Apache DruidÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-26919£©

°ä²¼¹¦·ò 2021-03-30

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-26919

ʱ    ¼ä

2021-03-30

Àà   ÐÍ

 RCE

µÈ    ¼¶

ÖÐΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Druid <= 0.20.1

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

Apache DruidÊÇרΪ´óÊý¾Ý¼¯µÄ¼±¾çÇÐÆ¬·ÖÎö£¨OLAP²éÎÊ£©¶øÉè¼ÆµÄ¸ß»úÄÜ·ÖÎöÊý¾Ý¿â¡£

2021Äê03ÔÂ29ÈÕ £¬Apache¹Ù·½°ä²¼°²È«²¼¸æ £¬¹«¿ªÁËApache DruidÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-26919£©¡£

Druid ʹÓÃJDBC´ÓÆäËüÊý¾Ý¿â¶ÁÈ¡Êý¾Ý £¬´ËÖ°ÄÜÊÇΪÁËÈÃÊÜÐÅÀµµÄÓû§Í¨¹ýÊʵ±µÄȨÏÞÀ´ÉèÖòéÕÒ»òÌá½»ÌáÈ¡¹¤×÷¡£ÓÉÓÚApache Druid ĬÈÏÇé¿öϲ»×ãÊÚȨÈÏÖ¤ £¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâÒªÇóÖ´ÐÐËÁÒâ´úÂë £¬´Ó¶ø½ÚÔì·þÎñÆ÷¡£

 

0x02 ´ëÖý¨Òé

Ŀǰ¹Ù·½Òѽ¨¸´ÁË´Ë·ì϶ £¬½¨ÒéʵʱÉý¼¶µ½Druid 0.20.2¡£

ÏÂÔØÁ´½Ó£º

https://github.com/apache/druid/releases/tag/druid-0.20.2

 

0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202103.mbox/%3CCACZfFK6Va-CqhfDUPqPvqBCw8JsJwQ1xRe8JxeQbX5cRyi7qJg@mail.gmail.com%3E

https://github.com/apache/druid/releases/tag/druid-0.20.2

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26919

 

0x04 ¹¦·òÏß

2021-03-29  Apache°ä²¼°²È«²¼¸æ

2021-03-30  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png