¹«º£²Ê´¬¡¤6600(ÖйúÓÎ)¹Ù·½ÍøÕ¾

µã»÷ÏÂÔØ¡¶ÍòÕ×Ô°ÇøÒÔÌ«²Ê¹âÑо¿±¨¸æ¡·£¬½âËøÍòÕ×Ô°ÇøÍøÂ罨ÉèÖ¸ÄÏ
Á¢¼´ÏÂÔØ
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨·¢²¼
Ô¤Ô¼Ö±²¥
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ

¹«º£²Ê´¬¡¤6600°²È«¹ØÓÚ¼«Î£React Server ComponentsÔ¶³Ì´úÂëÖ´ÐЩ¶´µÄ½â¶Á

½üÆÚ£¬React ÍŶÓÅû¶ÁËReact Server Components×é¼þÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2025-55182£©¡£React ·þÎñÆ÷×é¼þ£¨RSC£©ÊÇÒ»ÏîºËÐŦÄÜ£¬ËüÔÊÐí¿ª·¢ÕßÔÚ·þÎñÆ÷¶ËÖ±½ÓäÖȾ×é¼þ£¬²¢½«½á¹û·¢ËÍÖÁ¿Í»§¶Ë£¬´Ó¶øÌáÉýÐÔÄÜÓëÓû§ÌåÑ顣Ŀǰ£¬¸Ã¼¼ÊõÒѱ»Next.js¡¢Shopify Hydrogen¡¢Gatsby 5µÈÖ÷Á÷¿ò¼Ü¹ã·º²ÉÓã¬ÔÚµçÉÌÆ½Ì¨¡¢SaaS·þÎñÒÔ¼°ÄÚÈÝÕ¾µãµÈ¶à¸öÁìÓò¾ßÓÐÆÕ±éÓ¦Óá£ÔÚFOFA×ʲú²â»æÆ½Ì¨µÄ¼à²âÊý¾ÝÖУ¬¹«º£²Ê´¬¡¤6600°²È«·¢ÏÖ»ùÓÚNext.jsµÄÓ¦ÓÃ×ʲúÊýÁ¿ÒÑ´ï766Íò£¬ÕâÒâζ×ų¬¹ý200Íǫ̀·þÎñÆ÷¿ÉÄÜÃæÁÙ°²È«·çÏÕ¡£ÓÈΪÑϾþµÄÊÇ£¬Ïà¹ØÂ©¶´µÄÀûÓóɹ¦Âʼ«¸ß£¬½Ó½ü100%£¬¹¥»÷ÕßÄܹ»Îȶ¨ÊµÏÖÍêÕûµÄÔ¶³Ì´úÂëÖ´ÐУ¬¶Ôϵͳ°²È«¹¹³ÉÑÏÖØÍþв¡£

  • ·¢²¼Ê±¼ä£º2026-01-05

  • µã»÷Á¿£º

  • µãÔÞ£º

·ÖÏíÖÁ

ÎÒÏëÆÀÂÛ

½üÆÚ£¬React ÍŶÓÅû¶ÁËReact Server Components×é¼þÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2025-55182£©¡£React ·þÎñÆ÷×é¼þ£¨RSC£©ÊÇÒ»ÏîºËÐŦÄÜ£¬ËüÔÊÐí¿ª·¢ÕßÔÚ·þÎñÆ÷¶ËÖ±½ÓäÖȾ×é¼þ£¬²¢½«½á¹û·¢ËÍÖÁ¿Í»§¶Ë£¬´Ó¶øÌáÉýÐÔÄÜÓëÓû§ÌåÑ顣Ŀǰ£¬¸Ã¼¼ÊõÒѱ»Next.js¡¢Shopify Hydrogen¡¢Gatsby 5µÈÖ÷Á÷¿ò¼Ü¹ã·º²ÉÓã¬ÔÚµçÉÌÆ½Ì¨¡¢SaaS·þÎñÒÔ¼°ÄÚÈÝÕ¾µãµÈ¶à¸öÁìÓò¾ßÓÐÆÕ±éÓ¦Óá£

ÔÚFOFA×ʲú²â»æÆ½Ì¨µÄ¼à²âÊý¾ÝÖУ¬¹«º£²Ê´¬¡¤6600°²È«·¢ÏÖ»ùÓÚNext.jsµÄÓ¦ÓÃ×ʲúÊýÁ¿ÒÑ´ï766Íò£¬ÕâÒâζ×ų¬¹ý200Íǫ̀·þÎñÆ÷¿ÉÄÜÃæÁÙ°²È«·çÏÕ¡£ÓÈΪÑϾþµÄÊÇ£¬Ïà¹ØÂ©¶´µÄÀûÓóɹ¦Âʼ«¸ß£¬½Ó½ü100%£¬¹¥»÷ÕßÄܹ»Îȶ¨ÊµÏÖÍêÕûµÄÔ¶³Ì´úÂëÖ´ÐУ¬¶Ôϵͳ°²È«¹¹³ÉÑÏÖØÍþв¡£

1.©¶´¸ÅÊö

©¶´±àºÅ£ºCVE-2025-55182

©¶´ÀàÐÍ£ºÔ¶³Ì´úÂëÖ´ÐÐ(RCE)

©¶´µÈ¼¶£º¸ßΣ

Ó°Ï췶Χ£ºReact Server Components Ïà¹Ø¿ò¼ÜºÍ¿â£¬ÀýÈçNext.jsµÈ¡£

·¢ÏÖʱ¼ä£º2025Äê12ÔÂ3ÈÕ

CVSSÆÀ·Ö£º10£¨ÆÀ·Ö·¶Î§1-10£¬¸Ã©¶´ÆÀ·Ö×î¸ß£©

POC״̬£ºÒѹ«¿ª

1.1 ©¶´Ó°Ïì°æ°æ±¾

Èí¼þ°ü ÊÜÓ°Ïì°æ±¾·¶Î§
Next.js 15.0.0 -15.0.4
15.1.0 -15.1.8
15.2.0 -15.2.5
15.3.0 -15.3.5
15.4.0 -15.4.7
16.0.0 -16.0.6
React RSC 19.0.0
19.1.0 -19.1.1

  

1.2 ©¶´¸´ÏÖ

·¢Ë͹«¿ªµÄHTTP¶ñÒâÇëÇóPayload¿ÉÒÔ¿´µ½·þÎñÆ÷³É¹¦Ö´ÐÐÎÒÃÇÒªÇóÖ´ÐÐwhoamiÃüÁ·þÎñÆ÷³É¹¦Ö´ÐÐwhoami²¢ÔÚÏìÓ¦Öзµ»ØwhoamiÃüÁîÖ´ÐеĽá¹û¡£

2.©¶´Ô­Àí·ÖÎö

FlightЭÒ飺

React 19ÒýÈëµÄ¿Í»§¶Ë-·þÎñ¶ËͨÐÅЭÒé

ʹÓÃÌØÊâµÄÐòÁл¯¸ñʽ´«ÊäReact×é¼þÊ÷

Ö§³ÖÒýÓÃϵͳ£º$@N (chunkÒýÓÃ), $B N (BlobÒýÓÃ), $F N (º¯ÊýÒýÓÃ)

·þÎñ¶Ë·´ÐòÁл¯ºóÖ´ÐÐServer Actions/Components

CVE-2025-55182©¶´ÊÇÔ´ÓÚ·þÎñ¶ËÔÚ·´ÐòÁл¯ Server Action ÇëÇóʱδУÑéÄ£¿éµ¼³öÊôÐԵĺϷ¨ÐÔ£¬¹¥»÷Õß¿Éͨ¹ý²Ù¿ØÇëÇó¸ºÔØ·ÃÎÊÔ­ÐÍÁ´ÉϵÄΣÏÕ·½·¨£¨Èç vm.runInThisContext£©£¬½ø¶øÖ´ÐÐÈÎÒâϵͳÃüÁֻҪӦÓÃÒÀÀµÖаüº¬ vm¡¢child_process »ò fs µÈ³£¼û Node.js Ä£¿é¼´¿É±»ÀûÓ㬹¥»÷Õß¿Éͨ¹ý¹¹Ôì¶ñÒâRSCÇëÇóÔÚ·þÎñÆ÷¶ËʵÏÖÈÎÒâ´úÂëÖ´ÐС£

3.ÐÞ¸´¹«º£²Ê´¬¡¤6600¹ÙÍø

3.1 ¹Ù·½ÐÞ¸´¹«º£²Ê´¬¡¤6600¹ÙÍø

ÐÞ¸´½â¾ö¹«º£²Ê´¬¡¤6600¹ÙÍø£¨º¬Â©¶´²¹¶¡£©£º

¹Ù·½ÒÑ·¢²¼°²È«²¹¶¡£¬Ç뼰ʱ¸üÐÂÖÁ×îа汾£ºReact Server 19.0.1¡¢React Server 19.1.2¡¢React Server 19.2.1

ÏÂÔØµØÖ·£ºhttps://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

»òÕßͨ¹ýÃüÁîÉý¼¶µ½°²È«°æ±¾£¬npm install react@19.0.1 react-dom@19.0.1 next@15.0.5

3.2 ¹«º£²Ê´¬¡¤6600·À»ðǽ·À»¤¹«º£²Ê´¬¡¤6600¹ÙÍø

¹«º£²Ê´¬¡¤6600ÍøÂç·À»ðǽÔÚÍøÂç±ß½ç¾«×¼¹ýÂËЯ´øCVE-2025-55182©¶´¹¥»÷ÌØÕ÷µÄ¶ñÒâÁ÷Á¿£¬Í¨¹ýͨÓÃÐÍ©¶´+¾ßÌå©¶´µÄ¼ì²âÀíÄʵÏÖ¶Ôδ֪+ÒÑ֪©¶´µÄ¾«×¼À¹½ØºÍ×è¶Ï£¬WEBÓ¦Óð²È«Í¨¹ýÉî¶È½âÎöHTTPÇëÇó±¨ÎÄ£¬¾«×¼Ê¶±ðÈçµ÷ÓÃchild_process.execSyncµÄ¸ßΣ²ÎÊý¼°¶ñÒâ¹¹ÔìÄÚÈÝ£¬ÖþÀÎWeb²ã×ÝÉî·ÀÓùÆÁÕÏ¡£

1.Éý¼¶·À»ðǽµÄIPS¹æÔò¿â°æ±¾µ½v20251208.1421°æ±¾

ÑéÖ¤¹æÔò13240144¡¢13240145¡¢13240146ÊÇ·ñÔÚ¹æÔò¿â¡£ÔÚϵͳ--ÌØÕ÷¿âÉý¼¶Ä£¿é¿ªÆô×Ô¶¯Éý¼¶ºó£¬ÌØÕ÷¿â½«»á×Ô¶¯ÁªÍø¸üУ¬×Ô¶¯¸üÐÂÌØÕ÷¿âµÄÉ豸²»Êܸé¶´Ó°Ïì¡£

2.δÁªÍøÉ豸¿ÉÒÔͨ¹ýµÇ¼¹«º£²Ê´¬¡¤6600°²È«ÔƹÙÍøhttps://secloud1.ruijie.com.cn/login£¬ÏÂÔØ×îеÄIPS¹æÔò¿â

±£Ö¤°æ±¾ÔÚv20251208.1421ÒÔÉÏ£¬ÀëÏßÉý¼¶¹æÔò¿â¡£

»ùÓÚÒÔÉÏ·ÖÎö£¬Õë¶ÔReact CVE-2025-55182ÕâÒ»CVSSÂú·Ö¸ßΣ©¶´£¬¹«º£²Ê´¬¡¤6600·À»ðǽµÄºËÐÄ·À»¤ÓÅÊÆ¿É¸ÅÀ¨Îª“¿ì¡¢È«¡¢¼ò”Èý´óÌØµã£º

ÏìӦѸËÙ£ºÂ©¶´Åû¶ºó24СʱÄÚ¼´Íê³É¹¥»÷ÌØÕ÷ÌáÈ¡Óë·À»¤¹æÔòͬ²½£¬°ïÖúÓû§ÔÚµÚһʱ¼äÆô¶¯ÓÐЧ·ÀÓù£»

¸²¸ÇÈ«Ãæ£ºÌṩÕë¶ÔÐÔ·À»¤¹æÔò£¬¼´¿ª¼´Óã¬ÎÞÐ踴ÔÓÅäÖã»

²¿Êð¼ò±ã£º¼´Ê¹ÔÝδÍê³Éϵͳ²¹¶¡Éý¼¶£¬Óû§Ò²¿Éͨ¹ýÒ»¼üÆôÓùæÔò£¬¿ìËÙ¹¹½¨°²È«»º³åµØ´ø¡£

Ïà¹Ø±êÇ©£º

µãÔÞ

¸ü¶à¼¼Êõ²©ÎÄ

ÈκÎÐèÒª£¬ÇëÁªÏµÎÒÃÇ

·µ»Ø¶¥²¿

ÊÕÆð
ÎĵµAIÖúÊÖ
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
Äú¶Ôµ±Ç°Ò³ÃæµÄÂúÒâ¶ÈÈçºÎ£¿
²»Õ¦µÎ
·Ç³£ºÃ
ÄúÂúÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
Äú¶ÔÎĵµÊÇ·ñ»¹ÓÐÆäËüµÄÎÊÌâ»ò½¨Ò飿
Ϊ¾¡¿ì½â¾öÎÊÌ⣬ÇëÄúÁôÏÂÁªÏµ·½Ê½Òﱋȯ¸´
ÓÊÏä
ÊÖ»úºÅ
¸ÐлÄúµÄ·´À¡£¡
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´À¡ Òâ¼û·´À¡
Òâ¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿