Apache DruidÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-26919£©
°ä²¼¹¦·ò 2021-03-300x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-26919 | ʱ ¼ä | 2021-03-30 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÖÐΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Druid <= 0.20.1 |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

Apache DruidÊÇרΪ´óÊý¾Ý¼¯µÄ¼±¾çÇÐÆ¬·ÖÎö£¨OLAP²éÎÊ£©¶øÉè¼ÆµÄ¸ß»úÄÜ·ÖÎöÊý¾Ý¿â¡£
2021Äê03ÔÂ29ÈÕ£¬Apache¹Ù·½°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËApache DruidÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-26919£©¡£
Druid ʹÓÃJDBC´ÓÆäËüÊý¾Ý¿â¶ÁÈ¡Êý¾Ý£¬´ËÖ°ÄÜÊÇΪÁËÈÃÊÜÐÅÀµµÄÓû§Í¨¹ýÊʵ±µÄȨÏÞÀ´ÉèÖòéÕÒ»òÌá½»ÌáÈ¡¹¤×÷¡£ÓÉÓÚApache Druid ĬÈÏÇé¿öϲ»×ãÊÚȨÈÏÖ¤£¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâÒªÇóÖ´ÐÐËÁÒâ´úÂ룬´Ó¶ø½ÚÔì·þÎñÆ÷¡£
0x02 ´ëÖý¨Òé
Ŀǰ¹Ù·½Òѽ¨¸´ÁË´Ë·ì϶£¬½¨ÒéʵʱÉý¼¶µ½Druid 0.20.2¡£
ÏÂÔØÁ´½Ó£º
https://github.com/apache/druid/releases/tag/druid-0.20.2
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202103.mbox/%3CCACZfFK6Va-CqhfDUPqPvqBCw8JsJwQ1xRe8JxeQbX5cRyi7qJg@mail.gmail.com%3E
https://github.com/apache/druid/releases/tag/druid-0.20.2
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26919
0x04 ¹¦·òÏß
2021-03-29 Apache°ä²¼°²È«²¼¸æ
2021-03-30 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ