¡¾Â©¶´Í¨¸æ¡¿ApacheÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-42013£©

Ðû²¼Ê±¼ä 2021-10-08


0x00 ©¶´¸ÅÊö

CVE     ID

CVE-2021-42013

ʱ      ¼ä

2021-10-07

Àà      ÐÍ

RCE

µÈ      ¼¶

ÑÏÖØ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ

2.4.49¡¢2.4.50

¹¥»÷ÅÓ´ó¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ©¶´ÏêÇé

image.png

Apache HTTP Server ÊÇÒ»¸ö¿ªÔ´¡¢¿çƽ̨µÄ Web ·þÎñÆ÷ £¬ËüÔÚÈ«Çò·¶Î§ÄÚ±»¹ã·ºÊ¹Óà ¡£

2021 Äê 10 Ô 7 ÈÕ £¬Apache Èí¼þ»ù½ð»áÐû²¼ÁËApache HTTP Server 2.4.51  £¬ÒÔÐÞ¸´ Apache HTTP Server 2.4.49 ºÍ 2.4.50 ÖеÄ·¾¶±éÀúºÍÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-41773¡¢CVE-2021-42013£© £¬Ä¿Ç°ÕâЩ©¶´Òѱ»¹ã·ºÀûÓà ¡£

Apache HTTP Server·¾¶±éÀú©¶´£¨CVE-2021-41773£©

2021Äê10ÔÂ5ÈÕ £¬ApacheÐû²¼¸üÐÂͨ¸æ £¬ÐÞ¸´ÁËApache HTTP Server 2.4.49ÖеÄÒ»¸ö·¾¶±éÀúºÍÎļþ鶩¶´£¨CVE-2021-41773£© ¡£

¹¥»÷Õß¿ÉÒÔͨ¹ý·¾¶±éÀú¹¥»÷½« URL Ó³Éäµ½Ô¤ÆÚÎĵµ¸ùĿ¼֮ÍâµÄÎļþ £¬Èç¹ûÎĵµ¸ùĿ¼֮ÍâµÄÎļþ²»ÊÜ¡°require all denied¡± ·ÃÎÊ¿ØÖƲÎÊýµÄ±£»¤ £¬ÔòÕâЩ¶ñÒâÇëÇó¾Í»áÀÖ³É ¡£³ý´ËÖ®Íâ £¬¸Ã©¶´»¹¿ÉÄܻᵼÖÂй© CGI ½Å±¾µÈ½âÊÍÎļþµÄÀ´Ô´ ¡£

ShodanËÑË÷ÏÔʾ £¬È«Çò²¿ÊðÓÐÁè¼ÝÊ®Íò¸ö £¬ÆäÖÐÐí¶à·þÎñÆ÷ÖпÉÄÜ´æÔÚ´Ë©¶´ £¬¶øÇÒ´Ë©¶´Ä¿Ç°Òѱ»¹ã·ºÀûÓà £¬½¨ÒéÏà¹ØÓû§¾¡¿ì¸üР¡£

image.png

 

Apache HTTP Server·¾¶±éÀúºÍÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-42013£©

ÓÉÓÚ¶ÔCVE-2021-41773µÄÐÞ¸´²»³äʵ £¬¹¥»÷Õß¿ÉÒÔʹÓ÷¾¶±éÀú¹¥»÷ £¬½«URLÓ³Éäµ½ÓÉÀàËƱðÃûµÄÖ¸ÁîÅäÖõÄĿ¼֮ÍâµÄÎļþ £¬Èç¹ûÕâЩĿ¼ÍâµÄÎļþûÓÐÊܵ½Ä¬ÈÏÅäÖÃ"require all denied "µÄ±£»¤ £¬ÔòÕâЩ¶ñÒâÇëÇó¾Í»áÀÖ³É ¡£Èç¹û»¹ÎªÕâЩ±ðÃû·¾¶ÆôÓÃÁË CGI ½Å±¾ £¬ÔòÄܹ»µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£

 

Ó°Ï췶Χ

Apache HTTP Server 2.4.49

Apache HTTP Server 2.4.50

 

0x02 ´¦Öý¨Òé

Ä¿Ç°ÕâЩ©¶´ÒѾ­ÐÞ¸´ £¬¼øÓÚ©¶´µÄÑÏÖØÐÔ £¬½¨ÒéÊÜÓ°ÏìµÄÓû§Á¢¼´Éý¼¶¸üе½Apache HTTP Server 2.4.51£¨ÒÑÓÚ10ÔÂ7ÈÕÐû²¼£©»ò¸ü¸ß°æ±¾ ¡£

ÏÂÔØÁ´½Ó£º

https://httpd.apache.org/download.cgi#apache24

 

0x03 ²Î¿¼Á´½Ó

https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2021-42013

http://mail-archives.apache.org/mod_mbox/www-announce/202110.mbox/%3C7c4d9498-09ce-c4b4-b1c7-d55512fdc0b0@apache.org%3E

https://www.bleepingcomputer.com/news/security/apache-emergency-update-fixes-incomplete-patch-for-exploited-bug/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-10-06

Ê×´ÎÐû²¼

V1.1

2021-10-08

Ôö¼ÓCVE-2021-42013©¶´ÐÅÏ¢µÈ

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚ¶«É­Æ½Ì¨

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png