
여러 장치에 F5의 공식 스크립트를 적용하여 CVE-2023-46747(BIG-IP 인증되지 않은 RCE) 완화를 자동화하는 Ansible 플레이북.
다음은 링크입니다 https://my.f5.com/manage/s/article/K000137353
ansible-playbook -i hosts.ini playbook.yaml
출력은 다음과 같습니다.
PLAY [Execute script on F5 BIG-IP] ****************************************************************************************************************
TASK [Copy the script to the BIG-IP] **************************************************************************************************************
changed: [172.16.10.31]
changed: [172.16.10.30]
TASK [Execute the script on the BIG-IP] ***********************************************************************************************************
changed: [172.16.10.30]
changed: [172.16.10.31]
TASK [Save script output messages] ****************************************************************************************************************
ok: [172.16.10.30]
ok: [172.16.10.31]
TASK [Aggregate script output messages on localhost] **********************************************************************************************
ok: [172.16.10.30 -> localhost] => (item=Applying ID1378329 mitigation...)
ok: [172.16.10.30 -> localhost] => (item=Restarting httpd...)
ok: [172.16.10.31 -> localhost] => (item=Applying ID1378329 mitigation...)
)k: [172.16.10.30 -> localhost] => (item=Stopping httpd: [ OK ]
ok: [172.16.10.31 -> localhost] => (item=Restarting httpd...)
)k: [172.16.10.30 -> localhost] => (item=Starting httpd: [ OK ]
)k: [172.16.10.31 -> localhost] => (item=Stopping httpd: [ OK ]
)k: [172.16.10.31 -> localhost] => (item=Starting httpd: [ OK ]
ok: [172.16.10.30 -> localhost] => (item=Restarting tomcat...)
ok: [172.16.10.30 -> localhost] => (item=Done!)
ok: [172.16.10.31 -> localhost] => (item=Restarting tomcat...)
ok: [172.16.10.31 -> localhost] => (item=Done!)