Apache Dubbo 6Ô¶à¸ö¸ßΣ©¶´
Ðû²¼Ê±¼ä 2021-06-240x00 ©¶´¸ÅÊö
Apache DubboÊÇÒ»¿îÓ¦Óù㷺µÄJava RPCÂþÑÜʽ·þÎñ¿ò¼Ü¡£
2021Äê06ÔÂ22ÈÕ£¬Github SecurityLab¹ûÈ»Åû¶ÁËApache DubboÖеĶà¸ö¸ßΣ©¶´£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ô¶³ÌÖ´ÐдúÂë¡£
0x01 ©¶´ÏêÇé
Ñо¿ÈËÔ±¹ûÈ»Åû¶µÄÊ®¸öÎÊÌâ±»·ÖÅäÈçÏÂCVE ID£ºCVE-2021-25641¡¢ CVE-2021-30179¡¢CVE-2021-32824¡¢CVE-2021-30180ºÍCVE-2021-30181£¬ÆäÏêÇéÈçÏ£º
Apache Dubbo Hessian2·´ÐòÁл¯Â©¶´£¨CVE-2021-25641£©
¹¥»÷Õß¿ÉÒÔÀûÓÃÆäËüÐÒéÈÆ¹ý Hessian2 ºÚÃûµ¥Ôì³É·´ÐòÁл¯Â©¶´¡£
Apache Dubbo Generic filterÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-30179£©
ÓÉÓÚApache Dubbo Generic filter¹ýÂ˲»ÑÏ£¬¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇóµ÷ÓöñÒâÒªÁì´Ó¶øÔì³ÉÈÎÒâ´úÂëÖ´ÐС£´Ë©¶´Éæ¼°Generic filter Java ·´ÐòÁл¯£¨GHSL-2021-037£©ºÍ µ¼ÖÂRCEµÄJNDI ²éÕÒµ÷ÓÃ(GHSL-2021-038)¡£
Apache Dubbo Telnet handlerÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-32824£©
Telnet handlerÌṩһЩ»ù±¾µÄÒªÁìÀ´ÊÕ¼¯ÓйطþÎñ¹ûÈ»µÄÌṩÕߺÍÒªÁìµÄÐÅÏ¢£¬ÉõÖÁ¿ÉÒÔÔÊÐí¹Ø±Õ·þÎñ¡£Apache Dubbo Telnet handlerÔÚ´¦ÖÃÏà¹ØÇëÇóʱ£¬¹¥»÷Õß¿ÉÒÔͨ¹ýµ÷ÓöñÒâÒªÁìÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£
Apache Dubbo yaml·´ÐòÁл¯Â©¶´£¨CVE-2021-30180£©
Apache DubboʹÓÃÁËyaml.load´ÓÍⲿ¼ÓÔØÊý¾ÝÄÚÈݼ°ÅäÖÃÎļþ£¬¹¥»÷ÕßÔÚ¿ØÖÆÅäÖÃÖÐÐÄ£¨ÈçZookeeper¡¢Nacos µÈ£©ºó¿ÉÉÏ´«¶ñÒâÅäÖÃÎļþ£¬´Ó¶øÔì³ÉYaml·´ÐòÁл¯Â©¶´¡£´Ë©¶´Éæ¼°±êǩ·ÓÉÖж¾(GHSL-2021-040)¡¢Ìõ¼þ·ÓÉÖж¾£¨GHSL-2021-041£©ºÍÅäÖÃÖж¾£¨GHSL-2021-043£©¡£
Apache Dubbo Nashorn ½Å±¾Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-30181£©
¹¥»÷ÕßÔÚ¿ØÖÆÅäÖÃÖÐÐÄ£¨ÈçZookeeper¡¢Nacos µÈ£©ºó¿É½á¹¹¶ñÒâÇëÇó×¢ÈëNashorn½Å±¾£¨½Å±¾Â·ÓÉÖж¾£¬GHSL-2021-042£©£¬Ôì³ÉÈÎÒâ´úÂëÖ´ÐС£
Ó°Ï췶Χ
Apache Dubbo < 2.7.10
Apache Dubbo < 2.6.10
0x02 ´¦Öý¨Òé
ĿǰÕâЩ©¶´ÒѾÐÞ¸´£¬½¨Ò鼰ʱÉý¼¶¸üÐÂÖÁÒÔÏ»ò¸ü¸ß°æ±¾£º
Apache Dubbo 2.7.10
Apache Dubbo 2.6.10
0x03 ²Î¿¼Á´½Ó
https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25641
0x04 ʱ¼äÏß
2021-06-22 ©¶´Åû¶
2021-06-24 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/