Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Next.js ÖÐÐļþÊÚÈ¨ÈÆ¹ýÎó²î |
CVE ID | CVE-2025-29927 |
Îó²îÀàÐÍ | ÊÚÈ¨ÈÆ¹ýÎó²î | ·¢Ã÷ʱ¼ä | 2025-03-24 |
Îó²îÆÀ·Ö | 9.1 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Next.jsÊÇÒ»¸ö»ùÓÚReactµÄ¿ªÔ´¿ò¼Ü£¬£¬£¬£¬ÓÃÓÚ¹¹½¨ÏÖ´úwebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£ËüÌṩÁËЧÀÍÆ÷¶ËäÖȾ£¨SSR£©¡¢¾²Ì¬ÌìÉú£¨SSG£©¡¢API·Óɵȹ¦Ð§£¬£¬£¬£¬Ö§³Ö¿ìËÙ¹¹½¨¸ßÐÔÄܵÄȫջӦÓᣡ£¡£¡£¡£Next.jsÌṩÁË¿ª·¢ºÍÉú²úÇéÐεÄÓÅ»¯£¬£¬£¬£¬Ò×ÓÚ°²ÅÅ£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÆóÒµ¼¶Ó¦ÓúÍÄÚÈÝÇý¶¯µÄÍøÕ¾¡£¡£¡£¡£¡£
2025Äê3ÔÂ24ÈÕ£¬£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½ÍâÑóÇå¾²Ñо¿Ô±ÔÚzhero-web-secÐû²¼µÄÎÄÕÂÖÐÖ¸³ö£¬£¬£¬£¬Next.js 14.2.25¼°15.2.3֮ǰµÄ°æ±¾±£´æÒ»¸öÑÏÖØµÄÖÐÐļþÊÚÈ¨ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÇëÇóÖÐÌí¼Óx-middleware-subrequestÍ·²¿£¬£¬£¬£¬ÈƹýÖÐÐļþµÄÊÚȨºÍÈÏÖ¤¼ì²é£¬£¬£¬£¬½ø¶ø»á¼ûÊܱ£»£»£»£»£»£»¤µÄ×ÊÔ´»òÈÆ¹ýÇå¾²¿ØÖÆ¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÐÅϢй¶¡¢¶ñÒâÊý¾Ý»á¼ûµÈÇ徲Σº¦¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.1£¬£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
11.1.4 <= next.js <= 13.5.614.0 <= next.js < 14.2.25
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì¸üС£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/vercel/next.js/releases/
3.2 ÔÝʱ²½·¥
ÈôÊÇÎÞ·¨Á¬Ã¦Éý¼¶£¬£¬£¬£¬½¨Òéͨ¹ý×èÖ¹°üÀ¨x-middleware-subrequestÍ·²¿µÄÍⲿÇëÇóÀ´ïÔÌΣº¦¡£¡£¡£¡£¡£Õâ¿ÉÒÔͨ¹ýÉèÖÃWebЧÀÍÆ÷»òʹÓ÷À»ðǽ¹æÔòÀ´ÊµÏÖ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffwhttps://github.com/vercel/next.js/commit/52a078da3884efe6501613c7834a3d02a91676d2https://github.com/vercel/next.js/commit/5fd3ae8f8542677c6294f32d18022731eab6fe48https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middlewarehttps://nvd.nist.gov/vuln/detail/CVE-2025-29927