Next.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²î(CVE-2025-29927)À´Ï® £¬×ðÁú¿­¹ÙÍøÈë¿ÚÌṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2025-03-25

Next.js ÊÇÒ»¸ö»ùÓÚ React µÄÊ¢ÐÐ Web Ó¦Óÿò¼Ü £¬Ìṩ·þÎñÆ÷¶ËäÖȾ¡¢¾²Ì¬ÍøÕ¾ÌìÉúºÍ¼¯³É·ÓÉϵͳµÈ¹¦Ð§¡£


2025Äê3Ô £¬×ðÁú¿­¹ÙÍøÈë¿Ú¼à¿Øµ½Next.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²îÇ鱨(CVE-2025-29927) £¬µ±ÔÚNext.jsÓ¦ÓÃÖÐʹÓÃmiddleware ʱ £¬ÔÚÇëÇóÍ·ÖмÓÈëÌØ¶¨µÄ x-middleware-subrequest ÇëÇóÍ·¼´¿ÉÈÆ¹ý middleware ÖеÄÂß¼­¡£ÀýÈ統ʹÓà middleware ¾ÙÐÐÉí·ÝÑéÖ¤ÓëÊÚȨ £¬¿ÉʹÓøÃÎó²îÈÆ¹ýÉí·ÝÑéÖ¤¡£¸ÃÎó²îCVSSv3ÆÀ·Ö9.1 £¬Îó²îÆ·¼¶Îª¸ßΣ¡£


±í1.png


Îó²î¸´ÏÖ½ØÍ¼


ͼ1.png


Ó°Ïì°æ±¾


15.* <= Next.js<15.2.3

14.* <= Next.js<14.2.25

11.1.4 <= Next.js <= 13.5.6


ÐÞ¸´½¨Òé


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®£º


ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤ £¬ÏÂÔØÁ´½Ó£º

https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw


¶þ¡¢×ðÁú¿­¹ÙÍøÈë¿Ú¼Æ»®£º


1¡¢×ðÁú¿­¹ÙÍøÈë¿Ú¼ì²âÀà²úÆ·¼Æ»®


ÌìãÙÈëÇÖ¼ì²âÓë¹ÜÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEBÇå¾²Ó¦ÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£© £¬Éý¼¶µ½×îа汾¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦¡£


ÊÂÎñ¿âÏÂÔØµØÖ·£ºhttps://venustech.download.venuscloud.cn/


2¡¢×ðÁú¿­¹ÙÍøÈë¿Ú©ɨ²úÆ·¼Æ»®


£¨1£©¡°×ðÁú¿­¹ÙÍøÈë¿ÚÎó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè


ͼ2.png


£¨2£©×ðÁú¿­¹ÙÍøÈë¿ÚÎó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè


ͼ3.png


3¡¢×ðÁú¿­¹ÙÍøÈë¿Ú×ʲúÓëųÈõÐÔ¹ÜÀíÆ½Ì¨²úÆ·¼Æ»®


×ðÁú¿­¹ÙÍøÈë¿Ú×ʲúÓëųÈõÐÔ¹ÜÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢ £¬¶ÔÈë¿â×ʲúNext.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²î(CVE-2025-29927)¾ÙÐйÜÀí¡£


ͼ4.png


4¡¢×ðÁú¿­¹ÙÍøÈë¿ÚÇå¾²¹ÜÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²¹ÜÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ £¬¾ÙÐйØÁªÕ½ÂÔÉèÖà £¬ÍŽáÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø £¬´Ó¶ø·¢Ã÷¡°Next.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²î(CVE-2025-29927)¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£


1£© ÔÚÌ©ºÏµÄƽ̨ÖÐ £¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Next.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²î(CVE-2025-29927)¡±Îó²îɨÃèʹÃü £¬ÅŲé¹ÜÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú£»


ͼ5.png


2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿éÖÐ £¬Ìí¼Ó¡°L2_Next.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²î(CVE-2025-29927)¡± £¬Í¨¹ý×ðÁú¿­¹ÙÍøÈë¿Ú¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾ £¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º


ͼ6.png


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_Next.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²î(CVE-2025-29927)"Îó²îʹÓõĿÉÒÉÐÐΪԴµØÖ·Ìí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖÐ £¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓã»


3£©Ìí¼Ó¡°L3_Next.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²î(CVE-2025-29927)¡± £¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_Next.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²î(CVE-2025-29927)¡± £¬¹¥»÷Ч¹û¼´ÊÇ»òÊôÓÚ¡°¹¥»÷Àֳɡ± £¬Ä¿µÄµØÖ·ÒýÓÃ×ʲúÎó²î»òÔ´µØÖ·Æ¥ÅäÍþвÇ鱨 £¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£


ͼ7.png


4£©ATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé


ƾ֤¶ÔNext.js ÖÐÐļþȨÏÞÈÆ¹ýÎó²î(CVE-2025-29927)µÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö £¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒÕ½×¶Î £¬ÁýÕÖµÄTTP°üÀ¨£º


TA0001-³õʼ»á¼û£ºT1190-ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò

TA0004-ȨÏÞÌáÉý£ºT1068-ʹÓÃÎó²îÌáȨ

TA0010-Êý¾Ýй¶£ºT1041-ͨ¹ýC2ͨµÀÇÔÈ¡Êý¾Ý


±í2.jpg


ͨ¹ýÌ©ºÏÇå¾²¹ÜÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦ £¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾 £¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£