¡¾·ì϶¹«¸æ¡¿Apache CouchDBÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-24706£©

°ä²¼¹¦·ò 2022-04-27


0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2022-24706

·¢ÏÖ¹¦·ò

2022-04-26

Àà    ÐÍ

´úÂëÖ´ÐÐ

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È


Óû§½»»¥


PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

Apache CouchDB ÊÇÒ»¸ö¿ªÔ´µÄÎÞ·ì¶àÖ÷ͬ²½Êý¾Ý¿â £¬£¬ £¬ £¬£¬£¬£¬£¬Ê¹ÓÃÖ±¹ÛµÄHTTP/JSON API £¬£¬ £¬ £¬£¬£¬£¬£¬²¢Îª¿¿µÃסÐÔ¶øÉè¼Æ¡£¡£¡£¡£¡£¡£¡£

4ÔÂ26ÈÕ £¬£¬ £¬ £¬£¬£¬£¬£¬Apache°ä²¼°²È«²¼¸æ £¬£¬ £¬ £¬£¬£¬£¬£¬¹«¿ªÁËApache CouchDBÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-24706£©¡£¡£¡£¡£¡£¡£¡£ÔÚ3.2.2 °æ±¾Ö®Ç°µÄ Apache CouchDB ÖÐ £¬£¬ £¬ £¬£¬£¬£¬£¬Äܹ»ÔÚ²»½øÐÐÉí·ÝÑéÖ¤µÄÇé¿öϽӼû²»ÕýÈ·µÄĬÈÏ×°Öò¢»ñµÃÖÎÀíԱȨÏÞ£º

1.    CouchDB ´ò¿ªÒ»¸öËæ»úÍøÂç¶Ë¿Ú £¬£¬ £¬ £¬£¬£¬£¬£¬°ó¶¨µ½ËùÓпÉÓõĽӿÚÒÔÔ¤ÆÚ¼¯Èº²Ù×÷»òruntime introspection £¬£¬ £¬ £¬£¬£¬£¬£¬³ÆÎª "epmd "µÄʵÓ÷¨Ê½ÏòÍøÂç°ä²¼ÁËÕâ¸öËæ»ú¶Ë¿Ú¡£¡£¡£¡£¡£¡£¡£epmd×ÔÉíÔÚÒ»¸ö¹Ì¶¨µÄ¶Ë¿ÚÉϼàÌý¡£¡£¡£¡£¡£¡£¡£

2.    CouchDB°üװ֮ǰΪµ¥½ÚµãºÍ¼¯Èº×°ÖÃÑ¡ÔñÁËÒ»¸öĬÈϵÄ"cookie "Öµ £¬£¬ £¬ £¬£¬£¬£¬£¬¸ÃcookieÓÃÓÚÑéÖ¤Erlang ½ÚµãÖ®¼äµÄÈκÎͨѶ¡£¡£¡£¡£¡£¡£¡£

CouchDB¹Ù·½½¨ÒéÔÚËùÓÐCouchDB×°ÖÃǰÉèÖ÷À»ðǽ¡£¡£¡£¡£¡£¡£¡£ÆëÈ«µÄCouchDB apiÔÚ×¢²áµÄ¶Ë¿Ú5984ÉÏ¿ÉÓà £¬£¬ £¬ £¬£¬£¬£¬£¬ÕâÊǵ¥½Úµã×°ÖñØÒª¹«¿ªµÄΨһ¶Ë¿Ú¡£¡£¡£¡£¡£¡£¡£²»½«µ¥¶ÀµÄ·Ö·¢¶Ë¿Ú¶³ö¸ø±í²¿½Ó¼ûµÄ×°Öò»Ò×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£


Ó°ÏìÁìÓò

Apache CouchDB < 3.2.2

 

0x02 °²È«½¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´ £¬£¬ £¬ £¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üе½Apache CouchDB 3.2.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://couchdb.apache.org/

×¢£ºCouchDB °æ±¾>= 3.2.2Öн«²»ÔÙʹÓÃÒÔǰĬÈϵÄErlang cookieÖµ`monster' £¬£¬ £¬ £¬£¬£¬£¬£¬Éý¼¶µ½´Ë°æ±¾µÄ×°Öý«±»ÆÈÑ¡Ôñ·ÖÆçµÄÖµ¡£¡£¡£¡£¡£¡£¡£

´Ë±í £¬£¬ £¬ £¬£¬£¬£¬£¬ËùÓжþ½øÔì°ü¶¼ÒѸüР£¬£¬ £¬ £¬£¬£¬£¬£¬ÒÔ°ó¶¨`epmd`ÒÔ¼°CouchDB·Ö·¢¶Ë¿Ú±ðÀëΪ`127.0.0.1`ºÍ/»ò`::1`¡£¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.mail-archive.com/announce@apache.org/msg07264.html

https://www.openwall.com/lists/oss-security/2022/04/26/1

https://docs.couchdb.org/en/stable/setup/cluster.html


0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2022-04-27

³õ´Î°ä²¼

 

0x05 ¸½Â¼

8827Ì«Ñô¼¯Íżò½é

8827Ì«Ñô¼¯ÍŹ«Ë¾³ÉÁ¢ÓÚ1996Äê £¬£¬ £¬ £¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐÓ×°åÕýʽ¹ÒÅÆÉÏÊÐ £¬£¬ £¬ £¬£¬£¬£¬£¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂ簲ȫ²úÆ·¡¢¿ÉÐŰ²È«ÖÎÀíÆ½Ì¨¡¢°²È«·þÎñÓë½â¾ö¹æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ° £¬£¬ £¬ £¬£¬£¬£¬£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹ £¬£¬ £¬ £¬£¬£¬£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÇþ·ϵͳºÍ¼¼ÊõÖ§³ÖÖÐÐÄ £¬£¬ £¬ £¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢ÕÑͨ¡¢³¤É³¡¢¾£ÃÅµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£

¶àÄêÀ´ £¬£¬ £¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ £¬£¬ £¬ £¬£¬£¬£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦ £¬£¬ £¬ £¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£¡£¡£¡£¡£¡£


¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ £¬£¬ £¬ £¬£¬£¬£¬£¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png