Apache Traffic Server¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-06-300x00 Îó²î¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | ÐÎò | Îó²îÆ·¼¶ | Ô¶³ÌʹÓà |
Apache Traffic Server | CVE-2021-27577 | »º´æÖж¾ | ÖÐΣ | ÊÇ |
CVE-2021-32565 | HTTPÇëÇó×ß˽ | ÖÐΣ | ||
CVE-2021-32566 | Dos | ¸ßΣ | ||
CVE-2021-32567 | ƵÈÔ¶ÁÈ¡ | ÖÐΣ | ||
CVE-2021-35474 | ¿ÍÕ»»º³åÇøÒç³ö | ¸ßΣ |
0x01 Îó²îÏêÇé
Apache Traffic Server? £¨ATS£©Èí¼þÊÇÒ»ÖÖ¿ìËÙ¡¢¿ÉÀ©Õ¹µÄHTTP/1.1 ºÍ HTTP/2 ¼æÈݵĿªÔ´Web»º´æÊðÀíЧÀÍÆ÷£¬£¬£¬ÏÖΪApache Èí¼þ»ù½ð»áµÄ¶¥¼¶ÏîÄ¿¡£¡£¡£
¿ËÈÕ£¬£¬£¬Apache Traffic Server±»Åû¶±£´æ¶à¸öÇå¾²Îó²î£¬£¬£¬Õ⽫µ¼ÖÂATSÈÝÒ×Êܵ½ÖÖÖÖ HTTP/1.x ºÍ HTTP/2 ¹¥»÷¡£¡£¡£
±¾´ÎÅû¶µÄÎó²î°üÀ¨£º
CVE-2021-27577£ºApache Traffic ServerµÄurlƬ¶Ï´¦Öóͷ£¹ýʧµ¼Ö»º´æÖж¾£¨ÖÐΣ£©
CVE-2021-32565£ºÍ¨¹ý½ç˵Content-Length×Ö¶ÎʵÏÖHTTPÇëÇó×ß˽£¨ÖÐΣ£©
CVE-2021-32566£ºHTTP/2 Ö¡µÄÌØ¶¨ÐòÁпÉÄܵ¼Ö ATS Í߽⣨¸ßΣ£©
CVE-2021-32567£º¶à´Î¶ÁÈ¡ HTTP/2 Ö¡£¡£¡£¨ÖÐΣ£©
CVE-2021-35474£ºcachekey²å¼þÖеĶ¯Ì¬¿ÍÕ»»º³åÇøÒç³ö£¨¸ßΣ£©
Ó°Ïì¹æÄ£
ATS 7.0.0 - 7.1.12
ATS 8.0.0 - 8.1.1
ATS 9.0.0 - 9.0.1
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º
7.x Óû§£ºÉý¼¶µ½ 8.1.2 »ò 9.0.2 »ò¸ü¸ß°æ±¾
8.x Óû§£ºÉý¼¶µ½ 8.1.2 »ò¸ü¸ß°æ±¾
9.x Óû§£ºÉý¼¶µ½ 9.0.2 »ò¸ü¸ß°æ±¾
ÏÂÔØÁ´½Ó£º
https://trafficserver.apache.org/downloads
0x03 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cannounce.trafficserver.apache.org%3E
https://trafficserver.apache.org/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32565
0x04 ʱ¼äÏß
2021-06-24 Îó²îÅû¶
2021-06-30 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/