Node.jsºÅÁî×¢Èë·ì϶£¨CVE-2021-21315£©

°ä²¼¹¦·ò 2021-02-25

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-21315

ʱ   ¼ä

2021-02-25

Àà   ÐÍ

ºÅÁî×¢Èë

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Systeminformation <   5.3.1

 

0x01 ·ì϶ÏêÇé

image.png

 

Node.js-systeminformationÊÇÓÃÓÚ»ñÈ¡¸÷ÀàϵͳÐÅÏ¢µÄNode.JSÄ£¿é£¬ËüÔ̺¬¶àÖÖÇáÁ¿¼¶Ö°ÄÜ£¬Äܹ»¼ìË÷¾ßÌåµÄÓ²¼þºÍϵͳÓйØÐÅÏ¢¡£×Ô°ä²¼ÖÁ½ñ£¬systeminformationÈí¼þ°üÏÂÔØ´ÎÊý½ü3400Íò¡£

2021Äê02ÔÂ24ÈÕ£¬npmÍŶӰ䲼°²È«²¼¸æ£¬Node.js¿âÖеÄsysteminformationÈí¼þ°üÖдæÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¨CVE-2021-21315£©£¬ÆäCVSSv3ÆÀ·ÖΪ7.8¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚδ¾­¹ýÂ˵IJÎÊýÖÐ×¢ÈëPayloadÀ´Ö´ÐÐϵͳºÅÁĿǰ¸Ã·ì϶ÒѾ­ÔÚ5.3.1°æ±¾Öн¨¸´£¬¸Ã°æ±¾µÄ½¨¸´·¨Ê½Äܹ»ÕýÈ·ËãÕʺÍÑéÖ¤²ÎÊý£¬ÈçÏÂËùʾ£º

image.png

 

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶ÒѾ­½¨¸´£¬½¨Ò齫systeminformationʵʱÉý¼¶µ½5.3.1»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://www.npmjs.com/package/systeminformation

 

»º½â´ëÊ©

ÈôÊÇÎÞ·¨Éý¼¶£¬Äܹ»²é³­»òËãÕÊ´«µÝ¸øsi.inetLatency()¡¢si.inetChecksite()¡¢si.services()¡¢si.processLoad()µÄ²ÎÊý£¬Ö»ÔÊÐíʹÓÃstring£¬»Ø¾øÈκÎÊý×é¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.npmjs.com/advisories/1628

https://www.bleepingcomputer.com/news/security/heavily-used-nodejs-package-has-a-code-injection-vulnerability/

https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2m8v-572m-ff2v

 

0x04 ¹¦·òÏß

2021-02-24  npm°ä²¼°²È«²¼¸æ

2021-02-25  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png