¡¾·ì϶¹«¸æ¡¿CVE-2021-3129 LaravelÔ¶³Ì´úÂëÖ´Ðзì϶
°ä²¼¹¦·ò 2021-01-140x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-3129 | ʱ ¼ä | 2021-01-14 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Laravel <= 8.4.2 |
0x01 ·ì϶ÏêÇé

LaravelÊÇÒ»Ì×¼ò½à¡¢¿ªÔ´µÄPHP Web¿ª·¢¿ò¼Ü£¬Ö¼ÔÚʵÏÖWebÈí¼þµÄMVC¼Ü¹¹¡£
2021Äê01ÔÂ12ÈÕ£¬Laravel±»Åû¶´æÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-3129£©¡£
µ±Laravel¿ªÆôÁËDebugģʽʱ£¬ÓÉÓÚLaravel×Ô´øµÄIgnition ×é¼þ¶Ôfile_get_contents()ºÍfile_put_contents()º¯ÊýµÄ²»°²È«Ê¹Ó㬹¥»÷ÕßÄܹ»Í¨¹ýÌáÒé¶ñÒâÒªÇ󣬻ú¹Ø¶ñÒâLogÎļþµÈ·½Ê½´¥·¢Phar·´ÐòÁл¯£¬×îÖÕÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£

½ØÖ¹Ä¿Ç°£¬Ê¹ÓÃZoomeyeËÑË÷£¬È«Çò¹²ÓÐ193851¸öÍøÕ¾ÔÚʹÓÃLaravel¡£

Ó°ÏìÁìÓò
Laravel <= 8.4.2
Ignition <2.5.2
0x02 ´ëÖý¨Òé
½¨Ò齫 Laravel ¿ò¼ÜÉý¼¶ÖÁ8.4.3¼°ÒÔÉϰ汾£¬»ò½« Ignition×é¼þÉý¼¶ÖÁ 2.5.2 ¼°ÒÔÉϰ汾¡£
ÏÂÔØÁ´½Ó£º
https://laravel.com/docs/8.x#laravel-the-fullstack-framework
0x03 ²Î¿¼Á´½Ó
https://github.com/facade/ignition/pull/334
https://www.tenable.com/cve/CVE-2021-3129
https://www.ambionics.io/blog/laravel-debug-rce
0x04 ¹¦·òÏß
2021-01-12 Ambionics SecurityÅû¶·ì϶
2021-01-14 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ