Apache HadoopDZÔÚȨÏÞÌáÉý·ì϶£¨CVE-2020-9492£©

°ä²¼¹¦·ò 2021-01-27

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-9492

ʱ  ¼ä

2021-01-27

Àà  ÐÍ

ȨÏÞÌáÉý

µÈ  ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

 

Apache HadoopÊÇÒ»Ì×ÓÃÓÚÓÉͨÓÃÓ²¼þ¹¹½¨µÄ´óÐͼ¯ÈºÉÏÔËÐÐÀûÓ÷¨Ê½µÄ¿ò¼Ü£¬ËüʵÏÖÁËMap/Reduce±à³Ì·¶ÐÍ£¬ÍÆË㹤×÷»á±»ÂÅ´ÎÔ׸î³ÉÓ׿鲢ÔËÐÐÔÚ·ÖÆçµÄ½ÚµãÉÏ¡£³ý´ËÖ®±í£¬Ëü»¹ÌṩÁËÒ»¿îÉ¢²¼Ê½Îļþϵͳ£¨HDFS£©£¬Êý¾Ý±»´æ´¢ÔÚÍÆËã½ÚµãÉÏÒÔÌṩ¸ßЧµÄ¿çÊý¾ÝÖÐÐľۺϴø¿í¡£

2021Äê01ÔÂ26ÈÕ£¬Apache°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËApache HadoopÖÐÒ»¸öDZÔÚµÄȨÏÞÌáÉý·ì϶£¨CVE-2020-9492£©¡£

WebHDFS¿Í»§¶Ë¿ÉÄÜ»áÔÚûÓÐÊʵ±ÑéÖ¤µÄÇé¿öϽ«SPNEGOÊÚȨ±êÍ··¢Ë͵½Ô¶³ÌURL£¬¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶½«·þÎñÆ÷ƾ֤·¢Ë͵½webhdfsõè¾¶À´»ñÈ¡·þÎñÖ÷Ìå¡£

 

Ó°ÏìÁìÓò

Apache Hadoop 3.2.0-3.2.1

Apache Hadoop 3.0.0-alpha1-3.1.3

Apache Hadoop 2.0.0-alpha-2.10.0


0x02 ´ëÖý¨Òé

Ŀǰ£¬¸Ã·ì϶µÄ²¹¶¡ÔÝδ°ä²¼£¬½¨ÒéʵʱÀûÓÃÒÔÏ»º½â´ëÊ©¡£

»º½â´ëÊ©

ÉèÖÃ·ÖÆçµÄhttpÊðÃû»úÃÜ£¬²¢Ê¹ÓÃרÓÃÖ÷»ú½øÐÐÿ¸öȨÏÞ·ÂÕÕ·þÎñ£¨ÈçHiveServer2£©¡£

Éý¼¶µ½3.3.0¡¢3.2.2¡¢3.1.4¡¢2.10.1»ò¸üеÄTLS¼ÓÃܰ汾£¬ÆôÓò¢½«dfs.http.policyÅäÖÃΪHTTPS_ONLY¡£

 

0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202101.mbox/%3CCAP+3qq6eDjjZG-G03RFRj9rrG4r1u=891UUEU2S8fbOCKTe4QA@mail.gmail.com%3E

https://hadoop2help.blogspot.com/2021/01/cve-2020-9492-apache-hadoop-potential.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9492

 

0x04 ¹¦·òÏß

2021-01-26  Apache°ä²¼°²È«²¼¸æ

2021-01-27  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png