¡¾Â©¶´Í¨¸æ¡¿AdobeÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-24086£©

Ðû²¼Ê±¼ä 2022-02-18


0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2022-24086

ʱ    ¼ä

2022-02-13

Àà    ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ©¶´ÏêÇé

Adobe MagentoÊÇAdobe¹«Ë¾µÄÒ»Ì׿ªÔ´µÄPHPµç×ÓÉÌÎñϵͳ £¬¸ÃϵͳÌṩȨÏÞ¹ÜÀí¡¢ËÑË÷ÒýÇæºÍÖ§¸¶Íø¹ØµÈ¹¦Ð§ £¬Magento Open SourceÊÇMagentoµÄ¿ªÔ´°æ±¾¡£

2022 Äê2ÔÂ13ÈÕ £¬AdobeÐû²¼Äþ¾²Í¨¸æ £¬ÐÞ¸´ÁËAdobe Commerce ºÍ Magento Open SourceÖÐÓÉÓÚÊäÈëÑéÖ¤²»Í×µ¼ÖµÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-24086£© £¬ÆäCVSSv3ÆÀ·ÖΪ9.8 £¬ÀÖ³ÉÀûÓôË©¶´½«µ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£¸Ã©¶´ÎÞÐèÈÎºÎÆ¾¾Ý¼´¿É±»ÀûÓà £¬µ«¹¥»÷Õß±ØÐë¾ßÓйÜÀíȨÏÞ¡£AdobeÌåÏÖ´Ë©¶´ÒÑÔÚÕë¶ÔAdobe CommerceÓû§µÄÓÐÏÞ¹¥»÷Öб»ÀûÓᣠ    

2ÔÂ17ÈÕ £¬Adobe¸üÐÂÄþ¾²Í¨¸æ £¬Adobe Commerce ºÍ Magento Open SourceÖдæÔÚÁíÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-24087£© £¬ÆäCVSSv3ÆÀ·ÖΪ9.8 £¬ÀÖ³ÉÀûÓôË©¶´½«µ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£

 

Ó°Ï췶Χ

Adobe Commerce¡¢Magento Open Source 2.3.3-p1 - 2.3.7-p2

Adobe Commerce¡¢Magento Open Source 2.4.0 - 2.4.3-p1

×¢£ºAdobe Commerce ºÍ Magento Open Source °æ±¾2.3.0 - 2.3.3 ²»ÊÜÓ°Ïì¡£

 

0x02 Äþ¾²½¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´ £¬½¨ÒéÊÜÓ°ÏìÓû§¼°Ê±°²×°²¹¶¡£º

ÊÜÓ°ÏìÓû§±ØÐë°²×°Á½¸ö²¹¶¡£ºÊ×ÏÈÓ¦Óà MDVA-43395 ²¹¶¡ £¬È»ºóÔÙÓ¦Óà MDVA-43443²¹¶¡¡£

ÏÂÔØÁ´½Ó£º

https://helpx.adobe.com/security/products/magento/apsb22-12.html

 

0x03 ²Î¿¼Á´½Ó

https://support.magento.com/hc/en-us/articles/4426353041293-Security-updates-available-for-Adobe-Commerce-APSB22-12-

https://helpx.adobe.com/security/products/magento/apsb22-12.html

https://thehackernews.com/2022/02/critical-magento-0-day-vulnerability.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24086

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-02-14

Ê×´ÎÐû²¼

V2.0

2022-02-18

ÐÂÔöCVE-2022-24087©¶´ÐÅÏ¢

 

0x05 ¸½Â¼

¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú¹«Ë¾½¨Á¢ÓÚ1996Äê £¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊÐ £¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ° £¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹ £¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ £¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´ £¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£


¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png