mongo-expressÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-03

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10758£¬£¬£¬£¬ £¬ £¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬ £¬ £¬CVSS·ÖÖµ£º9.9


Ó°Ïì°æ±¾


mongo-express 0.54.0֮ǰ°æ±¾


·ì϶¸ÅÊö


mongo-expressÊÇÒ»¿îÓÃÓÚ½»»¥Ê½ÖÎÀíMongoDBÊý¾Ý¿âµÄ¡¢»ùÓÚWebµÄÇáÁ¿¼¶ÖÎÀí½çÃæ¡£¡£ ¡£¡£¡£¡£


mongo-express 0.54.0֮ǰµÄ°æ±¾£¬£¬£¬£¬ £¬ £¬Í¨¹ýÈÏÖ¤ºó£¬£¬£¬£¬ £¬ £¬ÔÚÖÕ¶ËʹÓá®toBSON¡¯²½Ö裬£¬£¬£¬ £¬ £¬Äܹ»Ö´ÐÐÔ¶³ÌºÅÁ£¬£¬£¬ £¬ £¬¶ø mongo-express ĬÈϵÄÕ˺ÅÃÜÂëÊÇ admin:pass ¡£¡£ ¡£¡£¡£¡£


·ì϶ÑéÖ¤


POC£ºhttps://github.com/masahiro331/CVE-2019-10758¡£¡£ ¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬ £¬ £¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://github.com/mongo-express¡£¡£ ¡£¡£¡£¡£Éý¼¶µ½×îа棬£¬£¬£¬ £¬ £¬ÔÚconfig.jsÎļþÖÐÅäÖÃÇ¿¿ÚÁ£¬£¬£¬ £¬ £¬ÉèÖÃÊÜÐÅÀµµÄ½Ó¼ûÔ´¡£¡£ ¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://snyk.io/vuln/SNYK-JS-MONGOEXPRESS-473215