Zimbra Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-18Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£º
ZimbraCollaboration Server 8.8.11 ֮ǰµÄ°æ±¾¶¼Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£º
1. Zimbra < 8.7.11 °æ±¾ÖУ¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÎÞÐèµÇ¼µÄÇéÐÎÏ£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ
2. Zimbra < 8.8.11 °æ±¾ÖУ¬£¬£¬ÔÚЧÀͶËʹÓà Memcached ×ö»º´æµÄÇéÐÎÏ£¬£¬£¬¾ÓɵǼÈÏÖ¤ºóµÄ¹¥»÷Õß¿ÉÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ
Îó²î¸ÅÊö
Zimbra ÊÇÒ»¼ÒÌṩרҵµÄµç×ÓÓʼþÈí¼þ¿ª·¢¹©Ó¦ÉÌ£¬£¬£¬Ö÷ÒªÌṩ Zimbra Collaboration Server Ð×÷ЧÀÍÆ÷Ì×¼þ¡¢Zimbra Desktop ÓʼþÖÎÀíÈí¼þµÈÓʼþ·½ÃæµÄÈí¼þ¡£¡£¡£¡£¡£¡£¡£
3 Ô 13 ÈÕ£¬£¬£¬ ÍâÑóÇå¾²Ñо¿Ô± tint0 Ðû²¼ÁËһƪ²©¿Í£¬£¬£¬Ö¸³ö Zimbra Collaboration Server ϵͳȫ°æ±¾±£´æÒ»ÏµÁÐÎó²î£¬£¬£¬Í¨¹ý¶ñÒâʹÓÿÉÒÔµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£
Îó²îϸ½Ú
µ± Zimbra ±£´æÏñí§ÒâÎļþ¶ÁÈ¡¡¢XXE£¨XML ÍⲿʵÌå×¢È룩 ÕâÖÖÎó²îʱ£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î¶ÁÈ¡ localconfig.xml ÉèÖÃÎļþ£¬£¬£¬»ñÈ¡µ½ zimbra admin ldap password£¬£¬£¬²¢Í¨¹ý 7071 admin ¶Ë¿Ú¾ÙÐÐ SOAP AuthRequest ÈÏÖ¤£¬£¬£¬»ñµÃ admin authtoken£¬£¬£¬È»ºó¾Í¿ÉÒÔʹÓà admin authtoken ¾ÙÐÐí§ÒâÎļþÉÏ´«£¬£¬£¬´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄΣº¦¡£¡£¡£¡£¡£¡£¡£
¶ø tint0 ²©¿ÍÎÄÕÂÀïÖ¸³ö£¬£¬£¬×ÝÈ»ÔÚ 7071 admin ¶Ë¿Ú×öÁË·À»ðǽÉèÖá¢²î³ØÍ⿪·ÅµÄÇéÐÎÏ£¬£¬£¬Ò²¿ÉÒÔʹÓñ£´æÓÚ 443 ͨË×Óû§¶Ë¿ÚЧÀÍÀïÉí·ÝÈÏÖ¤µÄÒ»¸öÌØÕ÷£¬£¬£¬ÅäºÏ ProxyServlet.doProxy() ÒªÁìÀïµÄ SSRF£¬£¬£¬Í¬ÑùÒ²ÄÜÍê³É admin SOAP AuthRequest ÈÏÖ¤£¬£¬£¬»ñµÃ admin authtoken¡£¡£¡£¡£¡£¡£¡£
ÏÂͼΪÅäºÏʹÓà XXE ºÍ ProxyServlet SSRF Îó²îÄõ½ admin authtoken ºó£¬£¬£¬Í¨¹ýÎļþÉÏ´«ÔÚЧÀͶËÖ´ÐÐí§Òâ´úÂëµÄÍâµØ²âÊÔ½ØÍ¼£º
³ý´ËÖ®Í⣬£¬£¬ÔÚ ZimbraЧÀͶËʹÓà Memcached ×ö»º´æÐ§ÀÍʱ£¬£¬£¬»¹¿ÉÒÔʹÓà SSRF ¹¥»÷ Memcached »º´æÐ§ÀÍ£¬£¬£¬Í¨¹ý·´ÐòÁл¯ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£²»¹ýÓÉÓÚ Zimbra µÄ×°ÖÃÀú³ÌÖÐµÄ bug£¬£¬£¬µ¼Öµ¥Ð§ÀÍÆ÷µÄÇéÐÎÏ£¬£¬£¬Memcached Ö»¹Ü»áÆô¶¯£¬£¬£¬µ«²¢²»»áʹÓ㬣¬£¬Òò´Ë SSRF ¹¥»÷ Memcached ·´ÐòÁл¯µÄʹÓó¡¾°½ÏÁ¿ÓÐÏÞ¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
¸üйٷ½Ðû²¼µÄÇå¾²²¹¶¡»òÉý¼¶ Zimbra µ½×îа棺https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories