Node.jsÏÂÁî×¢ÈëÎó²î£¨CVE-2021-21315£©

Ðû²¼Ê±¼ä 2021-02-25

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-21315

ʱ   ¼ä

2021-02-25

Àà   ÐÍ

ÏÂÁî×¢Èë

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Systeminformation <   5.3.1

 

0x01 Îó²îÏêÇé

image.png

 

Node.js-systeminformationÊÇÓÃÓÚ»ñÈ¡ÖÖÖÖϵͳÐÅÏ¢µÄNode.JSÄ£¿£¿£¿£¿£¿£¿£¿é £¬£¬£¬£¬Ëü°üÀ¨¶àÖÖÇáÁ¿¼¶¹¦Ð§ £¬£¬£¬£¬¿ÉÒÔ¼ìË÷ÏêϸµÄÓ²¼þºÍϵͳÏà¹ØÐÅÏ¢¡£¡£¡£¡£¡£¡£×ÔÐû²¼ÖÁ½ñ £¬£¬£¬£¬systeminformationÈí¼þ°üÏÂÔØ´ÎÊý½ü3400Íò¡£¡£¡£¡£¡£¡£

2021Äê02ÔÂ24ÈÕ £¬£¬£¬£¬npmÍŶÓÐû²¼Ç徲ͨ¸æ £¬£¬£¬£¬Node.js¿âÖеÄsysteminformationÈí¼þ°üÖб£´æÒ»¸öÏÂÁî×¢ÈëÎó²î£¨CVE-2021-21315£© £¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.8¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚδ¾­ÓÉÂ˵IJÎÊýÖÐ×¢ÈëPayloadÀ´Ö´ÐÐϵͳÏÂÁî¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѾ­ÔÚ5.3.1°æ±¾ÖÐÐÞ¸´ £¬£¬£¬£¬¸Ã°æ±¾µÄÐÞ¸´³ÌÐò¿ÉÒÔ׼ȷÕûÀíºÍÑéÖ¤²ÎÊý £¬£¬£¬£¬ÈçÏÂËùʾ£º

image.png

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´ £¬£¬£¬£¬½¨Ò齫systeminformationʵʱÉý¼¶µ½5.3.1»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.npmjs.com/package/systeminformation

 

»º½â²½·¥

ÈôÊÇÎÞ·¨Éý¼¶ £¬£¬£¬£¬¿ÉÒÔ¼ì²é»òÕûÀíת´ï¸øsi.inetLatency()¡¢si.inetChecksite()¡¢si.services()¡¢si.processLoad()µÄ²ÎÊý £¬£¬£¬£¬Ö»ÔÊÐíʹÓÃstring £¬£¬£¬£¬¾Ü¾øÈκÎÊý×é¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.npmjs.com/advisories/1628

https://www.bleepingcomputer.com/news/security/heavily-used-nodejs-package-has-a-code-injection-vulnerability/

https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2m8v-572m-ff2v

 

0x04 ʱ¼äÏß

2021-02-24  npmÐû²¼Ç徲ͨ¸æ

2021-02-25  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png