¡¾Îó²îͨ¸æ¡¿Apache Jackrabbit Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-37895£©

Ðû²¼Ê±¼ä 2023-07-28


Ò»¡¢Îó²î¸ÅÊö

CVE   ID

CVE-2023-37895

·¢Ã÷ʱ¼ä

2023-07-26

Àà    ÐÍ

·´ÐòÁл¯

µÈ    ¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÖØÆ¯ºó

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷

 

Apache JackrabbitÊÇÒ»¸öǿʢµÄ¿ªÔ´ÄÚÈÝ´æ´¢¿â£¬£¬£¬ £¬£¬£¬ÊµÏÖÁËJavaµÄÄÚÈÝ´æ´¢¿â¹æ·¶£¨JSR-170ºÍJSR-283£©¡£¡£¡£¡£¡£

7ÔÂ26ÈÕ£¬£¬£¬ £¬£¬£¬Z6×ðÁú¿­Ê±VSRC¼à²âµ½Apache JackrabbitÖÐÐÞ¸´ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-37895£©¡£¡£¡£¡£¡£

Apache Jackrabbit webapp/standalone¶à¸ö°æ±¾Öб£´æJava ¹¤¾ß·´ÐòÁл¯Îó²î£¬£¬£¬ £¬£¬£¬ÓÉÓÚʹÓõÄcommons-beanutils ×é¼þÖб£´æÒ»¸ö¿Éͨ¹ý RMI Ô¶³ÌÖ´ÐдúÂëµÄÀ࣬£¬£¬ £¬£¬£¬¿Éͨ¹ý½á¹¹¶ñÒâÐòÁл¯Êý¾Ý£¬£¬£¬ £¬£¬£¬²¢·¢Ë͵½Ä¿µÄϵͳÉ쵀 RMI ЧÀͶ˿ڣ¨Ä¬ÒÔΪ1099¶Ë¿Ú£©»ò·¢Ë͵½RMI-over-HTTP·¾¶£¨Ä¬ÈÏʹÓ÷¾¶¡°/rmi¡±£©£¬£¬£¬ £¬£¬£¬µ±Ä¿µÄϵͳ·´ÐòÁл¯¸ÃÊý¾Ýʱ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£

 

¶þ¡¢Ó°Ïì¹æÄ£

Apache Jackrabbit Webapp (jackrabbit-webapp) 2.21.0 < 2.21.18

Apache Jackrabbit Webapp (jackrabbit-webapp) 1.0.0 < 2.20.11

Apache Jackrabbit Standalone (jackrabbit-standalone ºÍ jackrabbit-standalone-components) 2.21.0 < 2.21.18

Apache Jackrabbit Standalone (jackrabbit-standalone ºÍ jackrabbit-standalone-components) 1.0.0 < 2.20.11

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´£¬£¬£¬ £¬£¬£¬Jackrabbit standalone(-components) ºÍ webappÓû§¿É¸üе½2.20.11£¨Îȹ̣©»ò 2.21.18£¬£¬£¬ £¬£¬£¬ÈçÏ£º

Apache Jackrabbit Webapp (jackrabbit-webapp) 2.21.0 >= 2.21.18

Apache Jackrabbit Webapp (jackrabbit-webapp) 1.0.0 >= 2.20.11

Apache Jackrabbit Standalone (jackrabbit-standalone ºÍ jackrabbit-standalone-components) 2.21.0 >= 2.21.18

Apache Jackrabbit Standalone (jackrabbit-standalone ºÍ jackrabbit-standalone-components) 1.0.0 >= 2.20.11

ÏÂÔØÁ´½Ó£º

https://jackrabbit.apache.org/jcr/downloads.html#apache-jackrabbit-2-21-18-july-24th-2023

3.2 ÔÝʱ²½·¥

ÈôÊÇÆôÓà RMI£¬£¬£¬ £¬£¬£¬Î´ÐÞ¸´µÄ×é¼þºÜÈÝÒ×Êܵ½RCE¹¥»÷£¬£¬£¬ £¬£¬£¬¿ÉÒÔͨ¹ý¹Ø±ÕRMIÖ§³ÖÀ´»º½â¸ÃÎó²î¡£¡£¡£¡£¡£

ĬÈÏÇéÐÎÏÂJackrabbit webapp/standalone ÖÐÆôÓÃRMIÖ§³Ö£¬£¬£¬ £¬£¬£¬ÍâµØ RMI ЭÒéĬÈÏʹÓö˿Ú1099£¬£¬£¬ £¬£¬£¬Òª¼ì²é¶Ë¿ÚÊÇ·ñÆôÓ㬣¬£¬ £¬£¬£¬¿ÉÒÔʹÓà "netstat "µÈ¹¤¾ß¡£¡£¡£¡£¡£Jackrabbit ÖÐµÄ RMI-over-HTTP ĬÈÏÇéÐÎÏÂʹÓ÷¾¶¡°/rmi¡±¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬ £¬£¬£¬µ±ÔÚ¶Ë¿Ú 8080 ÉÏ×ÔÁ¦ÔËÐÐʱ£¬£¬£¬ £¬£¬£¬Çë¼ì²é localhost:8080/rmi É쵀 HTTP GET ÇëÇóÊÇ·ñ·µ»Ø 404£¨Î´ÆôÓã©»ò 200£¨ÆôÓã©¡£¡£¡£¡£¡£×¢ÖØ£¬£¬£¬ £¬£¬£¬HTTP ·¾¶¿ÉÄÜ»áÒò°²ÅŶøÓÐËù²î±ð¡£¡£¡£¡£¡£¸ü¶àÏêÇé¿É²Î¿¼£º

https://lists.apache.org/thread/j03b3qdhborc2jrhdc4d765d3jkh8bfw

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://lists.apache.org/thread/j03b3qdhborc2jrhdc4d765d3jkh8bfw

https://jackrabbit.apache.org/jcr/index.html

https://securityonline.info/cve-2023-37895-a-critical-remote-code-execution-in-apache-jackrabbit/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-07-28

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 Z6×ðÁú¿­Ê±¼ò½é

Z6×ðÁú¿­Ê±½¨ÉèÓÚ1996Ä꣬£¬£¬ £¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°Z6×ðÁú¿­Ê±´óÏ㬣¬£¬ £¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬ £¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬ £¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬ £¬£¬£¬Z6×ðÁú¿­Ê±ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬ £¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬ £¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

5.2 ¹ØÓÚZ6×ðÁú¿­Ê±

Z6×ðÁú¿­Ê±Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬ £¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬ £¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png