¡¾·ì϶¹«¸æ¡¿CVE-2020-13959 Apache Velocity XSS·ì϶
°ä²¼¹¦·ò 2021-01-180x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-13959 | ʱ ¼ä | 2021-01-18 |
Àà ÐÍ | XSS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Apache Velocity Tools ËùÓа汾 |
0x01 ·ì϶ÏêÇé

Apache VelocityÊÇ»ùÓÚJavaµÄÄ£°åÒýÇæ£¬¿ª·¢ÈËÔ±¿ÉʹÓÃÆäÔÚModel-View-Controller£¨MVC£©¼Ü¹¹ÖÐÉè¼ÆÊÓͼ¡£Velocity ToolsÊÇÒ»¸öÓÉÀà×é³ÉµÄ×ÓÏîÄ¿£¬Ëü½øÒ»²½¼ò»¯ÁËVelocityÔڳ߶ȺÍÍøÂçÀûÓÃÖеɡ£
½üÈÕ£¬Apache Velocity ToolsÖÐÒ»¸öδ¹«¿ªµÄXSS·ì϶£¨CVE-2020-13959£©±»Åû¶£¬¸Ã·ì϶»áÓ°ÏìÆäËùÓа汾¡£Ö»¹Ü¸Ã·ì϶ÉÐδ¹«¿ª£¬µ«Æä½¨¸´·¨Ê½ÔÚ2020Äê11ÔÂ05ÈÕ¾ÍÒÑÔÚGitHubÉϰ䲼¡£
¸Ã·ì϶Ϊ·´ÉäÐÍXSS£¬µ±½Ó¼ûÎÞЧµÄURLʱ£¬"template not found"µÄÃýÎóÒ³Ãæ½«URLµÄ×ÊÔ´õè¾¶²¿ÃŰ´ÔÑù·´Ó³³öÀ´£¬¶ø²»ºÏÆä½øÐÐתÒå¡£
¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÓÕÆÊܺ¦Õßµ¥»÷ÕâÑùµÄURL£¬´Ó¶ø½«Êܺ¦ÕßÊèµ¼ÖÁ±»¸ü¸ÄµÄÍøÂç´¹µöÒ³ÃæÐ¹Â¶ÆäµÇ¼»á»°ÐÅÏ¢£¬»òÕßÍøÂçÒѵǼÓû§µÄ»á»°Cookie£¬²¢½Ù³Ôìä»á»°¡£
Ŀǰ£¬¶à¸öµ±¾ÖÍøÕ¾£¨Èç* .nasa.gov ºÍ* .gov.au£©ÔÚʹÓÃÊÜÓ°ÏìµÄApache Velocity Tools¡£


0x02 ´ëÖý¨Òé
Ŀǰ£¬¸Ã·ì϶µÄ½¨¸´·¨Ê½ÒѾ°ä²¼¡£
ÏÂÔØÁ´½Ó£º
https://github.com/apache/velocity-tools/pull/9
0x03 ²Î¿¼Á´½Ó
http://velocity.apache.org/download.cgi#tools
https://www.bleepingcomputer.com/news/security/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13959
0x04 ¹¦·òÏß
2021-01-15 BleepingComputerÅû¶·ì϶
2021-01-18 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ