mongo-expressÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-01-03Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-10758£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.9
Ó°Ïì°æ±¾
mongo-express 0.54.0֮ǰ°æ±¾
Îó²î¸ÅÊö
mongo-expressÊÇÒ»¿îÓÃÓÚ½»»¥Ê½ÖÎÀíMongoDBÊý¾Ý¿âµÄ¡¢»ùÓÚWebµÄÇáÁ¿¼¶ÖÎÀí½çÃæ¡£¡£¡£¡£¡£
mongo-express 0.54.0֮ǰµÄ°æ±¾£¬£¬£¬Í¨¹ýÈÏÖ¤ºó£¬£¬£¬ÔÚÖÕ¶ËʹÓá®toBSON¡¯ÒªÁ죬£¬£¬¿ÉÒÔÖ´ÐÐÔ¶³ÌÏÂÁ£¬£¬¶ø mongo-express ĬÈϵÄÕ˺ÅÃÜÂëÊÇ admin:pass ¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
POC£ºhttps://github.com/masahiro331/CVE-2019-10758¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://github.com/mongo-express¡£¡£¡£¡£¡£Éý¼¶µ½×îа棬£¬£¬ÔÚconfig.jsÎļþÖÐÉèÖÃÇ¿¿ÚÁ£¬£¬ÉèÖÃÊÜÐÅÈεĻá¼ûÔ´¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://snyk.io/vuln/SNYK-JS-MONGOEXPRESS-473215


¾©¹«Íø°²±¸11010802024551ºÅ