¡¾Îó²îͨ¸æ¡¿CVE-2021-3129 LaravelÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2021-01-140x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-3129 | ʱ ¼ä | 2021-01-14 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Laravel <= 8.4.2 |
0x01 Îó²îÏêÇé
LaravelÊÇÒ»Ì×¾«Á·¡¢¿ªÔ´µÄPHP Web¿ª·¢¿ò¼Ü£¬£¬£¬£¬Ö¼ÔÚʵÏÖWebÈí¼þµÄMVC¼Ü¹¹¡£¡£¡£¡£
2021Äê01ÔÂ12ÈÕ£¬£¬£¬£¬Laravel±»Åû¶±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-3129£©¡£¡£¡£¡£
µ±Laravel¿ªÆôÁËDebugģʽʱ£¬£¬£¬£¬ÓÉÓÚLaravel×Ô´øµÄIgnition ×é¼þ¶Ôfile_get_contents()ºÍfile_put_contents()º¯ÊýµÄ²»Ç徲ʹÓ㬣¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÌᳫ¶ñÒâÇëÇ󣬣¬£¬£¬½á¹¹¶ñÒâLogÎļþµÈ·½·¨´¥·¢Phar·´ÐòÁл¯£¬£¬£¬£¬×îÖÕÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£
×èÖ¹ÏÖÔÚ£¬£¬£¬£¬Ê¹ÓÃZoomeyeËÑË÷£¬£¬£¬£¬È«Çò¹²ÓÐ193851¸öÍøÕ¾ÕýÔÚʹÓÃLaravel¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Laravel <= 8.4.2
Ignition <2.5.2
0x02 ´¦Öóͷ£½¨Òé
½¨Ò齫 Laravel ¿ò¼ÜÉý¼¶ÖÁ8.4.3¼°ÒÔÉϰ汾£¬£¬£¬£¬»ò½« Ignition×é¼þÉý¼¶ÖÁ 2.5.2 ¼°ÒÔÉϰ汾¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://laravel.com/docs/8.x#laravel-the-fullstack-framework
0x03 ²Î¿¼Á´½Ó
https://github.com/facade/ignition/pull/334
https://www.tenable.com/cve/CVE-2021-3129
https://www.ambionics.io/blog/laravel-debug-rce
0x04 ʱ¼äÏß
2021-01-12 Ambionics SecurityÅû¶Îó²î
2021-01-14 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/