Zimbra Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-03-18·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
ZimbraCollaboration Server 8.8.11 ֮ǰµÄ°æ±¾¶¼Êܵ½Ó°Ïì¡£¾ßÌåÀ´Ëµ£º
1. Zimbra < 8.7.11 °æ±¾ÖУ¬¹¥»÷ÕßÄܹ»ÔÚÎÞÐèµÇ¼µÄÇé¿öÏ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ
2. Zimbra < 8.8.11 °æ±¾ÖУ¬ÔÚ·þÎñ¶ËʹÓà Memcached ×ö»º´æµÄÇé¿öÏ£¬¾¹ýµÇ¼ÈÏÖ¤ºóµÄ¹¥»÷ÕßÄܹ»ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ
·ì϶¸ÅÊö
Zimbra ÊÇÒ»¼ÒÌṩרҵµÄµç×ÓÓʼþÈí¼þ¿ª·¢¹©¸øÉÌ£¬ÖØÒªÌṩ Zimbra Collaboration Server ºÏ×÷·þÎñÆ÷Ì×¼þ¡¢Zimbra Desktop ÓʼþÖÎÀíÈí¼þµÅ×ʼþ·½ÃæµÄÈí¼þ¡£
3 Ô 13 ÈÕ£¬ ¹ú±í°²È«×êÑÐÔ± tint0 °ä²¼ÁËһƪ²©¿Í£¬Ö¸³ö Zimbra Collaboration Server ϵͳȫ°æ±¾´æÔÚһϵÁзì϶£¬Í¨¹ý¶ñÒâÀûÓÃÄܹ»µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶¡£
·ì϶ϸ½Ú
µ± Zimbra ´æÔÚÏñËÁÒâÎļþ¶ÁÈ¡¡¢XXE£¨XML ±í²¿ÊµÌå×¢È룩 ÕâÖÖ·ì϶ʱ£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶¶ÁÈ¡ localconfig.xml ÅäÖÃÎļþ£¬»ñÈ¡µ½ zimbra admin ldap password£¬²¢Í¨¹ý 7071 admin ¶Ë¿Ú½øÐÐ SOAP AuthRequest ÈÏÖ¤£¬µÃµ½ admin authtoken£¬¶øºó¾ÍÄܹ»ÀûÓà admin authtoken ½øÐÐËÁÒâÎļþÉÏ´«£¬´Ó¶ø´ïµ½Ô¶³Ì´úÂëÖ´ÐеķçÏÕ¡£
¶ø tint0 ²©¿ÍÎÄÕÂÀïÖ¸³ö£¬¼´±ãÔÚ 7071 admin ¶Ë¿Ú×öÁË·À»ðǽÅäÖᢲ»ºÏ±íÊ¢¿ªµÄÇé¿öÏ£¬Ò²Äܹ»ÀûÓôæÔÚÓÚ 443 ͨ³£Óû§¶Ë¿Ú·þÎñÀïÉí·ÝÈÏÖ¤µÄÒ»¸ö¸öÐÔ£¬¹²Í¬ ProxyServlet.doProxy() ²½ÖèÀïµÄ SSRF£¬Í¬ÑùÒ²ÄÜʵÏÖ admin SOAP AuthRequest ÈÏÖ¤£¬µÃµ½ admin authtoken¡£
ÏÂͼΪ¹²Í¬ÀûÓà XXE ºÍ ProxyServlet SSRF ·ì϶Äõ½ admin authtoken ºó£¬Í¨¹ýÎļþÉÏ´«ÔÚ·þÎñ¶ËÖ´ÐÐËÁÒâ´úÂëµÄ±¾µØ²âÊÔ½ØÍ¼£º
³ý´ËÖ®±í£¬ÔÚ Zimbra·þÎñ¶ËʹÓà Memcached ×ö»º´æ·þÎñʱ£¬»¹Äܹ»ÀûÓà SSRF ¹¥»÷ Memcached »º´æ·þÎñ£¬Í¨¹ý·´ÐòÁл¯ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£²»ÍâÓÉÓÚ Zimbra µÄ×°Öùý³ÌÖÐµÄ bug£¬µ¼Öµ¥·þÎñÆ÷µÄÇé¿öÏ£¬Memcached Ö»¹Ü»áÆô¶¯£¬µ«²¢²»»áʹÓã¬Òò¶ø SSRF ¹¥»÷ Memcached ·´ÐòÁл¯µÄÀûÓó¡¾°±ÈÁ¦ÓÐÏÞ¡£
½¨¸´½¨Òé
¸üйٷ½°ä²¼µÄ°²È«²¹¶¡»òÉý¼¶ Zimbra µ½×îа棺https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories¡£
²Î¿¼Á´½Ó
https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories


¾©¹«Íø°²±¸11010802024551ºÅ