¡¾·ì϶¹«¸æ¡¿JsonWebTokenÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-23529£©

°ä²¼¹¦·ò 2023-01-10
 

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2022-23529

·¢ÏÖ¹¦·ò

2023-01-10

Àà    ÐÍ

ÊäÈëÑéÖ¤²»µ±

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

JsonWebTokenÊÇÒ»¸öÊÜ»¶Ó­µÄ¿ªÔ´¿â£¬£¬ £¬£¬£¬ÓÃÓÚ´´½¨¡¢ÊðÃûºÍÑéÖ¤ JSON Web ÁîÅÆ¡£¡£¡£¡£¡£¡£

2022Äê12ÔÂ21ÈÕ£¬£¬ £¬£¬£¬node-jsonwebtokenÏîÄ¿°ä²¼°²È«²¼¸æ£¬£¬ £¬£¬£¬½¨¸´ÁËJsonWebTokenÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-23529£©£¬£¬ £¬£¬£¬¸Ã·ì϶µÄCVSSv3ÆÀ·Ö×î¸ßΪ9.8¡£¡£¡£¡£¡£¡£

JsonWebToken 8.5.1¼°Ö®Ç°°æ±¾ÖУ¬£¬ £¬£¬£¬ÓÉÓÚjwt.verify()º¯ÊýÖдæÔÚ²»°²È«µÄÊäÈëÑéÖ¤·ì϶£¬£¬ £¬£¬£¬ÈôÊÇ¿ÉÄÜÅú¸Äjwt.verify()º¯ÊýµÄÃÜÔ¿¼ìË÷²ÎÊý£¨²Î¿¼readmeÁ´½ÓÖеÄsecretOrPublicKey²ÎÊý£©£¬£¬ £¬£¬£¬ÔòÄܹ»ÀûÓø÷ì϶ÔÚÖ÷»úÉÏдÈëËÁÒâÎļþ²¢Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

JsonWebToken°æ±¾ <= 8.5.1

 

0x02 °²È«½¨Òé

Ŀǰ¸Ã·ì϶ÒѾ­½¨¸´£¬£¬ £¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉʵʱÉý¼¶µ½JsonWebToken 9.0.0°æ±¾¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/auth0/node-jsonwebtoken/tags

×¢£º½öµ±ÔÊÐí²»ÊÜÐÅÀµµÄʵÌåÅú¸ÄÓû§½ÚÔìµÄÖ÷»úÉϵÄjwt.verify()µÄÃÜÔ¿¼ìË÷²ÎÊýʱ£¬£¬ £¬£¬£¬Óû§²Å»áÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://github.com/auth0/node-jsonwebtoken/security/advisories/GHSA-27h2-hvpr-p74q

https://github.com/auth0/node-jsonwebtoken#jwtverifytoken-secretorpublickey-options-callback

https://www.bleepingcomputer.com/news/security/auth0-fixes-rce-flaw-in-jsonwebtoken-library-used-by-22-000-projects/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2023-01-10

³õ´Î°ä²¼

 

0x05 ¸½Â¼

8827Ì«Ñô¼¯Íżò½é

8827Ì«Ñô¼¯ÍųÉÁ¢ÓÚ1996Ä꣬£¬ £¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°8827Ì«Ñô¼¯ÍÅ´óÏ㬣¬ £¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬ £¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬ £¬£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÀö½­ÖÐÓ×°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬ £¬£¬£¬8827Ì«Ñô¼¯ÍÅÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬£¬ £¬£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬£¬ £¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£¡£¡£¡£¡£

 

¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬ £¬£¬£¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png