Apache Dubbo 6Ô¶à¸ö¸ßΣ©¶´

Ðû²¼Ê±¼ä 2021-06-24

0x00 ©¶´¸ÅÊö

image.png

Apache DubboÊÇÒ»¿îÓ¦Óù㷺µÄJava RPCÂþÑÜʽ·þÎñ¿ò¼Ü ¡£

2021Äê06ÔÂ22ÈÕ£¬Github SecurityLab¹ûÈ»Åû¶ÁËApache DubboÖеĶà¸ö¸ßΣ©¶´£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ô¶³ÌÖ´ÐдúÂë ¡£

 

0x01 ©¶´ÏêÇé

Ñо¿ÈËÔ±¹ûÈ»Åû¶µÄÊ®¸öÎÊÌâ±»·ÖÅäÈçÏÂCVE ID£ºCVE-2021-25641¡¢ CVE-2021-30179¡¢CVE-2021-32824¡¢CVE-2021-30180ºÍCVE-2021-30181£¬ÆäÏêÇéÈçÏ£º

Apache Dubbo Hessian2·´ÐòÁл¯Â©¶´£¨CVE-2021-25641£©

¹¥»÷Õß¿ÉÒÔÀûÓÃÆäËüЭÒéÈÆ¹ý Hessian2 ºÚÃûµ¥Ôì³É·´ÐòÁл¯Â©¶´ ¡£

 

Apache Dubbo Generic filterÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-30179£©

ÓÉÓÚApache Dubbo Generic filter¹ýÂ˲»ÑÏ£¬¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇóµ÷ÓöñÒâÒªÁì´Ó¶øÔì³ÉÈÎÒâ´úÂëÖ´ÐÐ ¡£´Ë©¶´Éæ¼°Generic filter Java ·´ÐòÁл¯£¨GHSL-2021-037£©ºÍ µ¼ÖÂRCEµÄJNDI ²éÕÒµ÷ÓÃ(GHSL-2021-038) ¡£

 

Apache Dubbo Telnet handlerÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-32824£©

Telnet handlerÌṩһЩ»ù±¾µÄÒªÁìÀ´ÊÕ¼¯ÓйطþÎñ¹ûÈ»µÄÌṩÕߺÍÒªÁìµÄÐÅÏ¢£¬ÉõÖÁ¿ÉÒÔÔÊÐí¹Ø±Õ·þÎñ ¡£Apache Dubbo Telnet handlerÔÚ´¦ÖÃÏà¹ØÇëÇóʱ£¬¹¥»÷Õß¿ÉÒÔͨ¹ýµ÷ÓöñÒâÒªÁìÔì³ÉÔ¶³Ì´úÂëÖ´ÐÐ ¡£

 

Apache Dubbo yaml·´ÐòÁл¯Â©¶´£¨CVE-2021-30180£©

Apache DubboʹÓÃÁËyaml.load´ÓÍⲿ¼ÓÔØÊý¾ÝÄÚÈݼ°ÅäÖÃÎļþ£¬¹¥»÷ÕßÔÚ¿ØÖÆÅäÖÃÖÐÐÄ£¨ÈçZookeeper¡¢Nacos µÈ£©ºó¿ÉÉÏ´«¶ñÒâÅäÖÃÎļþ£¬´Ó¶øÔì³ÉYaml·´ÐòÁл¯Â©¶´ ¡£´Ë©¶´Éæ¼°±êǩ·ÓÉÖж¾(GHSL-2021-040)¡¢Ìõ¼þ·ÓÉÖж¾£¨GHSL-2021-041£©ºÍÅäÖÃÖж¾£¨GHSL-2021-043£© ¡£

 

Apache Dubbo Nashorn ½Å±¾Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-30181£©

¹¥»÷ÕßÔÚ¿ØÖÆÅäÖÃÖÐÐÄ£¨ÈçZookeeper¡¢Nacos µÈ£©ºó¿É½á¹¹¶ñÒâÇëÇó×¢ÈëNashorn½Å±¾£¨½Å±¾Â·ÓÉÖж¾£¬GHSL-2021-042£©£¬Ôì³ÉÈÎÒâ´úÂëÖ´ÐÐ ¡£

 

Ó°Ï췶Χ

Apache Dubbo < 2.7.10

Apache Dubbo < 2.6.10

 

0x02 ´¦Öý¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´£¬½¨Ò鼰ʱÉý¼¶¸üÐÂÖÁÒÔÏ»ò¸ü¸ß°æ±¾£º

Apache Dubbo 2.7.10

Apache Dubbo 2.6.10

 

0x03 ²Î¿¼Á´½Ó

https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25641

 

0x04 ʱ¼äÏß

2021-06-22  ©¶´Åû¶

2021-06-24  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png