Apache Dubbo 6Ô¶à¸ö¸ßΣÎó²î

Ðû²¼Ê±¼ä 2021-06-24

0x00 Îó²î¸ÅÊö

image.png

Apache DubboÊÇÒ»¿îÓ¦ÓÃÆÕ±éµÄJava RPCÂþÑÜʽЧÀÍ¿ò¼Ü¡£¡£¡£

2021Äê06ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬Github SecurityLab¹ûÕæÅû¶ÁËApache DubboÖеĶà¸ö¸ßΣÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£

 

0x01 Îó²îÏêÇé

Ñо¿Ö°Ô±¹ûÕæÅû¶µÄÊ®¸öÎÊÌâ±»·ÖÅÉÈçÏÂCVE ID£ºCVE-2021-25641¡¢ CVE-2021-30179¡¢CVE-2021-32824¡¢CVE-2021-30180ºÍCVE-2021-30181£¬£¬£¬£¬£¬£¬£¬ÆäÏêÇéÈçÏ£º

Apache Dubbo Hessian2·´ÐòÁл¯Îó²î£¨CVE-2021-25641£©

¹¥»÷Õß¿ÉÒÔʹÓÃÆäËüЭÒéÈÆ¹ý Hessian2 ºÚÃûµ¥Ôì³É·´ÐòÁл¯Îó²î¡£¡£¡£

 

Apache Dubbo Generic filterÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-30179£©

ÓÉÓÚApache Dubbo Generic filter¹ýÂ˲»ÑÏ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇóŲÓöñÒâÒªÁì´Ó¶øÔì³Éí§Òâ´úÂëÖ´ÐС£¡£¡£´ËÎó²îÉæ¼°Generic filter Java ·´ÐòÁл¯£¨GHSL-2021-037£©ºÍ µ¼ÖÂRCEµÄJNDI ²éÕÒŲÓÃ(GHSL-2021-038)¡£¡£¡£

 

Apache Dubbo Telnet handlerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-32824£©

Telnet handlerÌṩһЩ»ù±¾µÄÒªÁìÀ´ÍøÂçÓйØÐ§À͹ûÕæµÄÌṩÕߺÍÒªÁìµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÒÔÔÊÐí¹Ø±ÕЧÀÍ¡£¡£¡£Apache Dubbo Telnet handlerÔÚ´¦Öóͷ£Ïà¹ØÇëÇóʱ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýŲÓöñÒâÒªÁìÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£

 

Apache Dubbo yaml·´ÐòÁл¯Îó²î£¨CVE-2021-30180£©

Apache DubboʹÓÃÁËyaml.load´ÓÍⲿ¼ÓÔØÊý¾ÝÄÚÈݼ°ÉèÖÃÎļþ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ¿ØÖÆÉèÖÃÖÐÐÄ£¨ÈçZookeeper¡¢Nacos µÈ£©ºó¿ÉÉÏ´«¶ñÒâÉèÖÃÎļþ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔì³ÉYaml·´ÐòÁл¯Îó²î¡£¡£¡£´ËÎó²îÉæ¼°±êǩ·ÓÉÖж¾(GHSL-2021-040)¡¢Ìõ¼þ·ÓÉÖж¾£¨GHSL-2021-041£©ºÍÉèÖÃÖж¾£¨GHSL-2021-043£©¡£¡£¡£

 

Apache Dubbo Nashorn ¾ç±¾Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-30181£©

¹¥»÷ÕßÔÚ¿ØÖÆÉèÖÃÖÐÐÄ£¨ÈçZookeeper¡¢Nacos µÈ£©ºó¿É½á¹¹¶ñÒâÇëÇó×¢ÈëNashorn¾ç±¾£¨¾ç±¾Â·ÓÉÖж¾£¬£¬£¬£¬£¬£¬£¬GHSL-2021-042£©£¬£¬£¬£¬£¬£¬£¬Ôì³Éí§Òâ´úÂëÖ´ÐС£¡£¡£

 

Ó°Ïì¹æÄ£

Apache Dubbo < 2.7.10

Apache Dubbo < 2.6.10

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üÐÂÖÁÒÔÏ»ò¸ü¸ß°æ±¾£º

Apache Dubbo 2.7.10

Apache Dubbo 2.6.10

 

0x03 ²Î¿¼Á´½Ó

https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25641

 

0x04 ʱ¼äÏß

2021-06-22  Îó²îÅû¶

2021-06-24  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png