¡¾·ì϶¹«¸æ¡¿CVE-2021-3129 LaravelÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2021-01-14

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-3129

ʱ  ¼ä

2021-01-14

Àà  ÐÍ

RCE

µÈ  ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Laravel <= 8.4.2

 

0x01 ·ì϶ÏêÇé

image.png

 

LaravelÊÇÒ»Ì×¼ò½à¡¢¿ªÔ´µÄPHP Web¿ª·¢¿ò¼Ü£¬£¬£¬£¬ £¬£¬£¬£¬Ö¼ÔÚʵÏÖWebÈí¼þµÄMVC¼Ü¹¹¡£¡£¡£¡£¡£¡£

2021Äê01ÔÂ12ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬Laravel±»Åû¶´æÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-3129£©¡£¡£¡£¡£¡£¡£

µ±Laravel¿ªÆôÁËDebugģʽʱ£¬£¬£¬£¬ £¬£¬£¬£¬ÓÉÓÚLaravel×Ô´øµÄIgnition ×é¼þ¶Ôfile_get_contents()ºÍfile_put_contents()º¯ÊýµÄ²»°²È«Ê¹Ó㬣¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÌáÒé¶ñÒâÒªÇ󣬣¬£¬£¬ £¬£¬£¬£¬»ú¹Ø¶ñÒâLogÎļþµÈ·½Ê½´¥·¢Phar·´ÐòÁл¯£¬£¬£¬£¬ £¬£¬£¬£¬×îÖÕÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

image.png

 

½ØÖ¹Ä¿Ç°£¬£¬£¬£¬ £¬£¬£¬£¬Ê¹ÓÃZoomeyeËÑË÷£¬£¬£¬£¬ £¬£¬£¬£¬È«Çò¹²ÓÐ193851¸öÍøÕ¾ÔÚʹÓÃLaravel¡£¡£¡£¡£¡£¡£

image.png

 

Ó°ÏìÁìÓò

Laravel <= 8.4.2

Ignition <2.5.2

 

0x02 ´ëÖý¨Òé

½¨Ò齫 Laravel ¿ò¼ÜÉý¼¶ÖÁ8.4.3¼°ÒÔÉϰ汾£¬£¬£¬£¬ £¬£¬£¬£¬»ò½« Ignition×é¼þÉý¼¶ÖÁ 2.5.2 ¼°ÒÔÉϰ汾¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://laravel.com/docs/8.x#laravel-the-fullstack-framework


0x03 ²Î¿¼Á´½Ó

https://github.com/facade/ignition/pull/334

https://www.tenable.com/cve/CVE-2021-3129

https://www.ambionics.io/blog/laravel-debug-rce

 

0x04 ¹¦·òÏß

2021-01-12  Ambionics SecurityÅû¶·ì϶

2021-01-14  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png