Node.jsºÅÁî×¢Èë·ì϶£¨CVE-2021-21315£©
°ä²¼¹¦·ò 2021-02-250x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-21315 | ʱ ¼ä | 2021-02-25 |
Àà ÐÍ | ºÅÁî×¢Èë | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Systeminformation < 5.3.1 |
0x01 ·ì϶ÏêÇé

Node.js-systeminformationÊÇÓÃÓÚ»ñÈ¡¸÷ÀàϵͳÐÅÏ¢µÄNode.JSÄ£¿é£¬ËüÔ̺¬¶àÖÖÇáÁ¿¼¶Ö°ÄÜ£¬Äܹ»¼ìË÷¾ßÌåµÄÓ²¼þºÍϵͳÓйØÐÅÏ¢¡£×Ô°ä²¼ÖÁ½ñ£¬systeminformationÈí¼þ°üÏÂÔØ´ÎÊý½ü3400Íò¡£
2021Äê02ÔÂ24ÈÕ£¬npmÍŶӰ䲼°²È«²¼¸æ£¬Node.js¿âÖеÄsysteminformationÈí¼þ°üÖдæÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¨CVE-2021-21315£©£¬ÆäCVSSv3ÆÀ·ÖΪ7.8¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚδ¾¹ýÂ˵IJÎÊýÖÐ×¢ÈëPayloadÀ´Ö´ÐÐϵͳºÅÁĿǰ¸Ã·ì϶ÒѾÔÚ5.3.1°æ±¾Öн¨¸´£¬¸Ã°æ±¾µÄ½¨¸´·¨Ê½Äܹ»ÕýÈ·ËãÕʺÍÑéÖ¤²ÎÊý£¬ÈçÏÂËùʾ£º

0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶ÒѾ½¨¸´£¬½¨Ò齫systeminformationʵʱÉý¼¶µ½5.3.1»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://www.npmjs.com/package/systeminformation
»º½â´ëÊ©
ÈôÊÇÎÞ·¨Éý¼¶£¬Äܹ»²é³»òËãÕÊ´«µÝ¸øsi.inetLatency()¡¢si.inetChecksite()¡¢si.services()¡¢si.processLoad()µÄ²ÎÊý£¬Ö»ÔÊÐíʹÓÃstring£¬»Ø¾øÈκÎÊý×é¡£
0x03 ²Î¿¼Á´½Ó
https://www.npmjs.com/advisories/1628
https://www.bleepingcomputer.com/news/security/heavily-used-nodejs-package-has-a-code-injection-vulnerability/
https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2m8v-572m-ff2v
0x04 ¹¦·òÏß
2021-02-24 npm°ä²¼°²È«²¼¸æ
2021-02-25 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ