mongo-expressÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-01-03

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10758£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.9


Ó°Ïì°æ±¾


mongo-express 0.54.0֮ǰ°æ±¾


Îó²î¸ÅÊö


mongo-expressÊÇÒ»¿îÓÃÓÚ½»»¥Ê½ÖÎÀíMongoDBÊý¾Ý¿âµÄ¡¢»ùÓÚWebµÄÇáÁ¿¼¶ÖÎÀí½çÃæ¡£¡£¡£¡£


mongo-express 0.54.0֮ǰµÄ°æ±¾£¬£¬£¬£¬£¬£¬Í¨¹ýÈÏÖ¤ºó£¬£¬£¬£¬£¬£¬ÔÚÖÕ¶ËʹÓá®toBSON¡¯ÒªÁ죬£¬£¬£¬£¬£¬¿ÉÒÔÖ´ÐÐÔ¶³ÌÏÂÁ£¬£¬£¬£¬£¬¶ø mongo-express ĬÈϵÄÕ˺ÅÃÜÂëÊÇ admin:pass ¡£¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttps://github.com/masahiro331/CVE-2019-10758¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://github.com/mongo-express¡£¡£¡£¡£Éý¼¶µ½×îаæ£¬£¬£¬£¬£¬£¬ÔÚconfig.jsÎļþÖÐÉèÖÃÇ¿¿ÚÁ£¬£¬£¬£¬£¬ÉèÖÃÊÜÐÅÈεĻá¼ûÔ´¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://snyk.io/vuln/SNYK-JS-MONGOEXPRESS-473215