¡¾Îó²îͨ¸æ¡¿Apache Any23 Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40146£©

Ðû²¼Ê±¼ä 2021-09-13

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-40146

ʱ      ¼ä

2021-09-11

Àà      ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Any23 < 2.5

¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

Apache Everything To Triples (Any23) ÊÇÒ»¸ö¿â¡¢Web ЧÀͺÍÏÂÁîÐй¤¾ß£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚ´ÓÖÖÖÖ Web ÎĵµÖÐÌáÈ¡ RDF ÃûÌõĽṹ»¯Êý¾Ý¡£¡£¡£¡£¡£

2021Äê9ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬ApacheÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËApache Any23ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40146£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î±£´æÓÚAny23 YAMLExtractor.javaÖУ¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓôËÎó²îÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÔÚAny23µÄStreamUtils.javaÎļþÖз¢Ã÷Ò»¸öXMLÍⲿʵÌ壨XXE£©×¢ÈëÎó²î£¨CVE-2021-38555£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î×ÌÈÅÓ¦ÓóÌÐò¶ÔXMLµÄ´¦Öóͷ££¬£¬£¬£¬£¬£¬£¬ÊµÏÖÉó²éÓ¦ÓÃЧÀÍÆ÷ÎļþϵͳÉϵÄÎļþ£¬£¬£¬£¬£¬£¬£¬²¢ÓëÓ¦ÓóÌÐò×Ô¼º¿ÉÒÔ»á¼ûµÄÈκκó¶Ë»òÍⲿϵͳ¾ÙÐн»»¥¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

Apache Any23°æ±¾ < 2.5

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÉÏÊöÎó²îÒÑÔÚApache Any23 2.5°æ±¾ÖÐÐÞ¸´£¨ÒÑÐû²¼£©£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üС£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

http://any23.apache.org/download.html

 

0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202109.mbox/%3Cpony-b7497055821405926d63668ab1112e0f108e2346-24b556bb9c8200804abff20daacf3205f453d88d@announce.apache.org%3E

http://mail-archives.apache.org/mod_mbox/www-announce/202109.mbox/%3Cpony-b7497055821405926d63668ab1112e0f108e2346-fc7885638697ea0fec1186b16e985c55e5d49a83@announce.apache.org%3E

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-09-13

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¼øºÚµ£±£Íø

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png