Apache Dubbo 6Ô¶à¸ö¸ßΣ·ì϶

°ä²¼¹¦·ò 2021-06-24

0x00 ·ì϶¸ÅÊö

image.png

Apache DubboÊÇÒ»¿îÀûÓÃ¿í·ºµÄJava RPCÉ¢²¼Ê½·þÎñ¿ò¼Ü ¡£¡£¡£¡£¡£¡£¡£

2021Äê06ÔÂ22ÈÕ£¬£¬ £¬£¬£¬£¬£¬Github SecurityLab¹«¿ªÅû¶ÁËApache DubboÖеĶà¸ö¸ßΣ·ì϶£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Զ³ÌÖ´ÐдúÂë ¡£¡£¡£¡£¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

×êÑÐÈËÔ±¹«¿ªÅû¶µÄÊ®¸öÎÊÌâ±»·ÖÅäÈçÏÂCVE ID£ºCVE-2021-25641¡¢ CVE-2021-30179¡¢CVE-2021-32824¡¢CVE-2021-30180ºÍCVE-2021-30181£¬£¬ £¬£¬£¬£¬£¬ÆäÏêÇéÈçÏ£º

Apache Dubbo Hessian2·´ÐòÁл¯·ì϶£¨CVE-2021-25641£©

¹¥»÷ÕßÄܹ»ÀûÓÃÆäËüºÍÌ¸ÈÆ¹ý Hessian2 ºÚÃûµ¥Ôì³É·´ÐòÁл¯·ì϶ ¡£¡£¡£¡£¡£¡£¡£

 

Apache Dubbo Generic filterÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-30179£©

ÓÉÓÚApache Dubbo Generic filter¹ýÂ˲»ÑÏ£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õ߿ɻú¹Ø¶ñÒâÒªÇóŲÓöñÒâ²½Öè´Ó¶øÔì³ÉËÁÒâ´úÂëÖ´ÐÐ ¡£¡£¡£¡£¡£¡£¡£´Ë·ìÏ¶Éæ¼°Generic filter Java ·´ÐòÁл¯£¨GHSL-2021-037£©ºÍ µ¼ÖÂRCEµÄJNDI ²éÕÒŲÓÃ(GHSL-2021-038) ¡£¡£¡£¡£¡£¡£¡£

 

Apache Dubbo Telnet handlerÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-32824£©

Telnet handlerÌṩһЩ¸ù»ùµÄ²½ÖèÀ´ÍøÂçÓйطþÎñ¹«¿ªµÄÌṩÕߺͲ½ÖèµÄÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬ÉõÖÁÄܹ»ÔÊÐí¹Ø¹Ø·þÎñ ¡£¡£¡£¡£¡£¡£¡£Apache Dubbo Telnet handlerÔÚ´¦ÖÃÓйØÒªÇóʱ£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýŲÓöñÒâ²½ÖèÔì³ÉÔ¶³Ì´úÂëÖ´ÐÐ ¡£¡£¡£¡£¡£¡£¡£

 

Apache Dubbo yaml·´ÐòÁл¯·ì϶£¨CVE-2021-30180£©

Apache DubboʹÓÃÁËyaml.load´Ó±í²¿¼ÓÔØÊý¾ÝÄÚÈݼ°ÅäÖÃÎļþ£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ½ÚÔìÅäÖÃÖÐÐÄ£¨ÈçZookeeper¡¢Nacos µÈ£©ºó¿ÉÉÏ´«¶ñÒâÅäÖÃÎļþ£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÔì³ÉYaml·´ÐòÁл¯·ì϶ ¡£¡£¡£¡£¡£¡£¡£´Ë·ìÏ¶Éæ¼°±êǩ·ÓÉÖж¾(GHSL-2021-040)¡¢Ç°Ìá·ÓÉÖж¾£¨GHSL-2021-041£©ºÍÅäÖÃÖж¾£¨GHSL-2021-043£© ¡£¡£¡£¡£¡£¡£¡£

 

Apache Dubbo Nashorn ¾ç±¾Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-30181£©

¹¥»÷ÕßÔÚ½ÚÔìÅäÖÃÖÐÐÄ£¨ÈçZookeeper¡¢Nacos µÈ£©ºó¿É»ú¹Ø¶ñÒâÒªÇó×¢ÈëNashorn¾ç±¾£¨¾ç±¾Â·ÓÉÖж¾£¬£¬ £¬£¬£¬£¬£¬GHSL-2021-042£©£¬£¬ £¬£¬£¬£¬£¬Ôì³ÉËÁÒâ´úÂëÖ´ÐÐ ¡£¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

Apache Dubbo < 2.7.10

Apache Dubbo < 2.6.10

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´£¬£¬ £¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üÐÂÖÁÒÔÏ»ò¸ü¸ß°æ±¾£º

Apache Dubbo 2.7.10

Apache Dubbo 2.6.10

 

0x03 ²Î¿¼Á´½Ó

https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25641

 

0x04 ¹¦·òÏß

2021-06-22  ·ì϶Åû¶

2021-06-24  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png