¡¾Â©¶´Í¨¸æ¡¿Pac-ResolverÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-23406£©
Ðû²¼Ê±¼ä 2021-09-140x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-23406 | ʱ ¼ä | 2021-08-24 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | < 5.0.0 |
¹¥»÷ÅÓ´ó¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ©¶´ÏêÇé
Pac-resolverÊÇÒ»¸ö¹ã·ºÊ¹ÓõÄnpm°ü£¬¸Ã°üµÄÿÖÜÏÂÔØÁ¿Áè¼Ý300Íò´Î£¬GitHub ÉÏÓÐ285k¹«¹²ÒÀÀµ´æ´¢¿â¡£
½üÈÕ£¬Pac-resolverÖб»Åû¶´æÔÚÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-23406£©£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8¡£
ÊðÀí×Ô¶¯ÅäÖã¨PAC£©ÎļþÊÇÓà JavaScript ±àдµÄ½Å±¾£¬Ëü¾ö¶¨ÍøÂçä¯ÀÀÆ÷µÄÇëÇóÊÇÖ±½Ó·¢Ë͵½Ä¿µÄµØ»¹ÊÇת·¢µ½Ö¸¶¨Ö÷»úÃûµÄwebÊðÀí·þÎñÆ÷¡£PACÎļþÊÇÔÚÆóÒµ»·¾³Öзַ¢ÊðÀí¹æÔòµÄ·½Ê½¡£
Pac-resolver°üÓÃÓÚPac-Proxy-AgentÖеÄPACÎļþÖ§³Ö£¬¶øPac-Proxy-AgentÓÖ±»ÓÃÓÚProxy-AgentÖУ¬È»ºó±»×÷ΪNode.jsÖÐHTTPÊðÀí×Ô¶¯¼ì²âºÍÅäÖõij߶ȿÉÓðü¶ø±»¹ã·ºÊ¹Óá£Pac-resolver°ü·Ç³£ÊÜ»¶Ó£¬Proxy-Agent Ò²¼¸ºõÎÞ´¦²»ÔÚ£¬´Ó AWS µÄ CDK ¹¤¾ß°üµ½ Mailgun SDK ÔÙµ½ Firebase CLI¡£
ÓÉÓÚPac-Proxy-AgentûÓÐÕýÈ·µØ¶ÔPACÎļþ½øÐÐɳÏä´¦Ö㬵¼Ö²»ÊÜÐÅÈεÄPACÎļþ¿ÉÒÔ±»ÀÄÓ㬴ӶøÊ¹µÃ¹¥»÷Õß¿ÉÒÔÍêÈ«Í»ÆÆÉ³Ïä²¢ÔÚϵͳÉÏÔËÐÐÈÎÒâ´úÂë¡£µ«ÒªÀûÓôË©¶´£¬¹¥»÷ÕßҪôÄܹ»×¤ÁôÔÚµ±µØÍøÂçÉÏ£¬ÒªÃ´Äܹ»¸Ä¶¯ PAC ÎļþµÄÄÚÈÝ£¬ÒªÃ´¿ÉÒÔ½áºÏÆäËü©¶´¸ü¸ÄÊðÀíÅäÖá£
Ñо¿ÈËÔ±ÌåÏÖ£¬¸Ã©¶´ÊÇÕë¶ÔVM Ä£¿éµÄÖÚËùÖÜÖªµÄ¹¥»÷£¬ÒòΪNodeûÓÐÍêÈ«¸ôÀëɳÏäµÄÉÏÏÂÎÄ¡£¸Ã©¶´µÄÐÞ¸´ÒªÁìÊÇʹÓÃÕæÕýµÄɳÏä¶ø²»ÊÇVM ÄÚÖÃÄ£¿é¡£
Ó°Ï췶Χ
Pac-Resolver£¨npm£©°æ±¾ < 5.0.0
0x02 ´¦Öý¨Òé
ĿǰÒÑÔÚPac-Resolver v5.0.0¡¢Pac-Proxy-Agent v5.0.0 ºÍ Proxy-Agent v5.0.0ÖÐÐÞ¸´ÁË´Ë©¶´£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¼°Ê±Éý¼¶¸üС£
ÏÂÔØÁ´½Ó£º
https://www.npmjs.com/package/pac-resolver
´ËÍ⣬RedHatÓÚ2021Äê8ÔÂ22ÈÕÐû²¼ÁËCVE-2021-23406µÄÄþ¾²Í¨¸æ£¬ÌåÏÖRed Hat Advanced Cluster Management for Kubernetes ¸½´øÁË´æÔڸé¶´µÄ×é¼þ£¬µ«ÊÜÓ°ÏìµÄ×é¼þÊܵ½Óû§ÈÏÖ¤µÄ±£»¤£¬´Ó¶ø½µµÍÁ˸é¶´µÄDZÔÚÓ°Ïì¡£½¨ÒéÏà¹ØÓû§¼ì²ìRedHatÐû²¼µÄÄþ¾²Í¨¸æ²¢¼°Ê±ÐÞ¸´¡£
²Î¿¼Á´½Ó£º
https://access.redhat.com/security/cve/cve-2021-23406
0x03 ²Î¿¼Á´½Ó
https://httptoolkit.tech/blog/npm-pac-proxy-agent-vulnerability/
https://www.npmjs.com/package/pac-resolver
https://nvd.nist.gov/vuln/detail/CVE-2021-23406
https://thehackernews.com/2021/09/critical-bug-reported-in-npm-package.html
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-09-14 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º