Apache DruidÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-25646£©
Ðû²¼Ê±¼ä 2021-02-010x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-25646 | ʱ ¼ä | 2021-02-01 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache Druid <= 0.20.0 |
0x01 Îó²îÏêÇé
Apache DruidÊÇרΪ´óÊý¾Ý¼¯µÄ¿ìËÙÇÐÆ¬ÆÊÎö£¨OLAPÅÌÎÊ£©¶øÉè¼ÆµÄ¸ßÐÔÄÜʵʱÆÊÎöÊý¾Ý¿â¡£¡£¡£¡£
2021Äê01ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬¹ûÕæÁËDruidÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-25646£©¡£¡£¡£¡£
Apache DruidÄܹ»Ö´ÐÐǶÈëÔÚÖÖÖÖÀàÐ͵ÄÇëÇóÖеÄÓû§ÌṩµÄJavaScript´úÂ룬£¬£¬£¬£¬£¬Ä¬ÈÏÇéÐÎϸù¦Ð§ÊǽûÓõġ£¡£¡£¡£µ«ÔÚDruid 0.20.0¼°Ö®Ç°µÄ°æ±¾ÖУ¬£¬£¬£¬£¬£¬²»¹Ü¸Ã¹¦Ð§ÊÇ·ñÆôÓ㬣¬£¬£¬£¬£¬¾ÓÉÈÏÖ¤µÄÓû§¿ÉÒÔ·¢ËͶñÒâÇëÇóÀ´Ê¹DruidÇ¿ÖÆÔËÐиÃÇëÇóÖеÄJavaScript´úÂ룬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃDruidȨÏÞÔÚÄ¿µÄϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁDruid 0.20.1¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
http://druid.apache.org/downloads.html
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202101.mbox/%3CCACZfFK7WRWOfZ_3cZxXVE2nnGj73bBMBhND5gF=LzBeyfGxvpA@mail.gmail.com%3E
https://lists.apache.org/thread.html/rfda8a3aa6ac06a80c5cbfdeae0fc85f88a5984e32ea05e6dda46f866%40%3Cdev.druid.apache.org%3E
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25646
0x04 ʱ¼äÏß
2021-01-30 ApacheÐû²¼Ç徲ͨ¸æ
2021-02-01 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/