NginxÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-23017£©
Ðû²¼Ê±¼ä 2021-05-270x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-23017 | ʱ ¼ä | 2021-05-27 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | Nginx 0.6.18 - 1.20.0 |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
NginxÊÇÒ»¸ö¸ßÐÔÄܵÄHTTPºÍ·´ÏòÊðÀíweb·þÎñÆ÷£¬Í¬Ê±Ò²ÌṩÁËIMAP/POP3/SMTP·þÎñ£¬ÓÉÓÚÆä¾ßÓÐÐí¶àÓÅÔ½µÄÌØÐÔ£¬µ¼ÖÂÔÚÈ«Çò·¶Î§ÄÚ±»¹ã·ºÊ¹Óá£
2021Äê05ÔÂ25ÈÕ£¬Nginx¹Ù·½Ðû²¼Äþ¾²Í¨¸æ£¬¹ûÈ»ÁËNginx DNS ResolverÖеÄÒ»¸öÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-23017£©¡£
ÓÉÓÚNginxÔÚ´¦ÖÃDNSÏìӦʱ´æÔÚÄþ¾²ÎÊÌ⣬µ±ÔÚÅäÖÃÎļþÖÐʹÓà ¡°resolver ¡±Ö¸Áîʱ£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýαÔìÀ´×ÔDNS·þÎñÆ÷µÄUDPÊý¾Ý°ü£¬½á¹¹DNSÏìÓ¦Ôì³É1-byteÄÚ´æÁýÕÖ£¬´Ó¶øµ¼Ö¾ܾø·þÎñ»òÈÎÒâ´úÂëÖ´ÐС£
¸Ã©¶´½öÔÚÅäÖÃÁËÒ»¸ö»ò¶à¸ö¡°resolver¡±Ö¸ÁîµÄÇé¿öÏ´æÔÚ£¬¶øÄ¬ÈÏÇé¿öÏÂûÓÐÅäÖá£
0x02 ´¦Öý¨Òé
Ŀǰ¸Ã©¶´ÒÑÔÚÒÔϰ汾ÖÐÐÞ¸´£¬½¨Ò龡¿ì½øÐÐÉý¼¶¸üУº
NGINX Open Source 1.20.1 (stable)
NGINX Open Source 1.21.0 (mainline)
NGINX Plus R23 P1
NGINX Plus R24 P1
ÒÔϰ汾µÄNGINX Ingress Controller°üÂÞNGINX Open SourceºÍNGINX PlusµÄÐÞ¸´·¨Ê½°æ±¾£º
NGINX Ingress Controller 1.11.2 ¨C NGINX Plus R23 P1
NGINX Ingress Controller 1.11.3 ¨C NGINX Open Source 1.21.0 ºÍNGINX Plus R23 P1
ÏÂÔØÁ´½Ó£º
http://nginx.org/en/download.html
²¹¶¡Á´½Ó£º
http://nginx.org/download/patch.2021.resolver.txt
0x03 ²Î¿¼Á´½Ó
http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html
https://www.nginx.com/blog/updating-nginx-dns-resolver-vulnerability-cve-2021-23017/
https://support.f5.com/csp/article/K12331123
0x04 ʱ¼äÏß
2021-05-25 NginxÐû²¼Äþ¾²Í¨¸æ
2021-05-27 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/