¡¾·ì϶¹«¸æ¡¿Apache Struts XWork ×é¼þ XXE ·ì϶(CVE-2025-68493)
°ä²¼¹¦·ò 2026-01-12Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Apache Struts XWork ×é¼þ XXE ·ì϶ | ||
CVE ID | CVE-2025-68493 | ||
·ì϶ÀàÐÍ | XXE | ·¢ÏÖ¹¦·ò | 2026-1-12 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache StrutsÊÇÒ»¸ö»ùÓÚJavaµÄ¿ªÔ´WebÀûÓÿª·¢¿ò¼Ü£¬Ñ¡È¡MVC£¨Ä£ÐÍ-ÊÓͼ-½ÚÔìÆ÷£©¼Ü¹¹Ä£Ê½£¬ÖØÒªÓÃÓÚ¹¹½¨ÆóÒµ¼¶WebÀûÓá£Strutsͨ¹ýÇ峺·Ö²ã£¬½«ÒµÎñÂß¼¡¢Ò³ÃæÕ¹Ê¾ºÍÒªÇó½ÚÔì½âñÌáÉýÀûÓõĿÉÊØ»¤ÐÔÓë¿ÉÀ©´óÐÔ¡£ÆäÖ÷Ìâ×é¼þÔ̺¬Struts Core¡¢XWorkºÍOGNL£¬Ö§³Ö±íµ¥´¦ÖᢲÎÊý°ó¶¨¡¢À¹½ØÆ÷»úÔì¼°½Ã½ÝµÄÅäÖ÷½Ê½¡£Apache StrutsÔøÔÚJava WebÁìÓò±»¿í·ºÀûÓ㬵«Òòº¹ÇàÉÏÂŴγöÏÖ¸ßΣ°²È«·ì϶£¬µ±Ç°Ê¹ÓÃÖÐÐè³ö¸ñÆ÷³Á°æ±¾¸üÐÂÓ밲ȫ¼Ó¹Ì¡£
2026Äê1ÔÂ12ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Apache Struts¿ò¼ÜÖÐXWork×é¼þ´æÔÚµÄÒ»´¦XML±í²¿ÊµÌå×¢È루XXE£©·ì϶¡£¸Ã·ì϶ԴÓÚXWorkÔÚ½âÎöXMLÅäÖÃÎļþʱ£¬Î´¶ÔXML±í²¿ÊµÌå½øÐгä·ÖУÑéÓëÏÞ¶È£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâXMLÄÚÈÝ´¥°ä·¢²¿ÊµÌå½âÎö¡£³É¹¦ÀûÓú󣬿ÉÄÜÔì³ÉÃô¸ÐÊý¾Ýй¶¡¢»Ø¾ø·þÎñ£¨DoS£©ÒÔ¼°·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©µÈ°²È«Ó°Ïì¡£·ì϶ÆÀ·Ö9.8·Ö£¬·ì϶¼¶±ðÑϳÁ¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://struts.apache.org/download.cgi/


¾©¹«Íø°²±¸11010802024551ºÅ