¡¾Â©¶´Í¨¸æ¡¿Apache DubboÔ¶³Ì´úÂëÖ´ÐЩ¶´ (CVE-2021-36162)
Ðû²¼Ê±¼ä 2021-08-310x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-36162 | ʱ ¼ä | 2021-08-30 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà |
0x01 ©¶´ÏêÇé
Apache DubboÊÇÒ»¿îÓ¦Óù㷺µÄJava RPCÂþÑÜʽ·þÎñ¿ò¼Ü¡£
2021Äê8ÔÂ30ÈÕ£¬Github SecurityLab¹ûÈ»Åû¶ÁËApache DubboÖеĶà¸ö¸ßΣ©¶´£¨CVE-2021-36162ºÍCVE-2021-36163£©£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£
Apache Dubbo YAML ·´ÐòÁл¯Â©¶´£¨CVE-2021-36162£©
Apache DubboÖдæÔÚYAML ·´ÐòÁл¯Â©¶´£¬¿ÉÒÔ·ÃÎÊÅäÖÃÖÐÐĵĹ¥»÷Õß¿ÉÒÔÀûÓôË©¶´Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£
Apache DubboÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-36163£©
Apache DubboʹÓÃÁ˲»Äþ¾²µÄHessian ÐÒ飨¿ÉÑ¡£©£¬µ¼Ö²»Äþ¾²µÄ·´ÐòÁл¯£¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£
´ËÍ⣬SecurityLab»¹¹ûÈ»ÁËApache DubboÖеÄÁíÒ»¸öRCE©¶´£¨GHSL-2021-096£¬¾Ü¾øÐÞ¸´£©£¬ÓÉÓÚApache DubboʹÓÃÁ˲»Äþ¾²µÄ RMI ÐÒ飬µ¼Ö²»Äþ¾²µÄ·´ÐòÁл¯£¬¹¥»÷ÕßÄܹ»·¢ËÍÈÎÒâÀàÐ͵IJÎÊý²¢Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£
Ó°Ï췶Χ
Apache Dubbo v2.7.10
0x02 ´¦Öý¨Òé
Ä¿Ç°CVE-2021-36162ºÍCVE-2021-36163ÒѾÐÞ¸´£¬½¨Ò鼰ʱӦÓÃÄþ¾²²¹¶¡¡£µ«GHSL-2021-096ÎÊÌâ¾Ü¾øÐÞ¸´£¬½¨ÒéÓû§ÆôÓà JEP 290»úÖÆ¡£
CVE-2021-36162²¹¶¡Á´½Ó£º
https://github.com/apache/dubbo/pull/8350
CVE-2021-36163²¹¶¡Á´½Ó£º
https://github.com/apache/dubbo/pull/8238
0x03 ²Î¿¼Á´½Ó
https://securitylab.github.com/advisories/GHSL-2021-094-096-apache-dubbo/
https://dubbo.apache.org/en/downloads/
http://openjdk.java.net/jeps/290
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36162
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-31 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¶«Éƽ̨
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º