¡¾·ì϶¹«¸æ¡¿Apache DubboÔ¶³Ì´úÂëÖ´Ðзì϶ (CVE-2021-36162)
°ä²¼¹¦·ò 2021-08-310x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-36162 | ʱ ¼ä | 2021-08-30 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

Apache DubboÊÇÒ»¿îÀûÓÃ¿í·ºµÄJava RPCÉ¢²¼Ê½·þÎñ¿ò¼Ü¡£
2021Äê8ÔÂ30ÈÕ£¬Github SecurityLab¹«¿ªÅû¶ÁËApache DubboÖеĶà¸ö¸ßΣ·ì϶£¨CVE-2021-36162ºÍCVE-2021-36163£©£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë¡£
Apache Dubbo YAML ·´ÐòÁл¯·ì϶£¨CVE-2021-36162£©
Apache DubboÖдæÔÚYAML ·´ÐòÁл¯·ì϶£¬Äܹ»½Ó¼ûÅäÖÃÖÐÐĵĹ¥»÷ÕßÄܹ»ÀûÓô˷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë¡£
Apache DubboÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-36163£©
Apache DubboʹÓÃÁ˲»°²È«µÄHessian ºÍ̸£¨¿ÉÑ¡£©£¬µ¼Ö²»°²È«µÄ·´ÐòÁл¯£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë¡£
´Ë±í£¬SecurityLab»¹¹«¿ªÁËApache DubboÖеÄÁíÒ»¸öRCE·ì϶£¨GHSL-2021-096£¬»Ø¾ø½¨¸´£©£¬ÓÉÓÚApache DubboʹÓÃÁ˲»°²È«µÄ RMI ºÍ̸£¬µ¼Ö²»°²È«µÄ·´ÐòÁл¯£¬¹¥»÷Õß¿ÉÄÜ·¢ËÍËÁÒâÀàÐ͵IJÎÊý²¢Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£
Ó°ÏìÁìÓò
Apache Dubbo v2.7.10
0x02 ´ëÖý¨Òé
ĿǰCVE-2021-36162ºÍCVE-2021-36163ÒѾ½¨¸´£¬½¨ÒéʵʱÀûÓð²È«²¹¶¡¡£µ«GHSL-2021-096ÎÊÌâ»Ø¾ø½¨¸´£¬½¨ÒéÓû§ÆôÓà JEP 290»úÔì¡£
CVE-2021-36162²¹¶¡Á´½Ó£º
https://github.com/apache/dubbo/pull/8350
CVE-2021-36163²¹¶¡Á´½Ó£º
https://github.com/apache/dubbo/pull/8238
0x03 ²Î¿¼Á´½Ó
https://securitylab.github.com/advisories/GHSL-2021-094-096-apache-dubbo/
https://dubbo.apache.org/en/downloads/
http://openjdk.java.net/jeps/290
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36162
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-08-31 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ