¡¾·ì϶¹«¸æ¡¿Apache Tika XML±í²¿ÊµÌå×¢Èë·ì϶(CVE-2025-66516)
°ä²¼¹¦·ò 2025-12-09Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Apache Tika XML±í²¿ÊµÌå×¢Èë·ì϶ | ||
CVE ID | CVE-2025-66516 | ||
·ì϶ÀàÐÍ | XXE | ·¢ÏÖ¹¦·ò | 2025-12-9 |
·ì϶ÆÀ·Ö | 10 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache TikaÊÇÒ»¸ö¿ªÔ´µÄÄÚÈÝ·ÖÎö¹¤¾ß£¬ÓÃÓÚ´Ó¸÷ÀàÎĵµÌåʽÖÐÌáÈ¡Îı¾ºÍÔªÊý¾Ý¡£ËüÖ§³Ö¶àÖÖÎļþÀàÐÍ£¬Ô̺¬PDF¡¢Microsoft OfficeÎĵµ¡¢HTML¡¢XMLµÈ¡£TikaµÄÖ÷ÌâÄ£¿éÌṩͳһµÄAPI£¬Äܹ»ÇáËɼ¯³Éµ½ÆäËûÀûÓÃÖУ¬Ô®ÊÖ¿ª·¢ÈËÔ±×Ô¶¯»¯ÄÚÈÝÌáÈ¡¹ý³Ì¡£Í¨¹ýʹÓÃTika£¬Óû§Äܹ»¶Ô´ó¹æÄ£Îĵµ½øÐзÖÎöºÍË÷Òý£¬¿í·ºÀûÓÃÓÚÊý¾ÝÍÚ¾ò¡¢ËÑË÷ÒýÇæºÍÄÚÈÝÖÎÀíϵͳµÈÁìÓò¡£
2025Äê12ÔÂ9ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Ò»¸öÑϳÁµÄXML±í²¿ÊµÌå×¢È루XXE£©·ì϶£¬Ó°ÏìApache TikaÖ÷ÌâÄ£¿é¡¢Tika½âÎöÆ÷Ä£¿éºÍTika PDF½âÎöÄ£¿é¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚPDFÎļþÖÐǶÈ뾫ÐÄ»ú¹ØµÄXFAÎļþ£¬ÀûÓø÷ì϶ִÐжñÒâµÄ±í²¿ÊµÌåŲÓ㬴ӶøÔì³ÉÐÅϢй¶»òÔ¶³Ì´úÂëÖ´ÐеÈÑϳÁ°²È«·çÏÕ¡£¸Ã·ì϶µÄÑϳÁÐÔÔÚÓÚ£¬Ëü¿ÉÄÜͨ¹ý¶ñÒâµÄXMLÎļþ´¥°ä·¢²¿ÊµÌå×¢È룬¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶»òϵͳ±»Ô¶³Ì½ÚÔ죬¸øÓû§ºÍϵͳ´øÀ´³Á´óµÄ°²È«Íþв¡£¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://tika.apache.org/download.html/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ