Zimbra Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-18

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º

ZimbraCollaboration Server 8.8.11 ֮ǰµÄ°æ±¾¶¼Êܵ½Ó°Ïì¡£¾ßÌåÀ´Ëµ£º

1. Zimbra < 8.7.11 °æ±¾ÖУ¬¹¥»÷ÕßÄܹ»ÔÚÎÞÐèµÇ¼µÄÇé¿öÏ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

2. Zimbra < 8.8.11 °æ±¾ÖУ¬ÔÚ·þÎñ¶ËʹÓà Memcached ×ö»º´æµÄÇé¿öÏ£¬¾­¹ýµÇ¼ÈÏÖ¤ºóµÄ¹¥»÷ÕßÄܹ»ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ


·ì϶¸ÅÊö


Zimbra ÊÇÒ»¼ÒÌṩרҵµÄµç×ÓÓʼþÈí¼þ¿ª·¢¹©¸øÉÌ£¬ÖØÒªÌṩ Zimbra Collaboration Server ºÏ×÷·þÎñÆ÷Ì×¼þ¡¢Zimbra Desktop ÓʼþÖÎÀíÈí¼þµÅ×ʼþ·½ÃæµÄÈí¼þ¡£


3 Ô 13 ÈÕ£¬ ¹ú±í°²È«×êÑÐÔ± tint0 °ä²¼ÁËһƪ²©¿Í£¬Ö¸³ö Zimbra Collaboration Server ϵͳȫ°æ±¾´æÔÚһϵÁзì϶£¬Í¨¹ý¶ñÒâÀûÓÃÄܹ»µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶¡£


·ì϶ϸ½Ú


µ± Zimbra ´æÔÚÏñËÁÒâÎļþ¶ÁÈ¡¡¢XXE£¨XML ±í²¿ÊµÌå×¢È룩 ÕâÖÖ·ì϶ʱ£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶¶ÁÈ¡ localconfig.xml ÅäÖÃÎļþ£¬»ñÈ¡µ½ zimbra admin ldap password£¬²¢Í¨¹ý 7071 admin ¶Ë¿Ú½øÐÐ SOAP AuthRequest ÈÏÖ¤£¬µÃµ½ admin authtoken£¬¶øºó¾ÍÄܹ»ÀûÓà admin authtoken ½øÐÐËÁÒâÎļþÉÏ´«£¬´Ó¶ø´ïµ½Ô¶³Ì´úÂëÖ´ÐеķçÏÕ¡£


¶ø tint0 ²©¿ÍÎÄÕÂÀïÖ¸³ö£¬¼´±ãÔÚ 7071 admin ¶Ë¿Ú×öÁË·À»ðǽÅäÖᢲ»ºÏ±íÊ¢¿ªµÄÇé¿öÏ£¬Ò²Äܹ»ÀûÓôæÔÚÓÚ 443 ͨ³£Óû§¶Ë¿Ú·þÎñÀïÉí·ÝÈÏÖ¤µÄÒ»¸ö¸öÐÔ£¬¹²Í¬ ProxyServlet.doProxy() ²½ÖèÀïµÄ SSRF£¬Í¬ÑùÒ²ÄÜʵÏÖ admin SOAP AuthRequest ÈÏÖ¤£¬µÃµ½ admin authtoken¡£


ÏÂͼΪ¹²Í¬ÀûÓà XXE ºÍ ProxyServlet SSRF ·ì϶Äõ½ admin authtoken ºó£¬Í¨¹ýÎļþÉÏ´«ÔÚ·þÎñ¶ËÖ´ÐÐËÁÒâ´úÂëµÄ±¾µØ²âÊÔ½ØÍ¼£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



³ý´ËÖ®±í£¬ÔÚ Zimbra·þÎñ¶ËʹÓà Memcached ×ö»º´æ·þÎñʱ£¬»¹Äܹ»ÀûÓà SSRF ¹¥»÷ Memcached »º´æ·þÎñ£¬Í¨¹ý·´ÐòÁл¯ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£²»ÍâÓÉÓÚ Zimbra µÄ×°Öùý³ÌÖÐµÄ bug£¬µ¼Öµ¥·þÎñÆ÷µÄÇé¿öÏ£¬Memcached Ö»¹Ü»áÆô¶¯£¬µ«²¢²»»áʹÓã¬Òò¶ø SSRF ¹¥»÷ Memcached ·´ÐòÁл¯µÄÀûÓó¡¾°±ÈÁ¦ÓÐÏÞ¡£


½¨¸´½¨Òé


¸üйٷ½°ä²¼µÄ°²È«²¹¶¡»òÉý¼¶ Zimbra µ½×îа棺https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories¡£


²Î¿¼Á´½Ó


https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories