¡¾Îó²îͨ¸æ¡¿ApacheÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-42013£©
Ðû²¼Ê±¼ä 2021-10-080x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-42013 | ʱ ¼ä | 2021-10-07 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | 2.4.49¡¢2.4.50 |
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÔÚҰʹÓà | ÊÇ |
0x01 Îó²îÏêÇé
Apache HTTP Server ÊÇÒ»¸ö¿ªÔ´¡¢¿çƽ̨µÄ Web ЧÀÍÆ÷£¬£¬£¬£¬ËüÔÚÈ«Çò¹æÄ£ÄÚ±»ÆÕ±éʹÓᣡ£¡£¡£¡£
2021 Äê 10 Ô 7 ÈÕ£¬£¬£¬£¬Apache Èí¼þ»ù½ð»áÐû²¼ÁËApache HTTP Server 2.4.51 £¬£¬£¬£¬ÒÔÐÞ¸´ Apache HTTP Server 2.4.49 ºÍ 2.4.50 ÖеÄ·¾¶±éÀúºÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-41773¡¢CVE-2021-42013£©£¬£¬£¬£¬ÏÖÔÚÕâЩÎó²îÒѱ»ÆÕ±éʹÓᣡ£¡£¡£¡£
Apache HTTP Server·¾¶±éÀúÎó²î£¨CVE-2021-41773£©
2021Äê10ÔÂ5ÈÕ£¬£¬£¬£¬ApacheÐû²¼¸üÐÂͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËApache HTTP Server 2.4.49ÖеÄÒ»¸ö·¾¶±éÀúºÍÎļþй¶Îó²î£¨CVE-2021-41773£©¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÒÔͨ¹ý·¾¶±éÀú¹¥»÷½« URL Ó³Éäµ½Ô¤ÆÚÎĵµ¸ùĿ¼֮ÍâµÄÎļþ£¬£¬£¬£¬ÈôÊÇÎĵµ¸ùĿ¼֮ÍâµÄÎļþ²»ÊÜ¡°require all denied¡± »á¼û¿ØÖƲÎÊýµÄ±£»£»£»£»£»¤£¬£¬£¬£¬ÔòÕâЩ¶ñÒâÇëÇó¾Í»áÀֳɡ£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬¸ÃÎó²î»¹¿ÉÄܻᵼÖÂ×ß© CGI ¾ç±¾µÈÚ¹ÊÍÎļþµÄȪԴ¡£¡£¡£¡£¡£
ShodanËÑË÷ÏÔʾ£¬£¬£¬£¬È«Çò°²ÅÅÓÐÁè¼ÝÊ®Íò¸ö£¬£¬£¬£¬ÆäÖÐÐí¶àЧÀÍÆ÷ÖпÉÄܱ£´æ´ËÎó²î£¬£¬£¬£¬²¢ÇÒ´ËÎó²îÏÖÔÚÒѱ»ÆÕ±éʹÓ㬣¬£¬£¬½¨ÒéÏà¹ØÓû§¾¡¿ì¸üС£¡£¡£¡£¡£
Apache HTTP Server·¾¶±éÀúºÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-42013£©
ÓÉÓÚ¶ÔCVE-2021-41773µÄÐÞ¸´²»³ä·Ö£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓ÷¾¶±éÀú¹¥»÷£¬£¬£¬£¬½«URLÓ³Éäµ½ÓÉÀàËÆÓÖÃûµÄÖ¸ÁîÉèÖõÄĿ¼֮ÍâµÄÎļþ£¬£¬£¬£¬ÈôÊÇÕâЩĿ¼ÍâµÄÎļþûÓÐÊܵ½Ä¬ÈÏÉèÖÃ"require all denied "µÄ±£»£»£»£»£»¤£¬£¬£¬£¬ÔòÕâЩ¶ñÒâÇëÇó¾Í»áÀֳɡ£¡£¡£¡£¡£ÈôÊÇ»¹ÎªÕâЩÓÖÃû·¾¶ÆôÓÃÁË CGI ¾ç±¾£¬£¬£¬£¬ÔòÄܹ»µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Apache HTTP Server 2.4.49
Apache HTTP Server 2.4.50
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬¼øÓÚÎó²îµÄÑÏÖØÐÔ£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§Á¬Ã¦Éý¼¶¸üе½Apache HTTP Server 2.4.51£¨ÒÑÓÚ10ÔÂ7ÈÕÐû²¼£©»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://httpd.apache.org/download.cgi#apache24
0x03 ²Î¿¼Á´½Ó
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2021-42013
http://mail-archives.apache.org/mod_mbox/www-announce/202110.mbox/%3C7c4d9498-09ce-c4b4-b1c7-d55512fdc0b0@apache.org%3E
https://www.bleepingcomputer.com/news/security/apache-emergency-update-fixes-incomplete-patch-for-exploited-bug/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-10-06 | Ê×´ÎÐû²¼ |
V1.1 | 2021-10-08 | ÔöÌíCVE-2021-42013Îó²îÐÅÏ¢µÈ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º