¡¾Îó²îͨ¸æ¡¿Apache OFBizí§ÒâÎļþÉÏ´«Îó²î (CVE-2021-37608)

Ðû²¼Ê±¼ä 2021-08-12



0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-37608

ʱ      ¼ä

2021-08-11

Àà      ÐÍ

ÎļþÉÏ´«

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ


PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

 

Apache OFBizÊÇÒ»¿îÆóÒµÁ÷³Ì×Ô¶¯»¯Èí¼þ£¬£¬£¬¿ÉÒÔ×ÊÖúÓû§ÊµÏÖÆóÒµÄÚÓªÒµµÄ×Ô¶¯»¯£¬£¬£¬ËüΪÓû§ÌṩÁËÈçERPÆóÒµ×ÊÔ´ÍýÏë¡¢CRM¿Í»§¹ØÏµÖÎÀíµÈ¶àÖÖÖÎÀí¹¦Ð§¡£¡£¡£¡£

2021Äê8ÔÂ11ÈÕ£¬£¬£¬ApacheÐû²¼Ç徲ͨ¸æ£¬£¬£¬¹ûÕæÁËOFBizÖеÄÒ»¸öí§ÒâÎļþÉÏ´«Îó²î£¨CVE-2021-37608£©¡£¡£¡£¡£ÓÉÓÚApache OFBiz±£´æÐ£Ñé¹ýʧ£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÉÏ´«í§ÒâÎļþ£¬£¬£¬²¢Ô¶³ÌÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

Apache OFBiz < 17.12.08

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´¡£¡£¡£¡£½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üе½17.12.08»ò¸ü¸ß°æ±¾¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

http://ofbiz.apache.org/download.html#vulnerabilities

 

²¹¶¡Á´½Ó£º

https://issues.apache.org/jira/browse/OFBIZ-12297

 

0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202108.mbox/%3C40716d3e-150d-10d6-ee27-aca4ae0480fb@apache.org%3E

https://issues.apache.org/jira/browse/OFBIZ-12297

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37608

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-08-12

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¼øºÚµ£±£Íø

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png