Apache DruidÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-25646£©

°ä²¼¹¦·ò 2021-02-01

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-25646

ʱ  ¼ä

2021-02-01

Àà   ÐÍ

RCE

µÈ  ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Apache Druid <= 0.20.0

 

0x01 ·ì϶ÏêÇé

image.png

 

Apache DruidÊÇרΪ´óÊý¾Ý¼¯µÄ¼±¾çÇÐÆ¬·ÖÎö£¨OLAP²éÎÊ£©¶øÉè¼ÆµÄ¸ß»úÄÜʵʱ³½ÎöÊý¾Ý¿â¡£

2021Äê01ÔÂ30ÈÕ£¬Apache¹Ù·½°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËDruidÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-25646£©¡£

Apache Druid¿ÉÄÜÖ´ÐÐǶÈëÔÚ¸÷ÖÖÀàÐ͵ÄÒªÇóÖеÄÓû§ÌṩµÄJavaScript´úÂ룬ĬÈÏÇé¿öϸÃÖ°ÄÜÊǽûÓõÄ¡£µ«ÔÚDruid 0.20.0¼°Ö®Ç°µÄ°æ±¾ÖУ¬²»ÂÛ¸ÃÖ°ÄÜÊÇ·ñÆôÓ㬾­¹ýÈÏÖ¤µÄÓû§Äܹ»·¢ËͶñÒâÒªÇóÀ´Ê¹DruidÇ¿ÔìÔËÐиÃÒªÇóÖеÄJavaScript´úÂ룬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÀûÓÃDruidȨÏÞÔÚÖ¸±êϵͳÉÏÖ´ÐдúÂë¡£

  

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶Òѱ»½¨¸´£¬½¨ÒéÉý¼¶ÖÁDruid 0.20.1¡£

ÏÂÔØÁ´½Ó£º

http://druid.apache.org/downloads.html

 

 

0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202101.mbox/%3CCACZfFK7WRWOfZ_3cZxXVE2nnGj73bBMBhND5gF=LzBeyfGxvpA@mail.gmail.com%3E

https://lists.apache.org/thread.html/rfda8a3aa6ac06a80c5cbfdeae0fc85f88a5984e32ea05e6dda46f866%40%3Cdev.druid.apache.org%3E

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25646

 

0x04 ¹¦·òÏß

2021-01-30  Apache°ä²¼°²È«²¼¸æ

2021-02-01  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png