CVE-2021-32827 (CNNVD-202108-1486)
中文标题:
MockServer 跨站脚本漏洞
英文标题:
Arbitrary code execution in MockServer
漏洞描述
中文描述:
MockServer是通过 HTTP 或 HTTPS 模拟任何服务器或服务,例如 REST 或 RPC 服务。 MockServer存在跨站脚本漏洞,该漏洞源于可以诱骗受害者在本地运行MockServer时访问恶意站点的攻击者可利用该漏洞,将能够在MockServer机器上运行任意代码。MockServer的默认CORS配置过于宽泛,允许任何站点发送跨站点请求。
英文描述:
MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine. With an overly broad default CORS configuration MockServer allows any site to send cross-site requests. Additionally, MockServer allows you to create dynamic expectations using Javascript or Velocity templates. Both engines may allow an attacker to execute arbitrary code on-behalf of MockServer. By combining these two issues (Overly broad CORS configuration + Script injection), an attacker could serve a malicious page so that if a developer running MockServer visits it, they will get compromised. For more details including a PoC see the referenced GHSL-2021-059.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| mock-server | mockserver | all | - | - |
cpe:2.3:a:mock-server:mockserver:all:*:*:*:*:*:*:*
|
| mock-server | mockserver | * | - | - |
cpe:2.3:a:mock-server:mockserver:*:*:*:*:*:*:*:*
|
| oracle | communications_cloud_native_core_policy | 1.14.0 | - | - |
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2021-32827 |
2025-11-11 15:20:58 | 2025-11-11 07:36:52 |
| NVD | nvd_CVE-2021-32827 |
2025-11-11 14:57:40 | 2025-11-11 07:45:11 |
| CNNVD | cnnvd_CNNVD-202108-1486 |
2025-11-11 15:10:42 | 2025-11-11 07:56:51 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 跨站脚本
- cnnvd_id: 未提取 -> CNNVD-202108-1486
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']