¡¾·ì϶¹«¸æ¡¿Apache DubboÔ¶³Ì´úÂëÖ´Ðзì϶ (CVE-2021-36162)

°ä²¼¹¦·ò 2021-08-31


0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-36162

ʱ      ¼ä

2021-08-30

Àà      ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

Apache DubboÊÇÒ»¿îÀûÓÃ¿í·ºµÄJava RPCÉ¢²¼Ê½·þÎñ¿ò¼Ü ¡£¡£¡£¡£¡£¡£¡£¡£

2021Äê8ÔÂ30ÈÕ£¬£¬£¬£¬ £¬£¬Github SecurityLab¹«¿ªÅû¶ÁËApache DubboÖеĶà¸ö¸ßΣ·ì϶£¨CVE-2021-36162ºÍCVE-2021-36163£©£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£

Apache Dubbo YAML ·´ÐòÁл¯·ì϶£¨CVE-2021-36162£©

Apache DubboÖдæÔÚYAML ·´ÐòÁл¯·ì϶£¬£¬£¬£¬ £¬£¬Äܹ»½Ó¼ûÅäÖÃÖÐÐĵĹ¥»÷ÕßÄܹ»ÀûÓô˷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£

 

Apache DubboÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-36163£©

Apache DubboʹÓÃÁ˲»°²È«µÄHessian ºÍ̸£¨¿ÉÑ ¡£¡£¡£¡£¡£¡£¡£¡£©£¬£¬£¬£¬ £¬£¬µ¼Ö²»°²È«µÄ·´ÐòÁл¯£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£

´Ë±í£¬£¬£¬£¬ £¬£¬SecurityLab»¹¹«¿ªÁËApache DubboÖеÄÁíÒ»¸öRCE·ì϶£¨GHSL-2021-096£¬£¬£¬£¬ £¬£¬»Ø¾ø½¨¸´£©£¬£¬£¬£¬ £¬£¬ÓÉÓÚApache DubboʹÓÃÁ˲»°²È«µÄ RMI ºÍ̸£¬£¬£¬£¬ £¬£¬µ¼Ö²»°²È«µÄ·´ÐòÁл¯£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÄÜ·¢ËÍËÁÒâÀàÐ͵IJÎÊý²¢Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

Apache Dubbo v2.7.10

 

0x02 ´ëÖý¨Òé

ĿǰCVE-2021-36162ºÍCVE-2021-36163ÒѾ­½¨¸´£¬£¬£¬£¬ £¬£¬½¨ÒéʵʱÀûÓð²È«²¹¶¡ ¡£¡£¡£¡£¡£¡£¡£¡£µ«GHSL-2021-096ÎÊÌâ»Ø¾ø½¨¸´£¬£¬£¬£¬ £¬£¬½¨ÒéÓû§ÆôÓà JEP 290»úÔì ¡£¡£¡£¡£¡£¡£¡£¡£

CVE-2021-36162²¹¶¡Á´½Ó£º

https://github.com/apache/dubbo/pull/8350

 

CVE-2021-36163²¹¶¡Á´½Ó£º

https://github.com/apache/dubbo/pull/8238

 

0x03 ²Î¿¼Á´½Ó

https://securitylab.github.com/advisories/GHSL-2021-094-096-apache-dubbo/

https://dubbo.apache.org/en/downloads/

http://openjdk.java.net/jeps/290

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36162

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-08-31

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬ £¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png