Palo Alto Networks Cortex XSOARδÊÚȨ½Ó¼û·ì϶£¨CVE-2021-3044£©

°ä²¼¹¦·ò 2021-06-23

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2021-3044

ʱ    ¼ä

2021-06-23

Àà    ÐÍ

δÊÚȨ½Ó¼û

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

Cortex? XSOARÊÇÈ«ÇòÍøÂ簲ȫ¸¨µ¼ÆóÒµPalo Alto NetworksÍÆ³öµÄÒ»¸öÈ«ÐÂÀ©´óµÄ°²È«±àÅÅ¡¢×Ô¶¯»¯ÓëÏìӦƽ̨£¬£¬£¬£¬£¬£¬£¬²¢¼¯³ÉÁËÍþвµý±¨ÖÎÀíÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÎªÆóÒµ°²È«Ìṩ¼´Ê±¡¢È«ÃæµÄÍþв·ÀÓù¡£¡£¡£¡£¡£¡£¡£ ¡£

2021Äê06ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬Palo Alto Networks°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËCortex XSOARÖеÄÒ»¸öδÊÚȨ½Ó¼û·ì϶£¨CVE-2021-3044£©£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£ ¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ͨ¹ýREST APIÖ´ÐÐδ¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£ ¡£

¸Ã·ì϶½ö´æÔÚÓÚÅäÖÃÁ˻µÄ¼¯³ÉAPI KeyµÄCortex XSOAR¡£¡£¡£¡£¡£¡£¡£ ¡£¿£¿£¿£¿£Äܹ»´ÓCortex XSOAR Web ¿Í»§¶ËÑ¡Ôñ¡®Settings > Integration > API Keys¡¯ À´²é¿´ÅäÖÃÊÇ·ñÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ ¡£


Ó°ÏìÁìÓò

Cortex XSOAR 6.1.0£ºbuilds >= 1016923 and < 1271064

Cortex XSOAR 6.2.0£ºbuilds < 1271065

 

0x02 ´ëÖý¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´£¬£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¸üС£¡£¡£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÓÉPalo Alto NetworksÍйܵÄËùÓÐCortex XSOARÊ·ý¶¼ÒÑÉý¼¶£¬£¬£¬£¬£¬£¬£¬²»±ØÒªÔÙÖ´ÐÐÆäËü²Ù×÷¡£¡£¡£¡£¡£¡£¡£ ¡£

°æ±¾

ÊÜÓ°Ïì°æ±¾

²»ÊÜÓ°Ïì°æ±¾

Cortex XSOAR 6.2.0

< 1271065

>= 1271065

Cortex XSOAR 6.1.0

>= 1016923 and < 1271064

< 1016923£¬£¬£¬£¬£¬£¬£¬ >= 1271064

Cortex XSOAR 6.0.2

None

all

Cortex XSOAR 6.0.1

None

all

Cortex XSOAR 6.0.0

None

all

Cortex XSOAR 5.5.0

None

all

 

ÏÂÔØÁ´½Ó£º

https://support.paloaltonetworks.com/support

 

»º½â´ëÊ©

³·ÏúËùÓлµÄ¼¯³É API Key£¬£¬£¬£¬£¬£¬£¬´ÓCortex XSOAR web ¿Í»§¶ËµÄSettings > Integration > API Keys£¬£¬£¬£¬£¬£¬£¬¶øºó³·Ïúÿ¸öAPI Key¡£¡£¡£¡£¡£¡£¡£ ¡£¿£¿£¿£¿£Äܹ»½«Cortex XSOARÉý¼¶µ½¹Ì¶¨°æ±¾ºó´´½¨ÐµÄAPI Key¡£¡£¡£¡£¡£¡£¡£ ¡£

Ï޶ȶÔCortex XSOAR·þÎñÆ÷µÄÍøÂç½Ó¼û£¬£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÊÜÐÅÀµµÄÓû§½Ó¼û¡£¡£¡£¡£¡£¡£¡£ ¡£

 

0x03 ²Î¿¼Á´½Ó

https://security.paloaltonetworks.com/CVE-2021-3044

https://security.paloaltonetworks.com/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044

 

0x04 ¹¦·òÏß

2021-06-22  Palo Alto Networks°ä²¼°²È«²¼¸æ

2021-06-23  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png