NGINX njs »º³åÇøÃýÎó·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-06-05·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12208£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
NGINXÖÐʹÓõÄnjs 0.3.1¼°Ö®Ç°°æ±¾
·ì϶¸ÅÊö
NGINXÊÇÃÀ¹úNGINX¹«Ë¾µÄÒ»¿îÇáÁ¿¼¶Web·þÎñÆ÷/·´Ïò´úÀí·þÎñÆ÷¼°µç×ÓÓʼþ£¨IMAP/POP3£©´úÀí·þÎñÆ÷¡£njsÊÇÆäÖеÄÒ»¸öÖ§³ÖÀ©´óNGINXÖ°Äܵľ籾˵»°×é¼þ¡£
NGINXÖÐʹÓõÄnjs 0.3.1¼°Ö®Ç°°æ±¾µÄnjs/njs_function.cÎļþµÄ¡®njs_function_native_call¡¯º¯Êý´æÔÚ»ùÓڶѵĻº³åÇøÒç¶Âí½Å¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬Î´ÕýÈ·ÑéÖ¤Êý¾ÝÌìǵ£¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æµØÎ»ÉÏÖ´ÐÐÁËÃýÎóµÄ¶Áд²Ù×÷¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶µ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£
·ì϶ÑéÖ¤
POC£ºhttps://github.com/nginx/njs/issues/163¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://nginx.org/ ¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ