¡¾Îó²îͨ¸æ¡¿CVE-2020-10148 SolarWinds Orion RCEÎó²î
Ðû²¼Ê±¼ä 2020-12-280x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-10148 | ʱ ¼ä | 2020-12-28 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ |
0x01 Îó²îÏêÇé
SolarWinds Orion PlatformÊÇ»ù´¡ÉèÊ©ºÍϵͳÖÎÀí²úÆ·Ì×¼þ¡£¡£¡£¡£SolarWinds Orion API±»Ç¶Èëµ½OrionÄÚºËÖУ¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÓëËùÓÐSolarWinds Orionƽ̨²úÆ·¾ÙÐÐÅþÁ¬¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬SolarWinds Orion APIÖб»Åû¶±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-10148£©¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚSolarWinds Orion APIÉí·ÝÑéÖ¤Äܹ»±»Èƹý£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚRequest.PathInfo URIÇëÇóÖÐʹÓÃÌØ¶¨²ÎÊýÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬×îÖÕ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐδ¾Éí·ÝÑéÖ¤µÄAPIÏÂÁî¡£¡£¡£¡£ÓÈÆäÊǵ±¹¥»÷Õ߸½¼ÓÒ»¸öPathInfoº¯ÊýµÄ²ÎÊýΪWebResource.adx¡¢ScriptResource.adx¡¢i18n.ashx¡¢»òSkipi18nµÄÇëÇó¸øSolarWinds OrionЧÀÍÆ÷ʱ£¬£¬£¬£¬£¬£¬£¬SolarWinds¿ÉÒÔÉèÖÃSkipAuthorization flag£¬£¬£¬£¬£¬£¬£¬ÕâÑù¿ÉÒÔÔÚ²»ÐèÒªÉí·ÝÑéÖ¤µÄÇéÐÎÏ´¦Öóͷ£APIÇëÇ󡣡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬SolarWindsÒѾÐû²¼ÁË´ËÎó²îµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬½¨Ò齫SolarWinds Orion¸üÐÂÖÁÈçϰ汾£º
2019.4 HF 6£¨2020Äê12ÔÂ14ÈÕÐû²¼£©
2020.2.1 HF 2£¨2020Äê12ÔÂ15ÈÕÐû²¼£©
2019.2 SUPERNOVA²¹¶¡£¡£¡£¡£¨2020Äê12ÔÂ23ÈÕÐû²¼£©
2018.4 SUPERNOVA²¹¶¡£¡£¡£¡£¨2020Äê12ÔÂ23ÈÕÐû²¼£©
2018.2 SUPERNOVA²¹¶¡£¡£¡£¡£¨2020Äê12ÔÂ23ÈÕÐû²¼£©
ÏÂÔØÁ´½Ó£º
https://www.solarwinds.com/securityadvisory
0x03 ²Î¿¼Á´½Ó
https://kb.cert.org/vuls/id/843464
https://github.com/solarwinds/OrionSDK/wiki
https://cyber.dhs.gov/ed/21-01/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10148
0x04 ʱ¼äÏß
2020-12-26 CERT/CCÅû¶Îó²î
2020-12-27 CERT/CC¸üÐÂÎó²î
2020-12-28 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/