¡¾Â©¶´Í¨¸æ¡¿Mitmproxy HTTP ÇëÇó×ß˽©¶´£¨CVE-2022-24766£©

Ðû²¼Ê±¼ä 2022-03-31


0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2022-24766

ʱ    ¼ä

2022-03-21

Àà    ÐÍ

HTTP ÇëÇó×ß˽

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

mitmproxyÊÇÒ»¸ö½»»¥Ê½µÄ¡¢Ö§³Ö SSL/TLS µÄÀ¹½ØÊðÀí£¬´øÓÐ HTTP/1¡¢HTTP/2 ºÍ WebSockets µÄ¿ØÖÆÌ¨½çÃæ¡£

3ÔÂ21ÈÕ£¬mitmproxyÏîÄ¿Ðû²¼Í¨¸æ£¬ÐÞ¸´ÁËmitmproxyÖеÄÒ»¸öHTTP ÇëÇó×ß˽©¶´£¨CVE-2022-24766£©£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8¡£

ÔÚ mitmproxy 7.0.4 ¼°Ö®Ç°µÄ°æ±¾ÖУ¬ÓÉÓÚ¶Ô HTTP ÇëÇó×ß˽µÄ± £»¤²»×㣬¶ñÒâ¿Í»§¶Ë»ò·þÎñÆ÷Äܹ»Í¨¹ý mitmproxy Ö´ÐÐ HTTP ÇëÇó×ß˽¹¥»÷¡£ÕâÒâζ×ŶñÒâ¿Í»§¶Ë/·þÎñÆ÷¿ÉÒÔͨ¹ý mitmproxy ½«ÇëÇó/ÏìÓ¦×÷ΪÁíÒ»¸öÇëÇó/ÏìÓ¦µÄ HTTP ÏûÏ¢ÌåµÄÒ»²¿ÃÅ×ß˽¡£ËäÈ» mitmproxy Ö»»á¿´µ½Ò»¸öÇëÇ󣬵«Ä¿±ê·þÎñÆ÷»á¿´µ½¶à¸öÇëÇó¡£×ß˽µÄÇëÇóÈÔ»á×÷ΪÁíÒ»¸öÇëÇóÕýÎĵÄÒ»²¿Ãű»²¶×½£¬µ«Ëü²»»á·ºÆðÔÚÇëÇóÁбíÖУ¬Ò²²»»áͨ¹ýͨ³£µÄ mitmproxy ʼþ¹Ò¹³£¬Óû§¿ÉÄÜÒѾ­ÊµÊ©ÁË×Ô½ç˵·ÃÎÊ¿ØÖƼì²é»òÊäÈëÇåÀí¡£

¸Ã©¶´Í¨³ £»áÓ°ÏìʹÓÃmitmproxyÀ´± £»¤ HTTP/1 ·þÎñµÄ mitmproxy Óû§£¬HTTP/2 ²»ÊÜÓ°Ïì¡£ËäÈ»¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬µ«ÏîĿά»¤ÈËÔ±ÌåÏÖÀûÓôË©¶´²¢²»ÈÝÒס£


Ó°Ï췶Χ

mitmproxy <=7.0.4

 

0x02 Äþ¾²½¨Òé

Ŀǰ´Ë©¶´ÒѾ­ÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÒÔÉý¼¶¸üе½mitmproxy 8.0.0 »ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://github.com/mitmproxy/mitmproxy/releases/tag/v8.0.0

 

0x03 ²Î¿¼Á´½Ó

https://github.com/mitmproxy/mitmproxy/security/advisories/GHSA-gcx2-gvj7-pxv3

https://nvd.nist.gov/vuln/detail/CVE-2022-24766

https://latesthackingnews.com/2022/03/30/a-mitmproxy-vulnerability-could-allow-http-request-smuggling-attacks/


0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-03-31

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£


¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png