¡¾Îó²îͨ¸æ¡¿CVE-2020-13959 Apache Velocity XSSÎó²î

Ðû²¼Ê±¼ä 2021-01-18

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-13959

ʱ   ¼ä

2021-01-18

Àà   ÐÍ

XSS

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Velocity Tools

ËùÓа汾

 

0x01 Îó²îÏêÇé

image.png

 

Apache VelocityÊÇ»ùÓÚJavaµÄÄ£°åÒýÇæ£¬£¬£¬¿ª·¢Ö°Ô±¿ÉʹÓÃÆäÔÚModel-View-Controller£¨MVC£©¼Ü¹¹ÖÐÉè¼ÆÊÓͼ¡£¡£¡£¡£Velocity ToolsÊÇÒ»¸öÓÉÀà×é³ÉµÄ×ÓÏîÄ¿£¬£¬£¬Ëü½øÒ»²½¼ò»¯ÁËVelocityÔÚ±ê×¼ºÍÍøÂçÓ¦ÓÃÖеɡ£¡£¡£¡£

¿ËÈÕ£¬£¬£¬Apache Velocity ToolsÖÐÒ»¸öδ¹ûÕæµÄXSSÎó²î£¨CVE-2020-13959£©±»Åû¶£¬£¬£¬¸ÃÎó²î»áÓ°ÏìÆäËùÓа汾¡£¡£¡£¡£Ö»¹Ü¸ÃÎó²îÉÐδ¹ûÕæ£¬£¬£¬µ«ÆäÐÞ¸´³ÌÐòÔÚ2020Äê11ÔÂ05ÈÕ¾ÍÒÑÔÚGitHubÉÏÐû²¼¡£¡£¡£¡£

¸ÃÎó²îΪ·´ÉäÐÍXSS£¬£¬£¬µ±»á¼ûÎÞЧµÄURLʱ£¬£¬£¬"template not found"µÄ¹ýÊ§Ò³Ãæ½«URLµÄ×ÊԴ·¾¶²¿·Ö°´Ô­Ñù·´Ó¦³öÀ´£¬£¬£¬¶ø²î³ØÆä¾ÙÐÐתÒå¡£¡£¡£¡£

¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓÕÆ­Êܺ¦Õßµ¥»÷ÕâÑùµÄURL£¬£¬£¬´Ó¶ø½«Êܺ¦ÕßÖ¸µ¼ÖÁ±»¸ü¸ÄµÄÍøÂç´¹ÂÚÒ³ÃæÐ¹Â¶ÆäµÇ¼»á»°ÐÅÏ¢£¬£¬£¬»òÕßÍøÂçÒѵÇÈÎÃü»§µÄ»á»°Cookie£¬£¬£¬²¢Ð®ÖÆÆä»á»°¡£¡£¡£¡£

ÏÖÔÚ£¬£¬£¬¶à¸öÕþ¸®ÍøÕ¾£¨Èç* .nasa.gov ºÍ* .gov.au£©ÕýÔÚʹÓÃÊÜÓ°ÏìµÄApache Velocity Tools¡£¡£¡£¡£

image.png

image.png

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬¸ÃÎó²îµÄÐÞ¸´³ÌÐòÒѾ­Ðû²¼¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/apache/velocity-tools/pull/9

 

0x03 ²Î¿¼Á´½Ó

http://velocity.apache.org/download.cgi#tools

https://www.bleepingcomputer.com/news/security/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13959

 

0x04 ʱ¼äÏß

2021-01-15  BleepingComputerÅû¶Îó²î

2021-01-18  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png