NGINX njs »º³åÇøÃýÎó·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-06-05·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12208£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
NGINXÖÐʹÓõÄnjs 0.3.1¼°Ö®Ç°°æ±¾
·ì϶¸ÅÊö
NGINXÊÇÃÀ¹úNGINX¹«Ë¾µÄÒ»¿îÇáÁ¿¼¶Web·þÎñÆ÷/·´Ïò´úÀí·þÎñÆ÷¼°µç×ÓÓʼþ£¨IMAP/POP3£©´úÀí·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£njsÊÇÆäÖеÄÒ»¸öÖ§³ÖÀ©´óNGINXÖ°Äܵľ籾˵»°×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£
NGINXÖÐʹÓõÄnjs 0.3.1¼°Ö®Ç°°æ±¾µÄnjs/njs_function.cÎļþµÄ¡®njs_function_native_call¡¯º¯Êý´æÔÚ»ùÓڶѵĻº³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬£¬£¬£¬£¬£¬£¬Î´ÕýÈ·ÑéÖ¤Êý¾ÝÌìǵ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æµØÎ»ÉÏÖ´ÐÐÁËÃýÎóµÄ¶Áд²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶µ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
POC£ºhttps://github.com/nginx/njs/issues/163¡£¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬£¬£¬£¬£¬£¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://nginx.org/ ¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ