¡¾Îó²îͨ¸æ¡¿Apache APISIX DashboardδÊÚȨ»á¼ûÎó²î£¨CVE-2021-45232£©

Ðû²¼Ê±¼ä 2021-12-29


0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-45232

ʱ      ¼ä

2021-12-27

Àà      ÐÍ

δÊÚȨ»á¼û

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ


Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

Apache APISIXÊÇÒ»¸öʵʱ¡¢¶¯Ì¬¡¢¸ßÐÔÄܵÄAPIÍø¹Ø¡£¡£¡£¡£¡£Apache APISIX DashboardÖ¼ÔÚÈÃÓû§¾¡¿ÉÄÜÈÝÒ×µØÍ¨¹ýǰ¶Ë½çÃæÀ´²Ù×÷Apache APISIX¡£¡£¡£¡£¡£

2021Äê12ÔÂ27ÈÕ£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬Apache APISIX DashboardÖб£´æÒ»¸öδÊÚȨ»á¼ûÎó²î£¨CVE-2021-45232£©¡£¡£¡£¡£¡£

ÔÚ2.10.1֮ǰµÄApache APISIX DashboardÖУ¬£¬£¬£¬£¬Manager APIʹÓÃÁËÁ½¸ö¿ò¼Ü£¬£¬£¬£¬£¬ÔÚ¿ò¼Ü "gin "µÄ»ù´¡ÉÏÒýÈëÁË¿ò¼Ü "droplet"¡£¡£¡£¡£¡£ËùÓÐAPIºÍÈÏÖ¤ÖÐÐļþ¶¼ÊÇ»ùÓÚ¿ò¼Ü "droplet "¿ª·¢µÄ£¬£¬£¬£¬£¬µ«ÓÐЩAPIÖ±½ÓʹÓÃÁË¿ò¼Ü"gin "µÄ½Ó¿Ú£¬£¬£¬£¬£¬´Ó¶øÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬µ¼ÖÂδÊÚȨ»á¼û¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

Apache APISIX Dashboard < 2.10.1

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶¸üÐÂÖÁApache APISIX Dashboard 2.10.1°æ±¾¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/apache/apisix-dashboard/releases

»º½â²½·¥£º

¸ü¸ÄĬÈÏÓû§ÃûºÍÃÜÂ룬£¬£¬£¬£¬ÏÞÖÆÔ´IP»á¼û Apache APISIX Dashboard¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://lists.apache.org/thread/979qbl6vlm8269fopfyygnxofgqyn6k5

https://github.com/apache/apisix-dashboard/releases

https://nvd.nist.gov/vuln/detail/CVE-2021-45232

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-12-29

Ê×´ÎÐû²¼

 

0x05 ¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£

¶àÄêÀ´£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

 

¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png