CVE-2020-11998 | Apache ActiveMQÔ¶³Ì´úÂëÖ´Ðзì϶
°ä²¼¹¦·ò 2020-09-140x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-11998 | ʱ ¼ä | 2020-09-14 |
Àà ÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | µÈ ¼¶ | ÖÐΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | ½öApache ActiveMQ 5.15.12°æ±¾¡£ |
2020Äê09ÔÂ10ÈÕ£¬ApacheÈí¼þ»ù½ð»á°ä²¼ActiveMQÐÂÎÅÖÐÑë¼þÖдæÔÚÒ»¸ö°²È«·ì϶£¬·ì϶¸ú×ÙΪCVE-2020-11998¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
0x01 ·ì϶ÏêÇé

Apache ActiveMQÊÇApacheÈí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬ËüÊÇÒ»¸ö»ùÓÚÐÂÎŵÄͨѶÖÐÑë¼þ£¬²¢Ö§³ÖJavaÐÂÎÅ·þÎñ¡¢¼¯Èº¡¢Spring FrameworkµÈ¡£
ActiveMQÊÇJMSµÄÒ»¸ö¾ßÌåʵÏÖ£¬Ö§³ÖJMSµÄÁ½ÖÖÐÂÎÅÄ£ÐÍ¡£Ëü×ñÑJMS1.1¹æ·¶£¨Java Message Service£©£¬ÊÇÐÂÎÅÇý¶¯ÖÐÑë¼þÈí¼þ£¨MOM£©¡£ËüΪÆóÒµÐÂÎÅ´«µÝÌṩ¸ß¿ÉÓᢽܳö»úÄÜ¡¢¿ÉÀ©´ó¡¢²»±äºÍ°²È«±£ÏÕ¡£
ActiveMQʹÓÃApacheÐí¿ÉºÍ̸¡£Òò¶ø£¬ÈκÎÈ˶¼Äܹ»Ê¹ÓúÍÅú¸ÄËü¶ø²»Ó÷´À¡ÈκÎŤת¡£Õâ¶ÔÓÚóÒ×´ó½«ActiveMQÓÃÔÚ³ÁÒªÓô¦µÄÈËÓÈΪ¹Ø¼ü¡£ActiveMQµÄÖ¸±êÊÇÔÚ¾¡¿ÉÄܶàµÄƽ̨ºÍ˵»°ÉÏÌṩһ¸ö³ß¶ÈµÄ£¬ÐÂÎÅÇý¶¯µÄÀûÓü¯³É¡£
CVE-2020-11998·ì϶ÐγɵÄÔÓÉÓÚ£º
1. ÔÚÌá½»Ô¤·ÀJMX(Java Management Extensions£¬¼´JavaÖÎÀíÀ©´ó,ÊÇÒ»¸öΪÀûÓ÷¨Ê½¡¢É豸¡¢ÏµÍ³µÈÖ²ÈëÖÎÀíÖ°ÄܵĿò¼Ü)³Áаó¶¨ÖÐÒýÈëÁËregression¡£
2. ½«Ò»¸ö¿ÕµÄ»·¾³Ó³Éä¶ø²»ÊÇÔ̺¬Éí·ÝÑé֤ʹ´¦µÄÓ³Éä´«µÝµ½RMIConnectorServer»áʹµÃActiveMQÈÝÒ×Êܵ½ÒÔϹ¥»÷£º
https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html¡£
3. ÔÚûÓа²È«ÖÎÀíÆ÷µÄÇé¿öÏ£¬Ô¶³Ì¿Í»§¶ËÄܹ»´´½¨Ò»¸öjavax.management.loading.MLet MBean£¬²¢Ê¹ÓÃËü´ÓËÁÒâURL´´½¨ÐµÄMBean£¬Õâ¿ÉÄܻᵼÖ¶ñÒâµÄÔ¶³Ì¿Í»§¶ËʹÓÃJavaÀûÓ÷¨Ê½Ö´ÐÐËÁÒâ´úÂë¡£
0x02 ´ëÖý¨Òé
ĿǰApache¹Ù·½ÒѰ䲼°²È«¸üУ¬½¨ÒéÉý¼¶µ½Apache ActiveMQ 5.15.13°æ±¾¡£
ÏÂÔØÁ´½Ó£º
http://activemq.apache.org/activemq-51513-release
0x03 ÓйØÐÂÎÅ
https://www.secfree.com/vul-150408.html
0x04 ²Î¿¼Á´½Ó
http://activemq.apache.org/security-advisories.data/CVE-2020-11998-announcement.txt
https://nvd.nist.gov/vuln/detail/CVE-2020-11998
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11998
0x05 ¹¦·òÏß
2020-09-10 Apache°ä²¼°²È«²¼¸æ
2020-09-14 VSRC°ä²¼°²È«¹«¸æ



¾©¹«Íø°²±¸11010802024551ºÅ