¡¾Â©¶´Í¨¸æ¡¿Adobe Magento Open SourceÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-24086£©

Ðû²¼Ê±¼ä 2022-02-14



0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2022-24086

ʱ    ¼ä

2022-02-13

Àà    ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ©¶´ÏêÇé

Adobe MagentoÊÇAdobe¹«Ë¾µÄÒ»Ì׿ªÔ´µÄPHPµç×ÓÉÌÎñϵͳ£¬¸ÃϵͳÌṩȨÏÞ¹ÜÀí¡¢ËÑË÷ÒýÇæºÍÖ§¸¶Íø¹ØµÈ¹¦Ð§£¬Magento Open SourceÊÇMagentoµÄ¿ªÔ´°æ±¾¡£

2022 Äê2ÔÂ13ÈÕ£¬AdobeÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËAdobe Commerce ºÍ Magento Open SourceÖÐÓÉÓÚÊäÈëÑéÖ¤²»Í×µ¼ÖµÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-24086£©£¬ÆäCVSSv3ÆÀ·ÖΪ9.8£¬ÀÖ³ÉÀûÓôË©¶´½«µ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£

¸Ã©¶´ÎÞÐèÈÎºÎÆ¾¾Ý¼´¿É±»ÀûÓ㬵«¹¥»÷Õß±ØÐë¾ßÓйÜÀíȨÏÞ¡£AdobeÌåÏÖ´Ë©¶´ÒÑÔÚÕë¶ÔAdobe CommerceÓû§µÄÓÐÏÞ¹¥»÷Öб»ÀûÓᣠ    

 

Ó°Ï췶Χ

Adobe Commerce¡¢Magento Open Source <= 2.4.3-p1(ËùÓÐÆ½Ì¨)

Adobe Commerce¡¢Magento Open Source <= 2.3.7-p2 (ËùÓÐÆ½Ì¨)

×¢£ºAdobe Commerce <= 2.3.3°æ±¾²»ÊÜÓ°Ïì¡£

 

0x02 Äþ¾²½¨Òé

Ŀǰ´Ë©¶´ÒѾ­ÐÞ¸´£¬½¨ÒéÊÜÓ°ÏìÓû§¼°Ê±Éý¼¶¸üе½ÒÔϰ汾£º

Adobe Commerce¸üÐÂÖÁ£ºMDVA-43395_EE_2.4.3-p1_v1(ËùÓÐÆ½Ì¨)

Magento Open Source¸üÐÂÖÁ£ºMDVA-43395_EE_2.4.3-p1_v1(ËùÓÐÆ½Ì¨)

²¹¶¡ÏÂÔØÁ´½Ó£º

https://support.magento.com/hc/en-us/articles/4426353041293-Security-updates-available-for-Adobe-Commerce-APSB22-12-

 

0x03 ²Î¿¼Á´½Ó

https://helpx.adobe.com/security/products/magento/apsb22-12.html

https://thehackernews.com/2022/02/critical-magento-0-day-vulnerability.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24086

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-02-14

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 


¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png