ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ ื ืขืฅ ืœื™ื™ื‘ืจืขืจื™ื– ืคื•ืŸ ื–ืฉืึทื•ื•ืขืจ ืื•ืŸ ื’ื™ื™ืŸ ืฉืคึผืจืึทื›ืŸ ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ื™ื™ืคึผืึทืก IP ืึทื“ืจืขืก ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ

ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืฉื™ื™ึทื›ื•ืช ืฆื• ืคืึทืœืฉ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ IP ืึทื“ืจืขืกืขืก ืžื™ื˜ ืึธืงื˜ืึทืœ ื“ื™ื“ื–ืฉืึทืฅ ืื™ืŸ ืึทื“ืจืขืก ืคึผืึทืจืกื™ื ื’ ืคืึทื ื’ืงืฉืึทื ื– ื–ืขื ืขืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ ื“ื™ ื ืึธืจืžืึทืœ ืœื™ื™ื‘ืจืขืจื™ื– ืคื•ืŸ ื“ื™ ื–ืฉืึทื•ื•ืขืจ ืื•ืŸ ื’ื™ื™ืŸ ืฉืคึผืจืึทื›ืŸ. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืžืึทื›ืŸ ืขืก ืžืขื’ืœืขืš ืฆื• ื‘ื™ื™ืคึผืึทืก ื˜ืฉืขืงืก ืคึฟืึทืจ ื’ื™ืœื˜ื™ืง ืึทื“ืจืขืกืขืก ืื™ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–, ืœืžืฉืœ, ืฆื• ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ืึทืงืกืขืก ืฆื• ืœื•ืคึผื‘ืึทืงืง ืฆื•ื‘ื™ื ื“ ืึทื“ืจืขืกืขืก (127.ืงืกืงืกืงืก) ืึธื“ืขืจ ื™ื ื˜ืจืึทื ืขื˜ ืกื•ื‘ื ืขืฅ ื•ื•ืขืŸ ื“ื•ืจื›ืคื™ืจืŸ SSRF (ืกืขืจื•ื•ืขืจ-ื–ื™ื™ึทื˜ ื‘ืขื˜ืŸ ืคืึธืจื“ื–ืฉืขืจื™) ืื ืคืืœืŸ. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืคืึธืจื–ืขืฆืŸ ื“ืขื ืฆื™ืงืœ ืคื•ืŸ ืคึผืจืึธื‘ืœืขืžืก ื‘ื™ื– ืึทื”ืขืจ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ ื“ื™ ืœื™ื™ื‘ืจืขืจื™ื– ื ืึธื“ืข-ื ืขื˜ืžืึทืกืง (JavaScript, CVE-2021-28918, CVE-2021-29418), ืคึผืจื™ื•ื•ืึทื˜-ื™ืคึผ (JavaScript, CVE-2020-28360), ื™ืคึผืึทื“ื“ืจืขืกืก (Python, CVE- 2021-29921), ื“ืึทื˜ืึท :: ื•ื•ืึทืœืึทื“ื™ื™ื˜ :: IP (ืคึผืขืจืœ, CVE-2021-29662) ืื•ืŸ ื ืขืฅ :: ื ืขื˜ืžืึทืกืง (ืคึผืขืจืœ, CVE-2021-29424).

ืœื•ื™ื˜ ื“ื™ ืกืคึผืขืกื™ืคื™ืงืึทื˜ื™ืึธืŸ, IP ืึทื“ืจืขืก ืฉื˜ืจื™ืงืœ ื•ื•ืึทืœื•ืขืก ืกื˜ืึทืจื˜ื™ื ื’ ืžื™ื˜ ืึท ื ื•ืœ ื–ืึธืœ ื–ื™ื™ืŸ ื™ื ื˜ืขืจืคึผืจืึทื˜ืึทื“ ื•ื•ื™ ืึธืงื˜ืึทืœ ื ื•ืžืขืจืŸ, ืึธื‘ืขืจ ืคื™ืœืข ืœื™ื™ื‘ืจืขืจื™ื– ื˜ืึธืŸ ื ื™ื˜ ื ืขืžืขืŸ ื“ืขื ืื™ืŸ ื—ืฉื‘ื•ืŸ ืื•ืŸ ืคืฉื•ื˜ ืึทื•ื•ืขืงื•ื•ืึทืจืคืŸ ื“ื™ ื ื•ืœ, ื˜ืจืขืึทื˜ื™ื ื’ ื“ื™ ื•ื•ืขืจื˜ ื•ื•ื™ ืึท ื“ืขืฆื™ืžืึทืœ ื ื•ืžืขืจ. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื“ื™ ื ื•ืžืขืจ 0177 ืื™ืŸ ืึธืงื˜ืึทืœ ืื™ื– ื’ืœื™ื™ึทืš ืฆื• 127 ืื™ืŸ ื“ืขืฆื™ืžืึทืœ. ืึท ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ื‘ืขื˜ืŸ ืึท ืžื™ื˜ืœ ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื•ื•ืขืจื˜ "0177.0.0.1", ื•ื•ืึธืก ืื™ืŸ ื“ืขืฆื™ืžืึทืœ ื ืึธื•ื˜ื™ื™ืฉืึทืŸ ืงืึธืจืึทืกืคึผืึทื ื“ื– ืฆื• "127.0.0.1". ืื•ื™ื‘ ื“ื™ ืคึผืจืึธื‘ืœืขืžืึทื˜ื™ืง ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืื™ื– ื’ืขื ื™ืฆื˜, ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื•ื•ืขื˜ ื ื™ืฉื˜ ื“ืขื˜ืขืงื˜ ืึทื– ื“ื™ ืึทื“ืจืขืก 0177.0.0.1 ืื™ื– ืื™ืŸ ื“ื™ ืกื•ื‘ื ืขื˜ 127.0.0.1/8, ืึธื‘ืขืจ ืื™ืŸ ืคืึทืงื˜, ื•ื•ืขืŸ ืื™ืจ ืฉื™ืงืŸ ืึท ื‘ืงืฉื”, ืขืก ืงืขื ืขืŸ ืึทืงืกืขืก ื“ื™ ืึทื“ืจืขืก "0177.0.0.1", ื•ื•ืึธืก ื ืขืฅ ืคืึทื ื’ืงืฉืึทื ื– ื•ื•ืขื˜ ืคึผืจืึธืฆืขืก ื•ื•ื™ 127.0.0.1. ืื™ืŸ ืึท ืขื ืœืขืš ื•ื•ืขื’, ืื™ืจ ืงืขื ืขืŸ ืึธืคึผื ืึทืจืŸ ื“ื™ ืงืึธื ื˜ืจืึธืœ ืคื•ืŸ ืึทืงืกืขืก ืฆื• ื™ื ื˜ืจืึทื ืขื˜ ืึทื“ืจืขืกืขืก ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื•ื•ืึทืœื•ืขืก ื•ื•ื™ "012.0.0.1" (ืขืงื•ื•ื™ื•ื•ืึทืœืขื ื˜ ืฆื• "10.0.0.1").

ืื™ืŸ Rust, ื“ื™ ื ืึธืจืžืึทืœ ื‘ื™ื‘ืœื™ืึธื˜ืขืง "std::net" ืื™ื– ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ืึทืŸ ืึทืจื•ื™ืกื’ืขื‘ืŸ (CVE-2021-29922). ื“ืขืจ IP ืึทื“ืจืขืก ืคึผืึทืจืกืขืจ ืคื•ืŸ ื“ืขืจ ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืึทื•ื•ืขืงื•ื•ืึทืจืคืŸ ืึท ื ื•ืœ ืื™ื™ื“ืขืจ ื“ื™ ื•ื•ืึทืœื•ืขืก ืื™ืŸ ื“ื™ ืึทื“ืจืขืก, ืึธื‘ืขืจ ื‘ืœื•ื™ื– ืื•ื™ื‘ ื ื™ื˜ ืžืขืจ ื•ื•ื™ ื“ืจื™ื™ ื“ื™ื“ื–ืฉืึทืฅ ื–ืขื ืขืŸ ืกืคึผืขืกื™ืคื™ืขื“, ืœืžืฉืœ, "0177.0.0.1" ื•ื•ืึธืœื˜ ื–ื™ื™ืŸ ื‘ืืžืขืจืงื˜ ื•ื•ื™ ืึท ืคืึทืจืงืจื™ืคึผืœื˜ ื•ื•ืขืจื˜ ืื•ืŸ ืึท ืคืึทืœืฉ ืจืขื–ื•ืœื˜ืึทื˜ ื•ื•ืึธืœื˜ ื–ื™ื™ืŸ ืื•ืžื’ืขืงืขืจื˜ ืื™ืŸ ืขื ื˜ืคืขืจ ืฆื• 010.8.8.8 ืื•ืŸ 127.0.026.1. ืึทืคึผืคึผืœื™ืงืึทื˜ื™ืึธื ืก ื•ื•ืึธืก ื ื•ืฆืŸ std::net::IPAddr ื•ื•ืขืŸ ืคึผืึทืจืกื™ื ื’ ื‘ืึทื ื™ืฆืขืจ-ืกืคึผืขืฆื™ืคื™ืฆื™ืจื˜ ืึทื“ืจืขืกืขืก ื–ืขื ืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืกืึทืกืขืคึผื˜ืึทื‘ืึทืœ ืฆื• SSRF (ืกืขืจื•ื•ืขืจ-ื–ื™ื™ึทื˜ ื‘ืขื˜ืŸ ืคืึธืจื“ื–ืฉืขืจื™), RFI (ืจื™ืžืึธื•ื˜ ื˜ืขืงืข ื™ื ืงืœื•ื–ืฉืึทืŸ) ืื•ืŸ ืœืคื™ (ืœืึธืงืึทืœ ื˜ืขืงืข ื™ื ืงืœื•ื–ืฉืึทืŸ) ืื ืคืืœืŸ. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ื™ Rust 1.53.0 ืฆื•ื•ื™ื™ึทื’.

ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ ื ืขืฅ ืœื™ื™ื‘ืจืขืจื™ื– ืคื•ืŸ ื–ืฉืึทื•ื•ืขืจ ืื•ืŸ ื’ื™ื™ืŸ ืฉืคึผืจืึทื›ืŸ ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ื™ื™ืคึผืึทืก IP ืึทื“ืจืขืก ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ

ืื™ืŸ Go, ื“ื™ ื ืึธืจืžืึทืœ ื‘ื™ื‘ืœื™ืึธื˜ืขืง "ื ืขืฅ" ืื™ื– ืึทืคืขืงื˜ืึทื“ (CVE-2021-29923). ื“ื™ ื ืขืฅ.ParseCIDR ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ืคึฟื•ื ืงืฆื™ืข ืกืงื™ืคึผืก ืœื™ื“ื™ื ื’ ื–ืขืจืึธืก ืื™ื™ื“ืขืจ ืึธืงื˜ืึทืœ ื ื•ืžืขืจืŸ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื–ื™ื™. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืึท ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ืคืึธืจืŸ ื“ื™ ื•ื•ืขืจื˜ 00000177.0.0.1, ื•ื•ืึธืก, ื•ื•ืขืŸ ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ื“ื™ net.ParseCIDR(00000177.0.0.1/24) ืคึฟื•ื ืงืฆื™ืข, ื•ื•ืขื˜ ื–ื™ื™ืŸ ืคึผืึทืจืกื˜ ื•ื•ื™ 177.0.0.1/24, ืื•ืŸ ื ื™ืฉื˜ 127.0.0.1/24. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื•ื™ืš ืžืึทื ืึทืคืขืกืฅ ื–ื™ืš ืื™ืŸ ื“ื™ Kubernetes ืคึผืœืึทื˜ืคืึธืจืžืข. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ Go release 1.16.3 ืื•ืŸ ื‘ื™ืชื 1.17.

ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ ื ืขืฅ ืœื™ื™ื‘ืจืขืจื™ื– ืคื•ืŸ ื–ืฉืึทื•ื•ืขืจ ืื•ืŸ ื’ื™ื™ืŸ ืฉืคึผืจืึทื›ืŸ ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ื™ื™ืคึผืึทืก IP ืึทื“ืจืขืก ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ


ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’