Apache TapestryÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-27850£©

°ä²¼¹¦·ò 2021-04-16

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-27850

ʱ    ¼ä

2021-04-16

Àà   ÐÍ

RCE

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

Apache TapestryÊÇÒ»ÖÖÓÃJava±àдµÄÃæÏò×é¼þµÄWebÀûÓ÷¨Ê½¿ò¼Ü¡£TapestryÄܹ»ÔÚÖ°ºÎÀûÓ÷¨Ê½·þÎñÆ÷Ϲ¤×÷ £¬²¢ÇÒÄܹ»ÇáËɼ¯³ÉËùÓкó¶Ë £¬ÈçSpring £¬HibernateµÈ¡£

2021Äê04ÔÂ14ÈÕ £¬Apache Tapestry±»Åû¶´æÔÚÒ»¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-27850£© £¬¹¥»÷ÕßÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓ᣸÷ìÏ¶ÈÆ¹ýÁËCVE-2019-0195µÄ½¨¸´·¨Ê½£¨CVSSÆÀ·ÖΪ9.8£©¡£

ÔÚCVE-2019-0195ÖÐ £¬Í¨¹ý°Ñ³Öclasspath×ʲúÎļþURL £¬¹¥»÷ÕßÄܹ»ÔÚclasspathÖв²âÎļþµÄõè¾¶ £¬¶øºóÏÂÔØ¸ÃÎļþ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÒªÇóÔ̺¬HMACÃØÔ¿µÄURL http://localhost:8080/assets/something/services/AppModule.classÀ´ÏÂÔØÎļþAppModule.class¡£

CVE-2019-0195µÄ½¨¸´Ê¹ÓÃÁ˺ÚÃûµ¥¹ýÂË £¬Æä²é³­URLÊÇ·ñÒÔ¡°.class¡±¡¢¡°.properties¡±»ò¡°.xml¡±½áβ £¬µ«ÕâÖÖºÚÃûµ¥¹ýÂËÄܹ»Í¨¹ýÔÚURL½áβÔö³¤¡°/¡±À´Èƹý¡£µ±http://localhost:8080/assets/something/services/AppModule.class/ÔÚºÚÃûµ¥²é³­ºó £¬Ð±Ïß±»°þÀë £¬AppModule.classÎļþ±»¼ÓÔØµ½ÏìÓ¦ÖС£Õâ¸öÀàͨ³£Ô̺¬ÓÃÓÚ¶ÔÐòÁл¯µÄJava¶ÔÏó½øÐÐÊðÃûµÄHMACÃØÔ¿ £¬ÔÚ֪·¸ÃÃÜÔ¿µÄÇé¿öÏ £¬¹¥»÷Õß¾ÍÄܹ»Ç©ÊðJavaÓ×¹¤¾ßÁ´£¨ÀýÈçysoserialµÄCommonsBeanUtils1£© £¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

 

Ó°ÏìÁìÓò

Apache Tapestry 5.4.5

Apache Tapestry 5.5.0

Apache Tapestry 5.6.2

Apache Tapestry 5.7.0

 

0x02 ´ëÖý¨Òé

Ŀǰ¹Ù·½Òѽ¨¸´ÁË´Ë·ì϶ £¬½¨ÒéÉý¼¶µ½ÒÔϰ汾£º

Apache Tapestry 5.4.0-5.6.2 £¬Éý¼¶µ½5.6.2»ò¸ü¸ß°æ±¾¡£

Apache Tapestry 5.7.0 £¬Éý¼¶µ½5.7.1»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://tapestry.apache.org/download.html

 

0x03 ²Î¿¼Á´½Ó

https://lists.apache.org/thread.html/r237ff7f286bda31682c254550c1ebf92b0ec61329b32fbeb2d1c8751%40%3Cusers.tapestry.apache.org%3E

https://nvd.nist.gov/vuln/detail/CVE-2019-0195

https://nvd.nist.gov/vuln/detail/CVE-2021-27850

 

0x04 ¹¦·òÏß

2021-04-14  Johannes MoritzÅû¶·ì϶

2021-04-16  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png