Apache TapestryÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-27850£©
°ä²¼¹¦·ò 2021-04-160x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-27850 | ʱ ¼ä | 2021-04-16 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

Apache TapestryÊÇÒ»ÖÖÓÃJava±àдµÄÃæÏò×é¼þµÄWebÀûÓ÷¨Ê½¿ò¼Ü¡£TapestryÄܹ»ÔÚÖ°ºÎÀûÓ÷¨Ê½·þÎñÆ÷Ϲ¤×÷£¬²¢ÇÒÄܹ»ÇáËɼ¯³ÉËùÓкó¶Ë£¬ÈçSpring£¬HibernateµÈ¡£
2021Äê04ÔÂ14ÈÕ£¬Apache Tapestry±»Åû¶´æÔÚÒ»¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-27850£©£¬¹¥»÷ÕßÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓ᣸÷ìÏ¶ÈÆ¹ýÁËCVE-2019-0195µÄ½¨¸´·¨Ê½£¨CVSSÆÀ·ÖΪ9.8£©¡£
ÔÚCVE-2019-0195ÖУ¬Í¨¹ý°Ñ³Öclasspath×ʲúÎļþURL£¬¹¥»÷ÕßÄܹ»ÔÚclasspathÖв²âÎļþµÄõè¾¶£¬¶øºóÏÂÔØ¸ÃÎļþ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÒªÇóÔ̺¬HMACÃØÔ¿µÄURL http://localhost:8080/assets/something/services/AppModule.classÀ´ÏÂÔØÎļþAppModule.class¡£
CVE-2019-0195µÄ½¨¸´Ê¹ÓÃÁ˺ÚÃûµ¥¹ýÂË£¬Æä²é³URLÊÇ·ñÒÔ¡°.class¡±¡¢¡°.properties¡±»ò¡°.xml¡±½á⣬µ«ÕâÖÖºÚÃûµ¥¹ýÂËÄܹ»Í¨¹ýÔÚURL½áβÔö³¤¡°/¡±À´Èƹý¡£µ±http://localhost:8080/assets/something/services/AppModule.class/ÔÚºÚÃûµ¥²é³ºó£¬Ð±Ïß±»°þÀ룬AppModule.classÎļþ±»¼ÓÔØµ½ÏìÓ¦ÖС£Õâ¸öÀàͨ³£Ô̺¬ÓÃÓÚ¶ÔÐòÁл¯µÄJava¶ÔÏó½øÐÐÊðÃûµÄHMACÃØÔ¿£¬ÔÚ֪·¸ÃÃÜÔ¿µÄÇé¿öÏ£¬¹¥»÷Õß¾ÍÄܹ»Ç©ÊðJavaÓ×¹¤¾ßÁ´£¨ÀýÈçysoserialµÄCommonsBeanUtils1£©£¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
Ó°ÏìÁìÓò
Apache Tapestry 5.4.5
Apache Tapestry 5.5.0
Apache Tapestry 5.6.2
Apache Tapestry 5.7.0
0x02 ´ëÖý¨Òé
Ŀǰ¹Ù·½Òѽ¨¸´ÁË´Ë·ì϶£¬½¨ÒéÉý¼¶µ½ÒÔϰ汾£º
Apache Tapestry 5.4.0-5.6.2£¬Éý¼¶µ½5.6.2»ò¸ü¸ß°æ±¾¡£
Apache Tapestry 5.7.0£¬Éý¼¶µ½5.7.1»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://tapestry.apache.org/download.html
0x03 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r237ff7f286bda31682c254550c1ebf92b0ec61329b32fbeb2d1c8751%40%3Cusers.tapestry.apache.org%3E
https://nvd.nist.gov/vuln/detail/CVE-2019-0195
https://nvd.nist.gov/vuln/detail/CVE-2021-27850
0x04 ¹¦·òÏß
2021-04-14 Johannes MoritzÅû¶·ì϶
2021-04-16 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ