 2 ã€ã®é倧ãªè匱æ§ã«å¯ŸåŠããããããé©çšããŸããã Strapi ã䜿çšããŠããçµç¹ã¯ããããã®æ¬ é¥ãæªçšããå¯èœæ§ã®ããè åšããã·ã¹ãã ãä¿è·ããããã«ãã€ã³ã¹ããŒã«ãçŽã¡ã«æŽæ°ããå¿ èŠããããŸãã
Synopsys Cybersecurity Research Center (CyRC) ã®ç ç©¶è ãè匱æ§ãçºèŠããæš©éã®äœããŠãŒã¶ãŒãæ©å¯æ å ±ãååŸã§ããããã«ãªããŸããããããã®æ¬ é¥ãæªçšãããšãæ»æè ã¯ç®¡çè ãå«ãé«ãæš©éãæã€ã¢ã«ãŠã³ãã®ãã¹ã¯ãŒãããªã»ããã§ããå¯èœæ§ããããŸããè匱æ§ãæªçšããã«ã¯ãæ»æè ã¯ãŸããè³æ Œæ å ±ã®äŸµå®³ããã£ãã·ã³ã°ãªã©ã®ææ³ã䜿çšããŠãæš©éã®äœãã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸãã
Node.js JavaScript ã©ã³ã¿ã€ã äžã«æ§ç¯ãããStrapi ãããŸããŸãªããŒã¿ããŒã¹ãšããã³ããšã³ã ãã¬ãŒã ã¯ãŒã¯ããµããŒããããããã¬ã¹ CMS ã§ãããã®äž»ãªæ©èœã¯ãã³ã³ãã³ããäœæã管çãããã³ä¿åããããã®ããã¯ãšã³ã ã·ã¹ãã ãæäŸããããšã§ãããã®ã³ã³ãã³ã㯠API ãä»ããŠå ¬éã§ãããããéçºè ã¯ç¬ç«ããããã³ããšã³ãçµ±åãäœæã§ããŸãããããã®åŒ·åãªããŒã«ã«ãããStrapi ã¯ãWeb ãµã€ããã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ãã¢ãã®ã€ã³ã¿ãŒããã (IoT) ããã€ã¹ãªã©ãè€æ°ã®ãŠãŒã¹ ã±ãŒã¹åãã® API ãèšèšããããšããŠããäŒæ¥ã«ãšã£ãŠäººæ°ã®ããéžæè¢ãšãªã£ãŠããŸãã
WordPress ã Joomla ãªã©ã®æ±çš CMS 補åã«æ¯ã¹ãŠåžå Žã·ã§ã¢ãå°ããã«ããããããã Strapi IBMãNASAãGeneraliãWalmartãToyota ãªã©ã®æåäŒæ¥ããŠãŒã¶ãŒãšããŠåŒãä»ããŠããŸããããã®åŸåã¯ãéèŠãªã°ããŒãã«äŒæ¥ã«åœ±é¿ãäžããå¯èœæ§ãããããããããã®è匱æ§ã«é¢é£ããæœåšçãªãªã¹ã¯ã瀺ããŠããŸãã
CVE-2022-30617 ãšåä»ããããæåã®æ¬ é¥ã¯ãã·ããã·ã¹ã®ç ç©¶è ã«ãã£ãŠ 11 æã«ç¹å®ãããŸããã圌ãã¯ãStrapi 管çããã« ã¢ã¯ã»ã¹ãæã€èªèšŒæžã¿ãŠãŒã¶ãŒããã³ã³ãã³ãé¢ä¿ãæã€ç®¡çãŠãŒã¶ãŒã®é»åã¡ãŒã«ããã³ãã¹ã¯ãŒã ãªã»ãã ããŒã¯ã³ã«ã¢ã¯ã»ã¹ã§ããããšãçºèŠããŸããããã®åŸãæ»æè ã¯ãã®æ å ±ã䜿çšããŠãæš©éã®é«ããŠãŒã¶ãŒã察象ãšãããã¹ã¯ãŒã ãªã»ãã ããã»ã¹ãéå§ããå¯èœæ§ããããŸãã Strapi圹å²ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ (RBAC) ãšãID ãããã€ããŒããã³ Microsoft Active Directory ãšã®ã·ã³ã°ã« ãµã€ã³ãªã³ (SSO) ã®çµ±åããµããŒãããŠããŸãã
Strapi v4.0.0 ã¯ã11 æã« CVE-2022-30617 ã®è匱æ§ã«ããããé©çšããŸããããã®ä¿®æ£ã¯ã仿ãªãªãŒã¹ããã Strapi v3.6.10 ã«ãããã¯ããŒããããŸããããã®æ¬ é¥ã® Common Vulnerabilities Scoring System (CVSS) è©äŸ¡ã¯ 8.8 (é«) ã§ãã
CVE-2022-30617 ã®æåã®ãããã確èªãããšãããSynopsys ã®ç ç©¶è ã¯ããã©ã°ã€ã³ users-permissions ã«ãã£ãŠç®¡çããã API ãŠãŒã¶ãŒã«åœ±é¿ãäžãããAPI ããŒããã·ã§ã³ ã·ã¹ãã ã«ãããåæ§ã®åé¡ãçºèŠããŸããããã® 2 çªç®ã®è匱æ§ã¯ãCVE-2022-30618 ãšããŠèå¥ãããCVSS è©äŸ¡ã¯ 7.5 (é«) ã§ãããã®è匱æ§ã«ãããStrapi 管çããã«ãžã®ã¢ã¯ã»ã¹æš©ãæã€èªèšŒæžã¿ãŠãŒã¶ãŒã¯ãä»ã® API ãŠãŒã¶ãŒãšã®ã³ã³ãã³ãé¢ä¿ãæã€ API ãŠãŒã¶ãŒã®é»åã¡ãŒã«ãšãã¹ã¯ãŒãã®ãªã»ãã ããŒã¯ã³ãååŸã§ããŸãã
CVE-2022-30618 ã®æ¬ é¥ãæªçšããã«ã¯ããã¹ã¯ãŒã ãªã»ãã API endpointãæå¹ã«ããå¿ èŠããããŸããææªã®ã·ããªãªã§ã¯ãæš©éã®äœããŠãŒã¶ãŒãæš©éã®é«ã API ã¢ã«ãŠã³ããžã®ã¢ã¯ã»ã¹æš©ãååŸããããŒã¿ã®èªã¿åããšå€æŽãè¡ããæš©éãåãæ¶ãããšã§ä»ã®ãã¹ãŠã®ãŠãŒã¶ãŒã®ç®¡çããã«ãš API ãžã®ã¢ã¯ã»ã¹ããããã¯ããããšãããããŸãã Strapi ã®ã¡ã³ãããŒã¯ 12 æã« CVE-2022-30618 ã®åé¡ãéç¥ããã5 æ 11 æ¥ã«ãªãªãŒã¹ãããããŒãžã§ã³ 3.6.10 ããã³ 4.0.10 ã«ããããé©çšãããŸããã
çµç¹ã¯ãåŸæ¥ã® CMS ãã©ãããã©ãŒã ã«å ããŠãç¹å®ã®ãŠãŒã¹ ã±ãŒã¹ã«å©ç¹ããããã代æ¿ãœãªã¥ãŒã·ã§ã³ãæ€èšããå ŽåããããŸãã匷åãªno-codeãã©ãããã©ãŒã ã§ããAppMaster䜿çšãããšããŠãŒã¶ãŒã¯ããã¯ãšã³ããWebãããã³ã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ãç°¡åã«äœæã§ããŸãã AppMaster ãããŒã¿ ã¢ãã«ãããžãã¹ ããžãã¯ãREST APIãããã³ WebSocket ã»ãã¥ã¢ ãšã³ããã€ã³ãã®äœæãå æ¬çã«ãµããŒããããããå¹ åºãã¢ããªã±ãŒã·ã§ã³éçºã·ããªãªã§åºã䜿çšãããŠããŸãã


