ãã®è¨äºã¯ç¾
éç¤ ã¢ããã³ãã«ã¬ã³ãã¼ 2024ã®20æ¥ç®ã®è¨äºã§ãã
qiita.com
19æ¥ç®ã®è¨äºã¯ ... ã§ããã
ä»åã®è¨äºã¯ã²ã¹ãã®æ¹ã®å¯ç¨¿è¨äºã¨ãªãã¾ããã¾ãããããªã¼ã¹ã¿ã¤ã«è¦é¢å¥³åã¬ã¹ã©ã¼ã®æ¹ããã®ãããããå¯ç¨¿ã§ãã
ã¯ããã«
ä¸ã¯ã¾ãã«å¤§LLMæ代ã§ããã
2024å¹´ã«å ¥ããLLMï¼å¤§è¦æ¨¡è¨èªã¢ãã«ï¼ã®æ®åãããã«é²ã¿ãã¨ã³ã·ã¹ãã ãæ¡å¤§ãå¤ãã®ä¼æ¥ã§æ´»ç¨ãä¸è¬åãã¦ããå°è±¡ãããã¾ãã
LLMã®ã»ãã¥ãªãã£ã«é¢ããã¬ã¤ãã³ã¹ã¨ãã¦OWASP LLM Top 10ãæåã§ããç¹ã«ããã³ããã¤ã³ã¸ã§ã¯ã·ã§ã³ã®ãããªè©±é¡ã¯ãè³ã«ããæ©ä¼ãå¢ããã®ã§ã¯ãªãã§ãããããã¾ããLLMãæ´»ç¨ããã»ãã¥ãªãã£ã®ã¦ã¼ã¹ã±ã¼ã¹ã¨ãã¦ãèå¼±æ§ã®èªåçºè¦ããã°ã»ã¢ã©ã¼ãã®ããªã¢ã¼ã¸ãªã©ã注ç®ããã¦ããã¨æãã¾ãã
ä¸æ¹ã§ãLLMç¹æã®èª²é¡ã«å ãã¦ãå¾æ¥ã®ã»ãã¥ãªãã£ãªã¹ã¯ãå¼ãç¶ãéè¦ãªãã¤ã³ãã«ãªãããã§ããä»å¹´ãç¹ã«å°è±¡çã ã£ãã®ã¯ãLLMéçºãæ¯ãããã¼ã«ãã¨ã³ã·ã¹ãã ã«ããããLLMèªä½ã¯ããã¾ã§é¢ä¿ã®ãªãããããããå¾æ¥åãã®èå¼±æ§ã§ããå¤ãã®OSSãã¼ã«ãç®ã¾ããããç»å ´ãããªãã§ããããã®ãã¼ã«ã«ãããæ·±å»ãªèå¼±æ§ãã¡ãã»ãè¦ãããå°è±¡ã§ãã
æ¬è¨äºã§ã¯ãã®è»¸ã§å人çã«é¢ç½ãã£ãèå¼±æ§3ã¤ããç´¹ä»ãã¾ããã¾ããè¨äºã®æå¾ã«ã¯ã©ã®ãããªå¯¾çããã¹ãããèãã¦ã¿ã¾ãã
LLMã®ã¨ã³ã·ã¹ãã ã§å人çã«æ³¨ç®ããèå¼±æ§3é¸
CVE-2024-37032 Ollamaã®digestã®æ¤è¨¼ä¸åã«ããRCE (Probllama)
LLMã¢ãã«ãèªåã§ãã¹ãã£ã³ã°ããéã«å©ç¨ãããOllamaã®èå¼±æ§ã§ãã
Ollama APIãµã¼ãã®ã¢ãã«ããã«ããAPIã§ã¯ããã©ã¤ãã¼ãã¬ã¸ã¹ããªããã¢ãã«(ã³ã³ããã¤ã¡ã¼ã¸)ãèªã¿è¾¼ããããã«ãªã£ã¦ãã¾ãã
æ¬æ¥ãã³ã³ããã¤ã¡ã¼ã¸ã®ããã·ã¥ã¨ãã¤ã¸ã§ã¹ãå¤ã¯ä¸è´ããã¯ãã§ããããã¤ã¸ã§ã¹ãå¤ããã¹ãã©ãã¼ãµã«ã®ãã¤ãã¼ãã«æ¸ãæãããã®ãèªã¿è¾¼ã¾ãããã¨ãã§ã(ä¿®æ£å)ãã¾ããã¤ã¸ã§ã¹ãå¤ã¯ã¢ãã«ãã¡ã¤ã«ããã£ã¹ã¯ã«ä¿åããããã«ã使ããããããä»»æã®ãã¡ã¤ã«ãç ´æããããã¨ãã§ããããã§ãã
ãã®åé¡ãèµ·ç¹ã«ãã¦ãä»»æã®ãã¡ã¤ã«èªã¿è¾¼ã¿ãããã«ä»»æã³ã¼ãå®è¡ã¾ã§å°éã§ãããã®ã§ããã
- Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) â Overview and Mitigations
- validate the format of the digest when getting the model path
CVE-2024-31621 Flowiseã®èªè¨¼ããã«ã¦ã§ã¢ã®ãã¹æ¤è¨¼ä¸åã«ããèªè¨¼åé¿
ãã¼ã³ã¼ãLLMã¢ããªãã«ãã¼ã®Flowiseã®èå¼±æ§ã§ãã
Flowiseããã¹ãã£ã³ã°ããéãusername/passwordã«ããã¢ããªã¬ãã«èªè¨¼ãããããã¨ãå¯è½ã§ãããAPIã®èªè¨¼ããã«ã¦ã§ã¢ã®ãã¹æ¤è¨¼ãã¸ãã¯ãä¸ååãªããã/api/v1/credentials
ãªã©ã®APIãèªè¨¼ãªãã§å©ããã¨ãã§ãã¾ããã
PoCãã·ã³ãã«ã«ä¸è¡ãªã®ãã¡ãã£ã¨é¢ç½ãã§ããã
ããã«Flowiseã«ã¯å¥ã®CVE-2024-36420ã¨ããä»»æãã¡ã¤ã«èªã¿è¾¼ã¿å¯è½ãªèå¼±æ§ãããããã§ããã¡ãã¨åãããã¨ãµã¼ãä¸ã®ä»»æã®ãã¡ã¤ã«ãæªèªè¨¼ã§èªã¿åãå¯è½ããããã¾ããã
CVE-2024-0440, CVE-2024-0455 AnythingLLMã®SSRF
ãã©ã¤ãã¼ããªChatGPT(ã£ã½ãã·ã¹ãã )ãæ§ç¯ã§ããAnythingLLMã®èå¼±æ§ã§ãã
Webã¹ã¯ã¬ã¤ãã¼æ©è½ãã¤ã³ã¹ã¿ã³ã¹å
ãããªã¯ã¨ã¹ããéãä»æ§ã¨ãªã£ã¦ãããCVE-2024-0440 ã§ã¯ file://
ã¹ãã¼ã ã使ã£ã¦ãµã¼ãã¼ä¸ã®ä»»æã®ãã¡ã¤ã« (/etc/passwd
ãªã©) ãèªã¿è¾¼ããã¨ãã§ãã¾ããã
- SSRF - reading local files, env secrets, AWS metadata endpoint in mintplex-labs/anything-llm
- Strict link protocol validation
ã¾ããCVE-2024-0455 ã§ã¯ãAWSã®ã¡ã¿ãã¼ã¿ã¨ã³ããã¤ã³ããå¼ã³åºããã¨ãã§ãããããã¤ã³ã¹ã¿ã³ã¹ã«ä»ä¸ããã権éã®IAMã¯ã¬ãã³ã·ã£ã«ãçããã¨ãã§ãã¾ããã
- protect AWS CF deployments by automatically blocking metadata URL
- The inclusion of the web scraper for AnythingLLM means...
ãã ããWebã¹ã¯ã¬ã¤ãã¼æ©è½ããããã®ã«ä¸å®ä»¥ä¸ã®æ¨©éãå¿ è¦ã¨ããæ¡ä»¶ã¯ããããã§ãã
ææã¨ãã¦ãLLMã«ã¹ã¯ã¬ã¤ãã³ã°çµæãèªã¿è¾¼ã¾ãããã¨ããã®ã¯ä¸è¬çãªæ¬²æ±ã ã¨æãã®ã§ãããç³»ã®è©±ã¯ä»ã®ãã¼ã«ã§ãå¤ãåºã¦ããæ°ããã¦ãã¾ãã
ã©ãå®ã£ã¦ãããï¼
以ä¸ã§ã¯ãããã£ãèå¼±æ§ã®ãªã¹ã¯ãæå°åããããã«ã©ã®ãããªæ段ãåãããï¼ãèãã¦ããã¾ãã(ãã¼ã«ã®éçºè ã¨ãããããããã¼ã«ãæå±ä¼ç¤¾ã§ã®å©ç¨åãã«ãã¹ãã£ã³ã°ãå§ããæ¹ãªã©ãæ³å®ãã¦ã¾ãã)
ãããããã¸ã¡ã³ãã¯LLMé¢ä¿ã®ã·ã¹ãã ã§ãå¼ãç¶ã大äº
LLMé¢ä¿ãªããä¼ç¤¾ã§å©ç¨ããã·ã¹ãã ã®ããããé 延ãªãå½ã¦ãã®ã¯å¤§åæã«ãªã£ã¦ãã¾ãããªãã®ãã¼ã«ãã©ãã«ãã¹ããã¦ãããã¨ãã£ãæ å ±ãæ´çã»ææ¡ãã¦ãèå¼±æ§ã¨ãããæ å ±ã確èªãã¦éããã«åæ ã§ããä½å¶ãã¤ããã¾ãããã
(ãã ããããããããããããªãã¨ãã£ããã¿ã¼ã³ãããã®ã§ããããã ããã¦ãã¦ãååã§ã¯ããã¾ãããä¾ã¨ãã¦ãCVE-2024-31621ã¯4/29ã«å ¬éãããã®ã¡ãä¿®æ£ãã¼ã¸ã§ã³ã®2.0.6ããªãªã¼ã¹ãããã®ã¯8/28ã ã£ãããã§ãã)
OSSãã¼ã«ã®ã¿ã§ãã¹ãã£ã³ã°ããã追å ã®èªè¨¼ãé²å¾¡ãè¡ã
ããããæ¥ãã¾ã§ã®æéãä¸¸è °ã§éããã®ã¯æããããã¢ã¯ã»ã¹ã§ããé¢ãããããçãã¦ãããã¨ãã£ã工夫ã¯å¿ ãè¡ãããã§ããç¡é²åã«ã¤ã³ã¿ã¼ãããã«å ¬éããã¦ãã¾ã£ã¦ããã¨ãã©ãããããã¡ã¤ã³ãçºè¦ããã¦ã¢ã¯ã»ã¹ãããããè¨å®ããã¼ã«ã«ãã£ã¦ã¯Googleã«ã¤ã³ããã¯ã¹ããã¦ãã¾ãã¨ãã£ããã¨ããããã¾ãã
ãããã£ããã¼ã«ã¯çµã¿è¾¼ã¿ã®èªè¨¼æ©è½ãåå¨ããªããã®ãå¤ãããã£ãã¨ãã¦ãååã§ãªã(ID/PWã®ã¿)ãã¾ãã¯èªè¨¼æ©è½ãã®ãã®ãèå¼±ã§ããå¯è½æ§ãèãã¦ããã追å ã®å±¤ãè¨ãããã¨ãæ¨å¥¨ããã¾ãã
AWS ALBã§ããã°Cognitoãä»»æã®OIDCæºæ ã®IdPã¨é£æºãããã¨ãã§ããããGCPã§ããã°Identity-Aware-Proxyãç¨ããã®ãããã§ãããã(ãããã使ããªãå ´åã§ããIPå¶éããããããã¯ãã¦ããã¨ã¯ããã«ãã·ã«ãªãã¾ã)
(ä½è£ãããã°)ã¢ã¯ã»ã¹ã許å¯ãããå é¨ããã®æ»æã®ãªã¹ã¯ãèãã¦ãã
åã®é ç®ã§å¤é¨ããã®è å¨ã¯ã ãã¶èããªãã¦è¯ããªããã®ã®ãå é¨ã§ã¢ã¯ã»ã¹æ¨©ãæã£ã¦ãã人ãæªæãæã¤å ´å(ãããã¯ãã®äººã®ç«¯æ«ã侵害ããããæ»æè ã)ãããã£ãèå¼±æ§ãããããããã¾ã§ã¯å©ç¨ã§ãã¦ãã¾ããããå é¨è ãã©ãã¾ã§ã®ç¯å²ã¨æãã¦æä¾ãã¦ãããããèæ ®ã®ãã¤ã³ãã¨ãªãããããã¾ããã
æ°åãè¦æ¨¡ã®ä¼ç¤¾ã§ã¯ãã¾ãæ°ã«ãããã¤ã³ãã§ã¯ãªãããããã¾ãããã大ããã®ä¼ç¤¾ã§åä¼ç¤¾ã»ååä¼ç¤¾ã«å ¬éããå ´åã®ç¯å²ã¯èæ ®ã®å¿ è¦ãããããããã¾ããããToBã§é¡§å®¢ã®ä¼æ¥ã«ãã®ã¾ã¾å©ç¨ãããã¨ãã£ã使ãæ¹ãããããå ´åã«ã¯ãã¤ã³ãã©ã®åé¢åº¦ã®è¨è¨ãªã©ã¯ããã·ãã¢ã«èæ ®ããã»ããããããã§ãã
ã¾ã¨ã
2024å¹´ãå人çã«æ°ã«ãªã£ãLLMã¨ã³ã·ã¹ãã ã®èå¼±æ§ãç´¹ä»ããã©ããªã¹ã¯ä½æ¸ããããèãã¦ã¿ã¾ããããããã ã£ãã§ãããããå¾æ¥çãªã»ãã¥ãªãã£ã®è¦ç¹ãå¿ããã«ãLLMæ´»ç¨ã楽ããã§ããã¾ãããï¼ï¼