¡¾·ì϶¹«¸æ¡¿Apache CouchDBÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-24706£©
°ä²¼¹¦·ò 2022-04-270x00 ·ì϶¸ÅÊö
CVE ID | CVE-2022-24706 | ·¢ÏÖ¹¦·ò | 2022-04-26 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | Óû§½»»¥ | ||
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ·ì϶ÏêÇé
Apache CouchDB ÊÇÒ»¸ö¿ªÔ´µÄÎÞ·ì¶àÖ÷ͬ²½Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÖ±¹ÛµÄHTTP/JSON API£¬£¬£¬£¬£¬£¬£¬£¬²¢Îª¿¿µÃסÐÔ¶øÉè¼Æ¡£¡£¡£¡£¡£¡£¡£
4ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Apache°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬¹«¿ªÁËApache CouchDBÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-24706£©¡£¡£¡£¡£¡£¡£¡£ÔÚ3.2.2 °æ±¾Ö®Ç°µÄ Apache CouchDB ÖУ¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÔÚ²»½øÐÐÉí·ÝÑéÖ¤µÄÇé¿öϽӼû²»ÕýÈ·µÄĬÈÏ×°Öò¢»ñµÃÖÎÀíԱȨÏÞ£º
1. CouchDB ´ò¿ªÒ»¸öËæ»úÍøÂç¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬£¬°ó¶¨µ½ËùÓпÉÓõĽӿÚÒÔÔ¤ÆÚ¼¯Èº²Ù×÷»òruntime introspection£¬£¬£¬£¬£¬£¬£¬£¬³ÆÎª "epmd "µÄʵÓ÷¨Ê½ÏòÍøÂç°ä²¼ÁËÕâ¸öËæ»ú¶Ë¿Ú¡£¡£¡£¡£¡£¡£¡£epmd×ÔÉíÔÚÒ»¸ö¹Ì¶¨µÄ¶Ë¿ÚÉϼàÌý¡£¡£¡£¡£¡£¡£¡£
2. CouchDB°üװ֮ǰΪµ¥½ÚµãºÍ¼¯Èº×°ÖÃÑ¡ÔñÁËÒ»¸öĬÈϵÄ"cookie "Öµ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃcookieÓÃÓÚÑéÖ¤Erlang ½ÚµãÖ®¼äµÄÈκÎͨѶ¡£¡£¡£¡£¡£¡£¡£
CouchDB¹Ù·½½¨ÒéÔÚËùÓÐCouchDB×°ÖÃǰÉèÖ÷À»ðǽ¡£¡£¡£¡£¡£¡£¡£ÆëÈ«µÄCouchDB apiÔÚ×¢²áµÄ¶Ë¿Ú5984ÉÏ¿ÉÓ㬣¬£¬£¬£¬£¬£¬£¬ÕâÊǵ¥½Úµã×°ÖñØÒª¹«¿ªµÄΨһ¶Ë¿Ú¡£¡£¡£¡£¡£¡£¡£²»½«µ¥¶ÀµÄ·Ö·¢¶Ë¿Ú¶³ö¸ø±í²¿½Ó¼ûµÄ×°Öò»Ò×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
Apache CouchDB < 3.2.2
0x02 °²È«½¨Òé
Ŀǰ´Ë·ì϶ÒѾ½¨¸´£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üе½Apache CouchDB 3.2.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://couchdb.apache.org/
×¢£ºCouchDB °æ±¾>= 3.2.2Öн«²»ÔÙʹÓÃÒÔǰĬÈϵÄErlang cookieÖµ`monster'£¬£¬£¬£¬£¬£¬£¬£¬Éý¼¶µ½´Ë°æ±¾µÄ×°Öý«±»ÆÈÑ¡Ôñ·ÖÆçµÄÖµ¡£¡£¡£¡£¡£¡£¡£
´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ËùÓжþ½øÔì°ü¶¼ÒѸüУ¬£¬£¬£¬£¬£¬£¬£¬ÒÔ°ó¶¨`epmd`ÒÔ¼°CouchDB·Ö·¢¶Ë¿Ú±ðÀëΪ`127.0.0.1`ºÍ/»ò`::1`¡£¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.mail-archive.com/announce@apache.org/msg07264.html
https://www.openwall.com/lists/oss-security/2022/04/26/1
https://docs.couchdb.org/en/stable/setup/cluster.html
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2022-04-27 | ³õ´Î°ä²¼ |
0x05 ¸½Â¼
8827Ì«Ñô¼¯Íżò½é
8827Ì«Ñô¼¯ÍŹ«Ë¾³ÉÁ¢ÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐÓ×°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬£¬£¬£¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂ簲ȫ²úÆ·¡¢¿ÉÐŰ²È«ÖÎÀíÆ½Ì¨¡¢°²È«·þÎñÓë½â¾ö¹æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÇþ·ϵͳºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢ÕÑͨ¡¢³¤É³¡¢¾£ÃÅµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£¡£¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îа²È«×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ