¡¾Îó²îͨ¸æ¡¿Apache APISIX DashboardδÊÚȨ»á¼ûÎó²î£¨CVE-2021-45232£©

Ðû²¼Ê±¼ä 2021-12-29


0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-45232

ʱ      ¼ä

2021-12-27

Àà      ÐÍ

δÊÚȨ»á¼û

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ


Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

Apache APISIXÊÇÒ»¸öʵʱ¡¢¶¯Ì¬¡¢¸ßÐÔÄܵÄAPIÍø¹Ø¡£¡£¡£Apache APISIX DashboardÖ¼ÔÚÈÃÓû§¾¡¿ÉÄÜÈÝÒ×µØÍ¨¹ýǰ¶Ë½çÃæÀ´²Ù×÷Apache APISIX¡£¡£¡£

2021Äê12ÔÂ27ÈÕ£¬ £¬£¬ £¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬ £¬£¬ £¬Apache APISIX DashboardÖб£´æÒ»¸öδÊÚȨ»á¼ûÎó²î£¨CVE-2021-45232£©¡£¡£¡£

ÔÚ2.10.1֮ǰµÄApache APISIX DashboardÖУ¬ £¬£¬ £¬Manager APIʹÓÃÁËÁ½¸ö¿ò¼Ü£¬ £¬£¬ £¬ÔÚ¿ò¼Ü "gin "µÄ»ù´¡ÉÏÒýÈëÁË¿ò¼Ü "droplet"¡£¡£¡£ËùÓÐAPIºÍÈÏÖ¤ÖÐÐļþ¶¼ÊÇ»ùÓÚ¿ò¼Ü "droplet "¿ª·¢µÄ£¬ £¬£¬ £¬µ«ÓÐЩAPIÖ±½ÓʹÓÃÁË¿ò¼Ü"gin "µÄ½Ó¿Ú£¬ £¬£¬ £¬´Ó¶øÈƹýÉí·ÝÑéÖ¤£¬ £¬£¬ £¬µ¼ÖÂδÊÚȨ»á¼û¡£¡£¡£

 

Ó°Ïì¹æÄ£

Apache APISIX Dashboard < 2.10.1

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬ £¬£¬ £¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶¸üÐÂÖÁApache APISIX Dashboard 2.10.1°æ±¾¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/apache/apisix-dashboard/releases

»º½â²½·¥£º

¸ü¸ÄĬÈÏÓû§ÃûºÍÃÜÂ룬 £¬£¬ £¬ÏÞÖÆÔ´IP»á¼û Apache APISIX Dashboard¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://lists.apache.org/thread/979qbl6vlm8269fopfyygnxofgqyn6k5

https://github.com/apache/apisix-dashboard/releases

https://nvd.nist.gov/vuln/detail/CVE-2021-45232

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-12-29

Ê×´ÎÐû²¼

 

0x05 ¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø

ÍòÀû¹ú¼Ê¹ÙÍø¼ò½é

ÍòÀû¹ú¼Ê¹ÙÍø¹«Ë¾½¨ÉèÓÚ1996Ä꣬ £¬£¬ £¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ £¬£¬ £¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ £¬£¬ £¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ £¬£¬ £¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬ £¬£¬ £¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£

¶àÄêÀ´£¬ £¬£¬ £¬ÍòÀû¹ú¼Ê¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬ £¬£¬ £¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬ £¬£¬ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£

 

¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø

ÍòÀû¹ú¼Ê¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬ £¬£¬ £¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png