¡¾Â©¶´Í¨¸æ¡¿Apache DubboÔ¶³Ì´úÂëÖ´ÐЩ¶´ (CVE-2021-36162)

Ðû²¼Ê±¼ä 2021-08-31


0x00 ©¶´¸ÅÊö

CVE     ID

CVE-2021-36162

ʱ      ¼ä

2021-08-30

Àà      ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

image.png

 

Apache DubboÊÇÒ»¿îÓ¦Óù㷺µÄJava RPCÂþÑÜʽ·þÎñ¿ò¼Ü¡£

2021Äê8ÔÂ30ÈÕ£¬Github SecurityLab¹ûÈ»Åû¶ÁËApache DubboÖеĶà¸ö¸ßΣ©¶´£¨CVE-2021-36162ºÍCVE-2021-36163£©£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

Apache Dubbo YAML ·´ÐòÁл¯Â©¶´£¨CVE-2021-36162£©

Apache DubboÖдæÔÚYAML ·´ÐòÁл¯Â©¶´£¬¿ÉÒÔ·ÃÎÊÅäÖÃÖÐÐĵĹ¥»÷Õß¿ÉÒÔÀûÓôË©¶´Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

 

Apache DubboÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-36163£©

Apache DubboʹÓÃÁ˲»Äþ¾²µÄHessian ЭÒ飨¿ÉÑ¡£©£¬µ¼Ö²»Äþ¾²µÄ·´ÐòÁл¯£¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

´ËÍ⣬SecurityLab»¹¹ûÈ»ÁËApache DubboÖеÄÁíÒ»¸öRCE©¶´£¨GHSL-2021-096£¬¾Ü¾øÐÞ¸´£©£¬ÓÉÓÚApache DubboʹÓÃÁ˲»Äþ¾²µÄ RMI ЭÒ飬µ¼Ö²»Äþ¾²µÄ·´ÐòÁл¯£¬¹¥»÷ÕßÄܹ»·¢ËÍÈÎÒâÀàÐ͵IJÎÊý²¢Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

 

Ó°Ï췶Χ

Apache Dubbo v2.7.10

 

0x02 ´¦Öý¨Òé

Ä¿Ç°CVE-2021-36162ºÍCVE-2021-36163ÒѾ­ÐÞ¸´£¬½¨Ò鼰ʱӦÓÃÄþ¾²²¹¶¡¡£µ«GHSL-2021-096ÎÊÌâ¾Ü¾øÐÞ¸´£¬½¨ÒéÓû§ÆôÓà JEP 290»úÖÆ¡£

CVE-2021-36162²¹¶¡Á´½Ó£º

https://github.com/apache/dubbo/pull/8350

 

CVE-2021-36163²¹¶¡Á´½Ó£º

https://github.com/apache/dubbo/pull/8238

 

0x03 ²Î¿¼Á´½Ó

https://securitylab.github.com/advisories/GHSL-2021-094-096-apache-dubbo/

https://dubbo.apache.org/en/downloads/

http://openjdk.java.net/jeps/290

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36162

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-08-31

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¶«É­Æ½Ì¨

¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png