Apache OFBiz Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-29200£©
Ðû²¼Ê±¼ä 2021-04-280x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-29200 | ʱ ¼ä | 2021-04-28 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache OFBiz < 17.12.07 |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
OFBizÊÇÒ»¸öÖøÃûµÄµç×ÓÉÌÎñƽ̨£¬£¬£¬£¬ÏÖÒѳÉΪApache¶¥¼¶ÏîÄ¿¡£¡£¡£ËüÌṩÁ˽¨Éè»ùÓÚ×îÐÂJ2EE/XML¹æ·¶ºÍÊÖÒÕ±ê×¼£¬£¬£¬£¬Ö÷ÒªÓÃÓÚ¹¹½¨´óÖÐÐÍÆóÒµ¼¶¡¢¿çƽ̨¡¢¿çÊý¾Ý¿â¡¢¿çÓ¦ÓÃЧÀÍÆ÷µÄ¶à²ã¡¢ÂþÑÜʽµç×ÓÉÌÎñÀàWEBÓ¦ÓÃϵͳµÄ¿ò¼Ü¡£¡£¡£
2021Äê04ÔÂ27ÈÕ£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬¹ûÕæÁËApache OFBizÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-29200£©ºÍÒ»¸ö·´ÐòÁл¯Îó²î£¨CVE-2021-30128£©¡£¡£¡£
Apache OFBiz·´ÐòÁл¯Îó²î£¨CVE-2021-30128£©
Apache OFBizÔÚ17.12.07֮ǰµÄ°æ±¾Öб£´æ·´ÐòÁл¯Îó²î¡£¡£¡£
Apache OFBizÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-29200£©
ÓÉÓÚʹÓÃRMI£¨Ô¶³ÌÒªÁìŲÓ㩵¼Ö²»Çå¾²µÄ·´ÐòÁл¯£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬½¨ÒéÉý¼¶µ½Apache OFBiz 17.12.07»ò¸ü¸ß°æ±¾¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://ofbiz.apache.org/download.html#vulnerabilities
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202104.mbox/%3Cfec5f041-0cc9-730f-478c-15926792b2a7@apache.org%3E
http://mail-archives.apache.org/mod_mbox/www-announce/202104.mbox/%3C74ac1d8c-ad68-3ceb-8445-624bce15087f@apache.org%3E
https://ofbiz.apache.org/release-notes-17.12.07.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30128
0x04 ʱ¼äÏß
2021-04-27 ApacheÐû²¼Ç徲ͨ¸æ
2021-04-28 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/