Node.jsÏÂÁî×¢ÈëÎó²î£¨CVE-2021-21315£©
Ðû²¼Ê±¼ä 2021-02-250x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-21315 | ʱ ¼ä | 2021-02-25 |
Àà ÐÍ | ÏÂÁî×¢Èë | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Systeminformation < 5.3.1 |
0x01 Îó²îÏêÇé
Node.js-systeminformationÊÇÓÃÓÚ»ñÈ¡ÖÖÖÖϵͳÐÅÏ¢µÄNode.JSÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬Ëü°üÀ¨¶àÖÖÇáÁ¿¼¶¹¦Ð§£¬£¬£¬£¬¿ÉÒÔ¼ìË÷ÏêϸµÄÓ²¼þºÍϵͳÏà¹ØÐÅÏ¢¡£¡£¡£¡£¡£¡£×ÔÐû²¼ÖÁ½ñ£¬£¬£¬£¬systeminformationÈí¼þ°üÏÂÔØ´ÎÊý½ü3400Íò¡£¡£¡£¡£¡£¡£
2021Äê02ÔÂ24ÈÕ£¬£¬£¬£¬npmÍŶÓÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬Node.js¿âÖеÄsysteminformationÈí¼þ°üÖб£´æÒ»¸öÏÂÁî×¢ÈëÎó²î£¨CVE-2021-21315£©£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.8¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚδ¾ÓÉÂ˵IJÎÊýÖÐ×¢ÈëPayloadÀ´Ö´ÐÐϵͳÏÂÁî¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѾÔÚ5.3.1°æ±¾ÖÐÐÞ¸´£¬£¬£¬£¬¸Ã°æ±¾µÄÐÞ¸´³ÌÐò¿ÉÒÔ׼ȷÕûÀíºÍÑéÖ¤²ÎÊý£¬£¬£¬£¬ÈçÏÂËùʾ£º
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬£¬£¬½¨Ò齫systeminformationʵʱÉý¼¶µ½5.3.1»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.npmjs.com/package/systeminformation
»º½â²½·¥
ÈôÊÇÎÞ·¨Éý¼¶£¬£¬£¬£¬¿ÉÒÔ¼ì²é»òÕûÀíת´ï¸øsi.inetLatency()¡¢si.inetChecksite()¡¢si.services()¡¢si.processLoad()µÄ²ÎÊý£¬£¬£¬£¬Ö»ÔÊÐíʹÓÃstring£¬£¬£¬£¬¾Ü¾øÈκÎÊý×é¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.npmjs.com/advisories/1628
https://www.bleepingcomputer.com/news/security/heavily-used-nodejs-package-has-a-code-injection-vulnerability/
https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2m8v-572m-ff2v
0x04 ʱ¼äÏß
2021-02-24 npmÐû²¼Ç徲ͨ¸æ
2021-02-25 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/