Apache OFBiz Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-29200£©

Ðû²¼Ê±¼ä 2021-04-28

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-29200

ʱ   ¼ä

2021-04-28

Àà   ÐÍ

RCE

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache OFBiz < 17.12.07

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

OFBizÊÇÒ»¸öÖøÃûµÄµç×ÓÉÌÎñƽ̨£¬£¬£¬£¬ÏÖÒѳÉΪApache¶¥¼¶ÏîÄ¿¡£¡£ ¡£ËüÌṩÁ˽¨Éè»ùÓÚ×îÐÂJ2EE/XML¹æ·¶ºÍÊÖÒÕ±ê×¼£¬£¬£¬£¬Ö÷ÒªÓÃÓÚ¹¹½¨´óÖÐÐÍÆóÒµ¼¶¡¢¿çƽ̨¡¢¿çÊý¾Ý¿â¡¢¿çÓ¦ÓÃЧÀÍÆ÷µÄ¶à²ã¡¢ÂþÑÜʽµç×ÓÉÌÎñÀàWEBÓ¦ÓÃϵͳµÄ¿ò¼Ü¡£¡£ ¡£

2021Äê04ÔÂ27ÈÕ£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬¹ûÕæÁËApache OFBizÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-29200£©ºÍÒ»¸ö·´ÐòÁл¯Îó²î£¨CVE-2021-30128£©¡£¡£ ¡£

Apache OFBiz·´ÐòÁл¯Îó²î£¨CVE-2021-30128£©

Apache OFBizÔÚ17.12.07֮ǰµÄ°æ±¾Öб£´æ·´ÐòÁл¯Îó²î¡£¡£ ¡£

 

Apache OFBizÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-29200£©

ÓÉÓÚʹÓÃRMI£¨Ô¶³ÌÒªÁìŲÓ㩵¼Ö²»Çå¾²µÄ·´ÐòÁл¯£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔ¶³ÌÖ´ÐдúÂë¡£¡£ ¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬½¨ÒéÉý¼¶µ½Apache OFBiz 17.12.07»ò¸ü¸ß°æ±¾¡£¡£ ¡£

ÏÂÔØÁ´½Ó£º

https://ofbiz.apache.org/download.html#vulnerabilities

 

0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202104.mbox/%3Cfec5f041-0cc9-730f-478c-15926792b2a7@apache.org%3E

http://mail-archives.apache.org/mod_mbox/www-announce/202104.mbox/%3C74ac1d8c-ad68-3ceb-8445-624bce15087f@apache.org%3E

https://ofbiz.apache.org/release-notes-17.12.07.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30128

 

0x04 ʱ¼äÏß

2021-04-27  ApacheÐû²¼Ç徲ͨ¸æ

2021-04-28  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png