¡¾·ì϶¹«¸æ¡¿ApacheÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-42013£©

°ä²¼¹¦·ò 2021-10-08


0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-42013

ʱ      ¼ä

2021-10-07

Àà      ÐÍ

RCE

µÈ      ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

2.4.49¡¢2.4.50

¹¥»÷¸´ÔÓ¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ·ì϶ÏêÇé

image.png

Apache HTTP Server ÊÇÒ»¸ö¿ªÔ´¡¢¿çƽ̨µÄ Web ·þÎñÆ÷£¬ËüÔÚÈ«ÇòÁìÓòÄÚ±»¿í·ºÊ¹Óá£

2021 Äê 10 Ô 7 ÈÕ£¬Apache Èí¼þ»ù½ð»á°ä²¼ÁËApache HTTP Server 2.4.51 £¬ÒÔ½¨¸´ Apache HTTP Server 2.4.49 ºÍ 2.4.50 ÖеÄõè¾¶±éÀúºÍÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-41773¡¢CVE-2021-42013£©£¬Ä¿Ç°ÕâЩ·ì϶Òѱ»¿í·ºÀûÓá£

Apache HTTP Serverõè¾¶±éÀú·ì϶£¨CVE-2021-41773£©

2021Äê10ÔÂ5ÈÕ£¬Apache°ä²¼¸üв¼¸æ£¬½¨¸´ÁËApache HTTP Server 2.4.49ÖеÄÒ»¸öõè¾¶±éÀúºÍÎļþй¶·ì϶£¨CVE-2021-41773£©¡£

¹¥»÷ÕßÄܹ»Í¨¹ýõè¾¶±éÀú¹¥»÷½« URL Ó³Éäµ½Ô¤ÆÚÎĵµ¸ùĿ¼֮±íµÄÎļþ£¬ÈôÊÇÎĵµ¸ùĿ¼֮±íµÄÎļþ²»ÊÜ¡°require all denied¡± ½Ó¼û½ÚÔì²ÎÊýµÄ±£»¤£¬ÔòÕâЩ¶ñÒâÒªÇó¾Í»á³É¹¦¡£³ý´ËÖ®±í£¬¸Ã·ì϶»¹¿ÉÄܻᵼÖÂй© CGI ¾ç±¾µÈÚ¹ÊÍÎļþµÄÆðÔ´¡£

ShodanËÑË÷ÏÔʾ£¬È«Çò²¿ÊðÓг¬¹ýÊ®Íò¸ö£¬ÆäÖкܶà·þÎñÆ÷ÖпÉÄÜ´æÔÚ´Ë·ì϶£¬²¢ÇÒ´Ë·ì϶ĿǰÒѱ»¿í·ºÀûÓ㬽¨ÒéÓйØÓû§¾¡¿ì¸üС£

image.png

 

Apache HTTP Serverõè¾¶±éÀúºÍÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-42013£©

ÓÉÓÚ¶ÔCVE-2021-41773µÄ½¨¸´²»³ä·Ö£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃõè¾¶±éÀú¹¥»÷£¬½«URLÓ³Éäµ½ÓÉÀàËÆ±ðºÅµÄÖ¸ÁîÅäÖõÄĿ¼֮±íµÄÎļþ£¬ÈôÊÇÕâЩĿ¼±íµÄÎļþûÓÐÊܵ½Ä¬ÈÏÅäÖÃ"require all denied "µÄ±£»¤£¬ÔòÕâЩ¶ñÒâÒªÇó¾Í»á³É¹¦¡£ÈôÊÇ»¹ÎªÕâЩ±ðºÅõè¾¶ÆôÓÃÁË CGI ¾ç±¾£¬Ôò¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

 

Ó°ÏìÁìÓò

Apache HTTP Server 2.4.49

Apache HTTP Server 2.4.50

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´£¬¼øÓÚ·ì϶µÄÑϳÁÐÔ£¬½¨ÒéÊÜÓ°ÏìµÄÓû§µ±¼´Éý¼¶¸üе½Apache HTTP Server 2.4.51£¨ÒÑÓÚ10ÔÂ7ÈÕ°ä²¼£©»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://httpd.apache.org/download.cgi#apache24

 

0x03 ²Î¿¼Á´½Ó

https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2021-42013

http://mail-archives.apache.org/mod_mbox/www-announce/202110.mbox/%3C7c4d9498-09ce-c4b4-b1c7-d55512fdc0b0@apache.org%3E

https://www.bleepingcomputer.com/news/security/apache-emergency-update-fixes-incomplete-patch-for-exploited-bug/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-10-06

³õ´Î°ä²¼

V1.1

2021-10-08

Ôö³¤CVE-2021-42013·ì϶ÐÅÏ¢µÈ

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png