Node.jsºÅÁî×¢Èë·ì϶£¨CVE-2021-21315£©

°ä²¼¹¦·ò 2021-02-25

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-21315

ʱ   ¼ä

2021-02-25

Àà   ÐÍ

ºÅÁî×¢Èë

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Systeminformation <   5.3.1

 

0x01 ·ì϶ÏêÇé

image.png

 

Node.js-systeminformationÊÇÓÃÓÚ»ñÈ¡¸÷ÀàϵͳÐÅÏ¢µÄNode.JSÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬ £¬£¬£¬£¬£¬ËüÔ̺¬¶àÖÖÇáÁ¿¼¶Ö°ÄÜ£¬£¬£¬ £¬£¬£¬£¬£¬Äܹ»¼ìË÷¾ßÌåµÄÓ²¼þºÍϵͳÓйØÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£×Ô°ä²¼ÖÁ½ñ£¬£¬£¬ £¬£¬£¬£¬£¬systeminformationÈí¼þ°üÏÂÔØ´ÎÊý½ü3400Íò¡£¡£¡£ ¡£¡£¡£¡£

2021Äê02ÔÂ24ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬npmÍŶӰ䲼°²È«²¼¸æ£¬£¬£¬ £¬£¬£¬£¬£¬Node.js¿âÖеÄsysteminformationÈí¼þ°üÖдæÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¨CVE-2021-21315£©£¬£¬£¬ £¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.8¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚδ¾­¹ýÂ˵IJÎÊýÖÐ×¢ÈëPayloadÀ´Ö´ÐÐϵͳºÅÁî¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°¸Ã·ì϶ÒѾ­ÔÚ5.3.1°æ±¾Öн¨¸´£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã°æ±¾µÄ½¨¸´·¨Ê½Äܹ»ÕýÈ·ËãÕʺÍÑéÖ¤²ÎÊý£¬£¬£¬ £¬£¬£¬£¬£¬ÈçÏÂËùʾ£º

image.png

 

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶ÒѾ­½¨¸´£¬£¬£¬ £¬£¬£¬£¬£¬½¨Ò齫systeminformationʵʱÉý¼¶µ½5.3.1»ò¸ü¸ß°æ±¾¡£¡£¡£ ¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.npmjs.com/package/systeminformation

 

»º½â´ëÊ©

ÈôÊÇÎÞ·¨Éý¼¶£¬£¬£¬ £¬£¬£¬£¬£¬Äܹ»²é³­»òËãÕÊ´«µÝ¸øsi.inetLatency()¡¢si.inetChecksite()¡¢si.services()¡¢si.processLoad()µÄ²ÎÊý£¬£¬£¬ £¬£¬£¬£¬£¬Ö»ÔÊÐíʹÓÃstring£¬£¬£¬ £¬£¬£¬£¬£¬»Ø¾øÈκÎÊý×é¡£¡£¡£ ¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.npmjs.com/advisories/1628

https://www.bleepingcomputer.com/news/security/heavily-used-nodejs-package-has-a-code-injection-vulnerability/

https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2m8v-572m-ff2v

 

0x04 ¹¦·òÏß

2021-02-24  npm°ä²¼°²È«²¼¸æ

2021-02-25  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png