[Git] Security Vulnerabilities (๋ณด์•ˆ ๋ฌธ์ œ ํ•ด๊ฒฐ)

2021. 5. 12. 11:46ยท๊ธฐํƒ€/git

 

๐ŸŽฏ Goal

  • ํ”„๋กœ์ ํŠธ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์— ์กด์žฌํ•˜๋Š” ๋ณด์•ˆ ์ทจ์•ฝ์„ฑ์„ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค.
  • npm์˜ ๋ชจ๋“  ํŒจํ‚ค์ง€๋ฅผ ๊ฐ„๋‹จํ•˜๊ฒŒ ์ตœ์‹ ํ™”ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•ˆ๋‹ค.

 

โš ๏ธ ๋ฌธ์ œ ์ƒํ™ฉ

github๋กœ ๋ถ€ํ„ฐ ์ž๊พธ gmail ๋กœ ๋ฉ”์ผ์ด ๋‚ ์•„์™”๋‹ค.

6๊ฐœ์›” ์ „์— ๋ฐฐํฌํ•ด๋†“์€ ํ”„๋กœ์ ํŠธ์— ๋Œ€ํ•ด ๊ฒฝ๊ณ  ์•Œ๋ฆผ์„ ๋ณด๋‚ด์™”๋Š”๋ฐ

"์—์ด ๋ญ ๋ฌธ์ œ์žˆ๊ฒ ์–ด?" ํ•˜๋‹ค๊ฐ€ ์ž๊พธ ์•Œ๋ฆผ์˜ค๋Š”๊ฒŒ ์งœ์ฆ๋‚˜์„œ๋ผ๋„ ๋Œ€์ฒด ๋ญ”๊ฐ€? ํ•˜๊ณ  ์‚ดํŽด๋ดค๋‹ค.

 

Dependabot ์ด๋ผ๊ณ  ํ•˜๋Š” git ์˜ ์˜คํ† ๋ด‡์ด CVE์— ๋“ฑ๋ก๋œ ์ทจ์•ฝ์ ์ด ์กด์žฌํ•˜๋Š” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋ฒ„์ „์„ ์‚ฌ์šฉ์ค‘์ธ์ง€ ์ž๋™ ํƒ์ƒ‰ํ•˜๊ณ , ์ทจ์•ฝ์  ๋ฐœ๊ฒฌ์‹œ ํ•ด๋‹น ๋ฆฌํฌ์ง€ํ† ๋ฆฌ ์‚ฌ์šฉ์ž์—๊ฒŒ ์•Œ๋ฆผ ๋ฉ”์ผ์„ ๋ณด๋‚ธ๋‹ค.

lodash ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๊ตฌ๋ฒ„์ „์—์„œ Command injection ์ทจ์•ฝ์ ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ๋‹ค.

 


๋ฌธ์ œ์™€ ํ•ด๊ฒฐ๋ฐฉ์•ˆ์„ ํ•œ์ค„๋กœ ์ •์˜ํ•ด๋ณด๊ฒ ๋‹ค.

"๋„ค๊ฐ€ ์“ฐ๊ณ  ์žˆ๋Š” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๊ตฌ๋ฒ„์ „์—์„œ ์ทจ์•ฝ์ ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ์œผ๋‹ˆ, ์ตœ์‹ ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธํ•ด!"

CVE (Common Vulnerabilities and Exposures) 

๊ณต๊ฐœ์ ์œผ๋กœ ์•Œ๋ ค์ง„ ๋ณด์•ˆ ์ทจ์•ฝ์„ฑ

๊ธฐ์—…๊ณผ ๊ธฐ๊ด€์ด ๋ณด์•ˆ ๊ฐ•ํ™”์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๋ฌด๋ฃŒ ์ฝ”๋“œ๋ฅผ ๋งŒ๋“ค๊ธฐ ์œ„ํ•ด ์‹œ์ž‘ํ•œ ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ 

ํ•ด์ปค๊ฐ€ ์•…์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์— ๋Œ€ํ•ด ๋ฌด๋ฃŒ ๊ณต๊ฐœํ•œ๋‹ค.

 

๐Ÿ”— CVE๋ž€??

 

 


๐Ÿ’Š ํ•ด๊ฒฐ ๋ฐฉ์•ˆ

node.js + npm ๊ธฐ๋ฐ˜์˜ ๋ฐฑ์—”๋“œ ํ”„๋กœ์ ํŠธ, '๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ(ํŒจํ‚ค์ง€) ์ตœ์‹ ํ™”' ๊ฐ„๋‹จํ•˜๊ฒŒ ํ•  ์ˆ˜ ์—†์„๊นŒ?

๋ฌผ๋ก  `npm update` ๋ช…๋ น์–ด๋ฅผ ์“ธ ์ˆ˜๋„ ์žˆ๊ฒ ์ง€๋งŒ ์ˆ˜๋งŽ์€ ํŒจํ‚ค์ง€๋ฅผ ํ•˜๋‚˜ํ•˜๋‚˜ ์ž…๋ ฅํ•˜๊ธฐ ๊ท€์ฐฎ์ง€ ์•Š์€๊ฐ€?

๋ˆ„๊ตฐ๊ฐ€ ๊ฐœ๋ฐœ์ž์˜ ์„ฑ์žฅ์€ ๊ฒŒ์œผ๋ฆ„->๊ท€์ฐจ๋‹ˆ์ฆ˜ ํ•ด๊ฒฐ์ด๋ผ๊ณ ํ–ˆ๋‹ค.

 

ํ˜น์‹œ ๋ˆ„๊ตฐ๊ฐ€ ์ด ๊ท€์ฐจ๋‹ˆ์ฆ˜์„ ํ•ด๊ฒฐํ•  ํˆด์„ ๋งŒ๋“ค์–ด ๋†“์ง€ ์•Š์•˜์„๊นŒ?

 

github.com/raineorshine/npm-check-updates

 

raineorshine/npm-check-updates

Find newer versions of package dependencies than what your package.json allows - raineorshine/npm-check-updates

github.com

์—ญ์‹œ๋‚˜~ 

npm-check-updates

`package.json` ์— ๋“ฑ๋ก๋œ dependencies ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋“ค์˜ ์ตœ์‹ ๋ฒ„์ „์ด ์กด์žฌํ•˜๋Š”์ง€ ๋ช…๋ น์–ด ํ•œ์ค„๋กœ ์ฒดํฌํ•˜๊ณ , ์ž๋™ ์—…๋ฐ์ดํŠธ๊นŒ์ง€ ํ•ด์ฃผ๋Š” ๊ณ ๋งˆ์šด ํˆด์ด๋‹ค.

์„ค์น˜ํ›„ ๋‹ค์Œ ๋ช…๋ น์–ด ํ•œ์ค„์ด๋ฉด ๋œ๋‹ค.

ncu -u

 


๐Ÿ“ ์กฐ์น˜ ๊ฒฐ๊ณผ

package.json update ๊ฒฐ๊ณผ


๐Ÿ”ง lodash ๋ฅผ ํฌํ•จํ•œ ๋ชจ๋“  ํŒจํ‚ค์ง€๊ฐ€ ์ตœ์‹ ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธ ๋˜์—ˆ๊ณ , ๋” ์ด์ƒ ๋ณด์•ˆ ์•Œ๋ฆผ์ด ๋œจ์ง€ ์•Š์•˜๋‹ค.


 

 

์ €์ž‘์žํ‘œ์‹œ (์ƒˆ์ฐฝ์—ด๋ฆผ)

'๊ธฐํƒ€ > git' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[git] Rebase vs Merge request, Pull request  (0) 2021.12.28
[Git] config  (0) 2021.11.11
[Git] branch  (0) 2021.03.29
gitlab Setting (gitlab ์‹œ์ž‘ํ•˜๊ธฐ, ์„ค์ •)  (0) 2020.01.13
error:src refspec master does not match any ํ•ด๊ฒฐ  (0) 2020.01.09
'๊ธฐํƒ€/git' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
  • [git] Rebase vs Merge request, Pull request
  • [Git] config
  • [Git] branch
  • gitlab Setting (gitlab ์‹œ์ž‘ํ•˜๊ธฐ, ์„ค์ •)
M_Falcon
M_Falcon
  • M_Falcon
    Falcon
    M_Falcon
  • ์ „์ฒด
    ์˜ค๋Š˜
    ์–ด์ œ
    • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (432)
      • Web (16)
        • Nodejs (14)
        • Javascript (23)
        • FrontEnd (4)
      • DataBase (39)
        • Fundamental (1)
        • Redis (4)
        • PostgreSQL (10)
        • NoSQL (4)
        • MySQL (9)
        • MSSQL (3)
        • Error (4)
      • Algorithm (79)
        • Algorithm (๋ฌธ์ œํ’€์ด) (56)
        • Algorithm (์ด๋ก ) (23)
      • JVM (65)
        • Spring (13)
        • JPA (5)
        • Kotlin (13)
        • Java (24)
        • Error (7)
      • ๊ธฐํƒ€ (70)
        • Kafka (3)
        • Kubernetes (3)
        • Docker (13)
        • git (19)
        • ์žก๋™์‚ฌ๋‹ˆ (27)
      • ์žฌํ…Œํฌ (11)
        • ์„ธ๋ฌด (4)
        • ํˆฌ์ž (3)
        • ๋ณดํ—˜ (0)
      • BlockChain (2)
        • BitCoin (0)
      • C (32)
        • C (10)
        • C++ (17)
        • Error (3)
      • Low Level (8)
        • OS (3)
        • ์‹œ์Šคํ…œ ๋ณด์•ˆ (5)
      • ๋„คํŠธ์›Œํฌ (3)
      • LINUX (30)
        • Linux (26)
        • Error (4)
      • ์ €์ž‘๊ถŒ๊ณผ ์Šค๋งˆํŠธํฐ์˜ ์ดํ•ด (0)
      • ์ƒ๊ฐ ๋ญ‰์น˜ (6)
      • ๊ถ๊ธˆ์ฆ (2)
      • Private (4)
        • ์ด์ง ๊ฒฝํ—˜ (0)
        • ๊ฟˆ์„ ์ฐพ์•„์„œ (1)
      • Android (21)
        • OS (4)
  • ๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

    • ํ™ˆ
    • WEB
    • ์•Œ๊ณ ๋ฆฌ์ฆ˜
    • DataBase
    • Linux
    • Mobile
    • C
    • ๋ฐฉ๋ช…๋ก
  • ๋งํฌ

    • github
  • ๊ณต์ง€์‚ฌํ•ญ

  • ์ธ๊ธฐ ๊ธ€

  • ํƒœ๊ทธ

    algorithm
    linux
    Kotlin
    javascript
    C++
    ubuntu
    kafka
    Bitcoin
    java
    database
    ์•Œ๊ณ ๋ฆฌ์ฆ˜
    android
    JPA
    PostgreSQL
    Spring
    ๋ฐฑ์ค€
    Programmers
    Git
    docker
    ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค
  • hELLOยท Designed By์ •์ƒ์šฐ.v4.10.3
M_Falcon
[Git] Security Vulnerabilities (๋ณด์•ˆ ๋ฌธ์ œ ํ•ด๊ฒฐ)
์ƒ๋‹จ์œผ๋กœ

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”