NginxËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-23017£©

°ä²¼¹¦·ò 2021-05-27

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-23017

ʱ    ¼ä

2021-05-27

Àà   ÐÍ

´úÂëÖ´ÐÐ

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Nginx 0.6.18 - 1.20.0

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

NginxÊÇÒ»¸ö¸ß»úÄܵÄHTTPºÍ·´Ïò´úÀíweb·þÎñÆ÷£¬Í¬Ê±Ò²ÌṩÁËIMAP/POP3/SMTP·þÎñ£¬ÓÉÓÚÆäÓµÓкܶàÓźñµÄ¸öÐÔ£¬µ¼ÖÂÔÚÈ«ÇòÁìÓòÄÚ±»¿í·ºÊ¹Óá£

2021Äê05ÔÂ25ÈÕ£¬Nginx¹Ù·½°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËNginx DNS ResolverÖеÄÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-23017£©¡£

ÓÉÓÚNginxÔÚ´¦ÖÃDNSÏìӦʱ´æÔÚ°²È«ÎÊÌ⣬µ±ÔÚÅäÖÃÎļþÖÐʹÓà ¡°resolver ¡±Ö¸Áîʱ£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýαÔìÀ´×ÔDNS·þÎñÆ÷µÄUDPÊý¾Ý°ü£¬»ú¹ØDNSÏìÓ¦Ôì³É1-byteÄڴ渲¸Ç£¬´Ó¶øµ¼Ö»ؾø·þÎñ»òËÁÒâ´úÂëÖ´ÐС£

¸Ã·ì϶½öÔÚÅäÖÃÁËÒ»¸ö»ò¶à¸ö¡°resolver¡±Ö¸ÁîµÄÇé¿öÏ´æÔÚ£¬¶øÄ¬ÈÏÇé¿öÏÂûÓÐÅäÖá£

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶ÒÑÔÚÒÔϰ汾Öн¨¸´£¬½¨Ò龡¿ì½øÐÐÉý¼¶¸üУº

NGINX Open Source 1.20.1 (stable)

NGINX Open Source 1.21.0 (mainline)

NGINX Plus R23 P1

NGINX Plus R24 P1

ÒÔϰ汾µÄNGINX Ingress ControllerÔ̺¬NGINX Open SourceºÍNGINX PlusµÄ½¨¸´·¨Ê½°æ±¾£º

NGINX Ingress Controller 1.11.2 ¨C NGINX Plus R23 P1

NGINX Ingress Controller 1.11.3 ¨C NGINX Open Source 1.21.0 ºÍNGINX Plus R23 P1

 

ÏÂÔØÁ´½Ó£º

http://nginx.org/en/download.html

²¹¶¡Á´½Ó£º

http://nginx.org/download/patch.2021.resolver.txt

 

0x03 ²Î¿¼Á´½Ó

http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html

https://www.nginx.com/blog/updating-nginx-dns-resolver-vulnerability-cve-2021-23017/

https://support.f5.com/csp/article/K12331123

 

0x04 ¹¦·òÏß

2021-05-25  Nginx°ä²¼°²È«²¼¸æ

2021-05-27  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png