Adobe ColdFusionÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21087£©
°ä²¼¹¦·ò 2021-03-230x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-21087 | ʱ ¼ä | 2021-03-23 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ÊÇ |
0x01 ·ì϶ÏêÇé

Adobe ColdFusionÊÇÃÀ¹úAdobe¹«Ë¾Ñз¢µÄÒ»¿î¶¯Ì¬Web·þÎñÆ÷²úÆ·£¬ÆäÔËÐеÄCFML£¨ColdFusion Markup Language£©ÊÇÒ»ÖÖÕë¶ÔWebÀûÓõľ籾˵»°¡£
2021Äê03ÔÂ22ÈÕ£¬Adobe¹Ù·½°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËColdFusionÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21087£©¡£ÓÉÓÚδÕýÈ·ÑéÖ¤ÊäÈ룬δÊÚȨµÄ¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâÒªÇóÀ´Ô¶³ÌÖ´ÐÐËÁÒâ´úÂ룬Ŀǰ¸Ã·ì϶ÒѾ³Ê´Ë¿ÌÒ°ÀûÓÃÇé¿ö£¬µ«·ì϶µÄϸ½ÚÉÐδ¹«¿ª¡£
Ó°ÏìÁìÓò
Adobe ColdFusion 2016 <= Update 16
Adobe ColdFusion 2018 <= Update 10
Adobe ColdFusion 2021°æ±¾2021.0.0.323925
0x02 ´ëÖý¨Òé
Ŀǰ¹Ù·½Òѽ¨¸´ÁË´Ë·ì϶£¬½¨Òéʵʱ¸üÐÂÖÁÒÔϰ汾£º
Adobe ColdFusion 2016 Update 17
Adobe ColdFusion 2018 Update 11
Adobe ColdFusion 2021 Update 1
ÊÖ¶¯×°ÖøüÐÂ
1.ÏÂÔØÒÔÏÂjar°ü¡£
Adobe ColdFusion 2016 Update 17
ÏÂÔØÁ´½Ó£º
https://cfdownload.adobe.com/pub/adobe/coldfusion/2016/updates/hotfix-017-325979.jar
Adobe ColdFusion 2018 Update 11
ÏÂÔØÁ´½Ó£º
https://cfdownload.adobe.com/pub/adobe/coldfusion/2018/updates/hotfix-011-326016.jar
Adobe ColdFusion 2021 Update 1
ÏÂÔØÁ´½Ó£º
https://cfdownload.adobe.com/pub/adobe/coldfusion/2021/updates/hotfix-001-325996.jar
2.ƾ¾ÝÏÂÔØµÄ²¹¶¡ÎļþÖ´ÐÐÒÔÏÂÏ౨ºÅÁ±ØÐëÓµÓÐÆô¶¯»òÖÕ³¡ColdFusion·þÎñÒÔ¼°¶ÔColdFusion¸ùĿ¼ÓÐÆëÈ«½Ó¼ûȨÏÞ¡££©
Windows:
<cf_root>/jre/bin/java.exe -jar <jar-file-dir>/hotfix-017-325979.jar
<cf_root>/jre/bin/java.exe -jar <jar-file-dir>/hotfix-011-326016.jar
<cf_root>/jre/bin/java.exe -jar <jar-file-dir>/hotfix-001-325996.jar
»ùÓÚLinuxµÄƽ̨:
<cf_root>/jre/bin/java -jar <jar-file-dir>/hotfix-017-325979.jar
<cf_root>/jre/bin/java -jar <jar-file-dir>/hotfix-011-326016.jar
<cf_root>/jre/bin/java -jar <jar-file-dir>/hotfix-001-325996.jar
3. È·±£ÓëColdFusion°ó¸¿ÔÚһ·µÄJREÓÃÓÚÖ´ÐÐÏÂÔØµÄJAR¡£¶ÔÓÚ¶ÀÁ¢µÄColdFusion£¬Ëü±ØÐëλÓÚ<cf_root>/jre/bin¡£
4.¸ü¶àÐÅÏ¢£¬Çë²Î¿¼£º
https://helpx.adobe.com/coldfusion/configuring-administering/using-the-coldfusion-administrator.html#serverupdate
0x03 ²Î¿¼Á´½Ó
https://helpx.adobe.com/security/products/coldfusion/apsb21-16.html#Solution
https://securityaffairs.co/wordpress/115864/security/adobe-coldfusion-flaw.html?
https://helpx.adobe.com/coldfusion/kb/coldfusion-2016-update-17.html
0x04 ¹¦·òÏß
2021-03-22 Adobe°ä²¼°²È«²¼¸æ
2021-03-23 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ