¡¾·ì϶¹«¸æ¡¿Apache DubboÔ¶³Ì´úÂëÖ´Ðзì϶ (CVE-2021-36162)

°ä²¼¹¦·ò 2021-08-31


0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-36162

ʱ      ¼ä

2021-08-30

Àà      ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

Apache DubboÊÇÒ»¿îÀûÓÃ¿í·ºµÄJava RPCÉ¢²¼Ê½·þÎñ¿ò¼Ü¡£

2021Äê8ÔÂ30ÈÕ£¬Github SecurityLab¹«¿ªÅû¶ÁËApache DubboÖеĶà¸ö¸ßΣ·ì϶£¨CVE-2021-36162ºÍCVE-2021-36163£©£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë¡£

Apache Dubbo YAML ·´ÐòÁл¯·ì϶£¨CVE-2021-36162£©

Apache DubboÖдæÔÚYAML ·´ÐòÁл¯·ì϶£¬Äܹ»½Ó¼ûÅäÖÃÖÐÐĵĹ¥»÷ÕßÄܹ»ÀûÓô˷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë¡£

 

Apache DubboÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-36163£©

Apache DubboʹÓÃÁ˲»°²È«µÄHessian ºÍ̸£¨¿ÉÑ¡£©£¬µ¼Ö²»°²È«µÄ·´ÐòÁл¯£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë¡£

´Ë±í£¬SecurityLab»¹¹«¿ªÁËApache DubboÖеÄÁíÒ»¸öRCE·ì϶£¨GHSL-2021-096£¬»Ø¾ø½¨¸´£©£¬ÓÉÓÚApache DubboʹÓÃÁ˲»°²È«µÄ RMI ºÍ̸£¬µ¼Ö²»°²È«µÄ·´ÐòÁл¯£¬¹¥»÷Õß¿ÉÄÜ·¢ËÍËÁÒâÀàÐ͵IJÎÊý²¢Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

 

Ó°ÏìÁìÓò

Apache Dubbo v2.7.10

 

0x02 ´ëÖý¨Òé

ĿǰCVE-2021-36162ºÍCVE-2021-36163ÒѾ­½¨¸´£¬½¨ÒéʵʱÀûÓð²È«²¹¶¡¡£µ«GHSL-2021-096ÎÊÌâ»Ø¾ø½¨¸´£¬½¨ÒéÓû§ÆôÓà JEP 290»úÔì¡£

CVE-2021-36162²¹¶¡Á´½Ó£º

https://github.com/apache/dubbo/pull/8350

 

CVE-2021-36163²¹¶¡Á´½Ó£º

https://github.com/apache/dubbo/pull/8238

 

0x03 ²Î¿¼Á´½Ó

https://securitylab.github.com/advisories/GHSL-2021-094-096-apache-dubbo/

https://dubbo.apache.org/en/downloads/

http://openjdk.java.net/jeps/290

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36162

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-08-31

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png