Strapi CMS ã§çºèŠãããé倧㪠JSON è匱æ§ãããŒã¿ ã»ãã¥ãªãã£ã«å¯Ÿããæœåšçãªè åš
ã·ããã·ã¹ ãµã€ããŒã»ãã¥ãªã㣠ãªãµãŒã ã»ã³ã¿ãŒã¯ããªãŒãã³ãœãŒã¹ã® Node.js ãããã¬ã¹ CMS Strapi ã« 2 ã€ã®é倧㪠JSON è匱æ§ãç¹å®ããŸããããããã¯ãããŒã¿ã®çé£ã管çããã« ãŠãŒã¶ãŒã®ã¢ã«ãŠã³ã䟵害ã«ã€ãªããå¯èœæ§ããããŸãã

ã·ããã·ã¹ ãµã€ããŒã»ãã¥ãªã㣠ãªãµãŒã ã»ã³ã¿ãŒã¯æè¿ããªãŒãã³ãœãŒã¹ã® Node.js ãããã¬ã¹ ã³ã³ãã³ã管çã·ã¹ãã (CMS) Strapiã§ããŒã¿ ã»ãã¥ãªãã£ãšãŠãŒã¶ãŒ ãã©ã€ãã·ãŒã«é倧ãªãªã¹ã¯ããããããJSON ã« 2 ã€ã®é倧ãªè匱æ§ãçºèŠããŸããã
ãããã®è匱æ§ã¯ãCVE-2022-30617 ããã³ CVE-2022-30618 ãšããŠæå®ãããŠãããæ©å¯ããŒã¿æŒããã®ãªã¹ã¯ãšããŠåé¡ãããŠããŸãããããã¯ã Strapiã®ç®¡çããã«ã§ã¢ã«ãŠã³ã䟵害ã«ã€ãªããå¯èœæ§ããããŸãã Strapi ãJavaScript ã§éçºãããåºã䜿çšãããŠãããªãŒãã³ãœãŒã¹ã®ãããã¬ã¹ CMS ãœãããŠã§ã¢ã§ããããŠãŒã¶ãŒã¯ã¢ããªã±ãŒã·ã§ã³ ããã°ã©ãã³ã° ã€ã³ã¿ãŒãã§ã€ã¹ (API) ããã°ããèšèšããã³æ§ç¯ã§ããŸãããã®ç®¡çããã«ã¯ããŠãŒã¶ãŒãã³ã³ãã³ã ã¿ã€ãã管çããAPI ãå®çŸ©ã§ãã Web ããŒã¹ã®ãŠãŒã¶ãŒ ã€ã³ã¿ãŒãã§ã€ã¹ã§ãã
圱é¿ãåããããŒãžã§ã³ã«ã¯ãv3.6.9 ãŸã§ã®Strapi v3 ããã³ v4.0.0-beta.15 ãŸã§ã®Strapi v4 ããŒã¿çãå«ãŸããŸãã CVE-2022-30617 ã¯ã管çããã« ãŠãŒã¶ãŒã䜿çšããå ŽåãJSON å¿çã§æ©å¯ããŒã¿ãå ¬éããŸãããCVE-2022-30618 ã¯åæ§ã«åäœããŸãã
ç ç©¶è ã¯ãæåã®è匱æ§ã«ããã Strapi管çããã«ãžã®ã¢ã¯ã»ã¹æš©ãååŸããèªèšŒæžã¿ãŠãŒã¶ãŒãããã©ã€ããŒã ããŒã¿ãæ©å¯ããŒã¿ã衚瀺ã§ããããã«ãªãããšã詳ãã説æããŸãããããã«ã¯ãé»åã¡ãŒã« ã¢ãã¬ã¹ããã¹ã¯ãŒã ãªã»ãã ããŒã¯ã³ãããã³èªèšŒããããŠãŒã¶ãŒãã¢ã¯ã»ã¹ã§ããã³ã³ãã³ããšé¢ä¿ã®ããä»ã®ç®¡çããã« ãŠãŒã¶ãŒã«é¢ããããŒã¿ãå«ãŸããŸããçŽæ¥çãŸãã¯éæ¥çãªé¢ä¿ãéããŠãJSON å¿çã§ä»ã®ãŠãŒã¶ãŒããã®è©³çŽ°ãæŒæŽ©ããå¯èœæ§ãããããŸããŸãªã·ããªãªãçºçããå¯èœæ§ããããŸãã
2 çªç®ã®è匱æ§ã«ããã Strapi管çããã«ãžã®ã¢ã¯ã»ã¹æš©ãæã€èªèšŒæžã¿ãŠãŒã¶ãŒããAPI ãŠãŒã¶ãŒã«é¢é£ãããã©ã€ããŒã ããŒã¿ãæ©å¯ããŒã¿ã衚瀺ã§ããããã«ãªããŸããããã¯ãèªèšŒããããŠãŒã¶ãŒãã¢ã¯ã»ã¹ã§ããã³ã³ãã³ã ã¿ã€ãã« API ãŠãŒã¶ãŒãšã®é¢ä¿ãå«ãŸããŠããå Žåã«çºçããå¯èœæ§ããããŸããæ¥µç«¯ãªå Žåãæš©éã®äœããŠãŒã¶ãŒãæš©éã®é«ã API ã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ã§ããããã«ãªããä»ã®ãã¹ãŠã®ãŠãŒã¶ãŒã®æš©éãåãæ¶ãããšã§ãããŒã¿ã®èªã¿åããšå€æŽãå¯èœã«ãªãã管çããã«ãš API ã®äž¡æ¹ãžã®ã¢ã¯ã»ã¹ããããã¯ãããŸãã
Synopsys 㯠11 æã«ãããã®è匱æ§ã«ã€ããŠæåã«Strapiã«éç¥ãããã®åŸã®ãªãªãŒã¹ã§ã¯ãã§ã«ãã®åé¡ã«å¯ŸåŠããŠããŸãããã ãããã¹ãŠã®ãŠãŒã¶ãŒããœãããŠã§ã¢ãããã«æŽæ°ããããã§ã¯ãªãããããã®ãªã¹ã¯ã«ãããããå¯èœæ§ãããããšã«æ³šæããããšãéèŠã§ãããããã®è匱æ§ã®æªçšãé²ãããã«ãã¿ã€ã ãªãŒãªãœãããŠã§ã¢æŽæ°ã«éç¹ã眮ãå¿ èŠããããŸãã
æè¿ã§ã¯ã no-codeããã³low-codeãã©ãããã©ãŒã ã®äººæ°ãé«ãŸã£ãŠããããããœãããŠã§ã¢éçºè ãšãŠãŒã¶ãŒã¯ãæœåšçãªã»ãã¥ãªãã£ã®åé¡ã«ã€ããŠèŠæããããšãäžå¯æ¬ ã§ãã匷åãªno-codeãã©ãããã©ãŒã ã§ãã AppMaster ãã¹ã±ãŒã©ããªãã£ãšããã©ãŒãã³ã¹ã«éç¹ã眮ããŠãå®å šãªããã¯ãšã³ããWebãããã³ã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ã確å®ã«çæããŸãã AppMaster ã®ãã¯ãããžã¯ãã»ãã¥ãªãã£ã®è匱æ§ã®ãªã¹ã¯ãå€§å¹ ã«è»œæžããäžå°äŒæ¥ããå€§äŒæ¥ãŸã§ãå¹ åºã顧客ã«ãšã£ãŠã¢ããªã±ãŒã·ã§ã³éçºãããè¿ éãã€è²»çšå¯Ÿå¹æã®é«ããã®ã«ããŸãã


