Zimbra Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-18

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º

ZimbraCollaboration Server 8.8.11 ֮ǰµÄ°æ±¾¶¼Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£ ¡£ÏêϸÀ´Ëµ£º

1. Zimbra < 8.7.11 °æ±¾ÖУ¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÎÞÐèµÇ¼µÄÇéÐÎÏ£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

2. Zimbra < 8.8.11 °æ±¾ÖУ¬£¬£¬ÔÚЧÀͶËʹÓà Memcached ×ö»º´æµÄÇéÐÎÏ£¬£¬£¬¾­ÓɵǼÈÏÖ¤ºóµÄ¹¥»÷Õß¿ÉÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ


Îó²î¸ÅÊö


Zimbra ÊÇÒ»¼ÒÌṩרҵµÄµç×ÓÓʼþÈí¼þ¿ª·¢¹©Ó¦ÉÌ£¬£¬£¬Ö÷ÒªÌṩ Zimbra Collaboration Server Э×÷ЧÀÍÆ÷Ì×¼þ¡¢Zimbra Desktop ÓʼþÖÎÀíÈí¼þµÈÓʼþ·½ÃæµÄÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£


3 Ô 13 ÈÕ£¬£¬£¬ ÍâÑóÇå¾²Ñо¿Ô± tint0 Ðû²¼ÁËһƪ²©¿Í£¬£¬£¬Ö¸³ö Zimbra Collaboration Server ϵͳȫ°æ±¾±£´æÒ»ÏµÁÐÎó²î£¬£¬£¬Í¨¹ý¶ñÒâʹÓÿÉÒÔµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£ ¡£


Îó²îϸ½Ú


µ± Zimbra ±£´æÏñí§ÒâÎļþ¶ÁÈ¡¡¢XXE£¨XML ÍⲿʵÌå×¢È룩 ÕâÖÖÎó²îʱ£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î¶ÁÈ¡ localconfig.xml ÉèÖÃÎļþ£¬£¬£¬»ñÈ¡µ½ zimbra admin ldap password£¬£¬£¬²¢Í¨¹ý 7071 admin ¶Ë¿Ú¾ÙÐÐ SOAP AuthRequest ÈÏÖ¤£¬£¬£¬»ñµÃ admin authtoken£¬£¬£¬È»ºó¾Í¿ÉÒÔʹÓà admin authtoken ¾ÙÐÐí§ÒâÎļþÉÏ´«£¬£¬£¬´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄΣº¦¡£¡£¡£¡£¡£¡£ ¡£


¶ø tint0 ²©¿ÍÎÄÕÂÀïÖ¸³ö£¬£¬£¬×ÝÈ»ÔÚ 7071 admin ¶Ë¿Ú×öÁË·À»ðǽÉèÖá¢²î³ØÍ⿪·ÅµÄÇéÐÎÏ£¬£¬£¬Ò²¿ÉÒÔʹÓñ£´æÓÚ 443 ͨË×Óû§¶Ë¿ÚЧÀÍÀïÉí·ÝÈÏÖ¤µÄÒ»¸öÌØÕ÷£¬£¬£¬ÅäºÏ ProxyServlet.doProxy() ÒªÁìÀïµÄ SSRF£¬£¬£¬Í¬ÑùÒ²ÄÜÍê³É admin SOAP AuthRequest ÈÏÖ¤£¬£¬£¬»ñµÃ admin authtoken¡£¡£¡£¡£¡£¡£ ¡£


ÏÂͼΪÅäºÏʹÓà XXE ºÍ ProxyServlet SSRF Îó²îÄõ½ admin authtoken ºó£¬£¬£¬Í¨¹ýÎļþÉÏ´«ÔÚЧÀͶËÖ´ÐÐí§Òâ´úÂëµÄÍâµØ²âÊÔ½ØÍ¼£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



³ý´ËÖ®Í⣬£¬£¬ÔÚ ZimbraЧÀͶËʹÓà Memcached ×ö»º´æÐ§ÀÍʱ£¬£¬£¬»¹¿ÉÒÔʹÓà SSRF ¹¥»÷ Memcached »º´æÐ§ÀÍ£¬£¬£¬Í¨¹ý·´ÐòÁл¯ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£ ¡£²»¹ýÓÉÓÚ Zimbra µÄ×°ÖÃÀú³ÌÖÐµÄ bug£¬£¬£¬µ¼Öµ¥Ð§ÀÍÆ÷µÄÇéÐÎÏ£¬£¬£¬Memcached Ö»¹Ü»áÆô¶¯£¬£¬£¬µ«²¢²»»áʹÓ㬣¬£¬Òò´Ë SSRF ¹¥»÷ Memcached ·´ÐòÁл¯µÄʹÓó¡¾°½ÏÁ¿ÓÐÏÞ¡£¡£¡£¡£¡£¡£ ¡£


ÐÞ¸´½¨Òé


¸üйٷ½Ðû²¼µÄÇå¾²²¹¶¡»òÉý¼¶ Zimbra µ½×îа棺https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories¡£¡£¡£¡£¡£¡£ ¡£


²Î¿¼Á´½Ó


https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories