Apache TapestryÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-27850£©
Ðû²¼Ê±¼ä 2021-04-160x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-27850 | ʱ ¼ä | 2021-04-16 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé

Apache TapestryÊÇÒ»ÖÖÓÃJava±àдµÄÃæÏò×é¼þµÄWebÓ¦ÓóÌÐò¿ò¼Ü¡£¡£¡£¡£¡£¡£Tapestry¿ÉÒÔÔÚÈκÎÓ¦ÓóÌÐòЧÀÍÆ÷ÏÂÊÂÇ飬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔÇáËɼ¯³ÉËùÓкó¶Ë£¬£¬£¬£¬£¬£¬£¬ÈçSpring£¬£¬£¬£¬£¬£¬£¬HibernateµÈ¡£¡£¡£¡£¡£¡£
2021Äê04ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache Tapestry±»Åû¶±£´æÒ»¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-27850£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£¡£¡£¡£¡£¸ÃÎó²îÈÆ¹ýÁËCVE-2019-0195µÄÐÞ¸´³ÌÐò£¨CVSSÆÀ·ÖΪ9.8£©¡£¡£¡£¡£¡£¡£
ÔÚCVE-2019-0195ÖУ¬£¬£¬£¬£¬£¬£¬Í¨¹ýʹÓÃclasspath×ʲúÎļþURL£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚclasspathÖÐÍÆ²âÎļþµÄ·¾¶£¬£¬£¬£¬£¬£¬£¬È»ºóÏÂÔØ¸ÃÎļþ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÇëÇó°üÀ¨HMACÃØÔ¿µÄURL http://localhost:8080/assets/something/services/AppModule.classÀ´ÏÂÔØÎļþAppModule.class¡£¡£¡£¡£¡£¡£
CVE-2019-0195µÄÐÞ¸´Ê¹ÓÃÁ˺ÚÃûµ¥¹ýÂË£¬£¬£¬£¬£¬£¬£¬Æä¼ì²éURLÊÇ·ñÒÔ¡°.class¡±¡¢¡°.properties¡±»ò¡°.xml¡±×îºó£¬£¬£¬£¬£¬£¬£¬µ«ÕâÖÖºÚÃûµ¥¹ýÂË¿ÉÒÔͨ¹ýÔÚURL×îºóÌí¼Ó¡°/¡±À´Èƹý¡£¡£¡£¡£¡£¡£µ±http://localhost:8080/assets/something/services/AppModule.class/ÔÚºÚÃûµ¥¼ì²éºó£¬£¬£¬£¬£¬£¬£¬Ð±Ïß±»°þÀ룬£¬£¬£¬£¬£¬£¬AppModule.classÎļþ±»¼ÓÔØµ½ÏìÓ¦ÖС£¡£¡£¡£¡£¡£Õâ¸öÀàͨ³£°üÀ¨ÓÃÓÚ¶ÔÐòÁл¯µÄJava¹¤¾ß¾ÙÐÐÊðÃûµÄHMACÃØÔ¿£¬£¬£¬£¬£¬£¬£¬ÔÚÖªµÀ¸ÃÃÜÔ¿µÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔÇ©ÊðJavaС¹¤¾ßÁ´£¨ÀýÈçysoserialµÄCommonsBeanUtils1£©£¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Apache Tapestry 5.4.5
Apache Tapestry 5.5.0
Apache Tapestry 5.6.2
Apache Tapestry 5.7.0
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶µ½ÒÔϰ汾£º
Apache Tapestry 5.4.0-5.6.2£¬£¬£¬£¬£¬£¬£¬Éý¼¶µ½5.6.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£
Apache Tapestry 5.7.0£¬£¬£¬£¬£¬£¬£¬Éý¼¶µ½5.7.1»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://tapestry.apache.org/download.html
0x03 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r237ff7f286bda31682c254550c1ebf92b0ec61329b32fbeb2d1c8751%40%3Cusers.tapestry.apache.org%3E
https://nvd.nist.gov/vuln/detail/CVE-2019-0195
https://nvd.nist.gov/vuln/detail/CVE-2021-27850
0x04 ʱ¼äÏß
2021-04-14 Johannes MoritzÅû¶Îó²î
2021-04-16 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ