NginxÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-23017£©

Ðû²¼Ê±¼ä 2021-05-27

0x00 ©¶´¸ÅÊö

CVE  ID

CVE-2021-23017

ʱ    ¼ä

2021-05-27

Àà   ÐÍ

´úÂëÖ´ÐÐ

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ

Nginx 0.6.18 - 1.20.0

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

NginxÊÇÒ»¸ö¸ßÐÔÄܵÄHTTPºÍ·´ÏòÊðÀíweb·þÎñÆ÷ £¬Í¬Ê±Ò²ÌṩÁËIMAP/POP3/SMTP·þÎñ £¬ÓÉÓÚÆä¾ßÓÐÐí¶àÓÅÔ½µÄÌØÐÔ £¬µ¼ÖÂÔÚÈ«Çò·¶Î§ÄÚ±»¹ã·ºÊ¹Óá£

2021Äê05ÔÂ25ÈÕ £¬Nginx¹Ù·½Ðû²¼Äþ¾²Í¨¸æ £¬¹ûÈ»ÁËNginx DNS ResolverÖеÄÒ»¸öÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-23017£©¡£

ÓÉÓÚNginxÔÚ´¦ÖÃDNSÏìӦʱ´æÔÚÄþ¾²ÎÊÌâ £¬µ±ÔÚÅäÖÃÎļþÖÐʹÓà ¡°resolver ¡±Ö¸Áîʱ £¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýαÔìÀ´×ÔDNS·þÎñÆ÷µÄUDPÊý¾Ý°ü £¬½á¹¹DNSÏìÓ¦Ôì³É1-byteÄÚ´æÁýÕÖ £¬´Ó¶øµ¼Ö¾ܾø·þÎñ»òÈÎÒâ´úÂëÖ´ÐС£

¸Ã©¶´½öÔÚÅäÖÃÁËÒ»¸ö»ò¶à¸ö¡°resolver¡±Ö¸ÁîµÄÇé¿öÏ´æÔÚ £¬¶øÄ¬ÈÏÇé¿öÏÂûÓÐÅäÖá£

 

0x02 ´¦Öý¨Òé

Ŀǰ¸Ã©¶´ÒÑÔÚÒÔϰ汾ÖÐÐÞ¸´ £¬½¨Ò龡¿ì½øÐÐÉý¼¶¸üУº

NGINX Open Source 1.20.1 (stable)

NGINX Open Source 1.21.0 (mainline)

NGINX Plus R23 P1

NGINX Plus R24 P1

ÒÔϰ汾µÄNGINX Ingress Controller°üÂÞNGINX Open SourceºÍNGINX PlusµÄÐÞ¸´·¨Ê½°æ±¾£º

NGINX Ingress Controller 1.11.2 ¨C NGINX Plus R23 P1

NGINX Ingress Controller 1.11.3 ¨C NGINX Open Source 1.21.0 ºÍNGINX Plus R23 P1

 

ÏÂÔØÁ´½Ó£º

http://nginx.org/en/download.html

²¹¶¡Á´½Ó£º

http://nginx.org/download/patch.2021.resolver.txt

 

0x03 ²Î¿¼Á´½Ó

http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html

https://www.nginx.com/blog/updating-nginx-dns-resolver-vulnerability-cve-2021-23017/

https://support.f5.com/csp/article/K12331123

 

0x04 ʱ¼äÏß

2021-05-25  NginxÐû²¼Äþ¾²Í¨¸æ

2021-05-27  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png