¡¾Îó²îͨ¸æ¡¿CVE-2020-13959 Apache Velocity XSSÎó²î
Ðû²¼Ê±¼ä 2021-01-180x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-13959 | ʱ ¼ä | 2021-01-18 |
Àà ÐÍ | XSS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache Velocity Tools ËùÓа汾 |
0x01 Îó²îÏêÇé
Apache VelocityÊÇ»ùÓÚJavaµÄÄ£°åÒýÇæ£¬£¬£¬¿ª·¢Ö°Ô±¿ÉʹÓÃÆäÔÚModel-View-Controller£¨MVC£©¼Ü¹¹ÖÐÉè¼ÆÊÓͼ¡£¡£¡£¡£Velocity ToolsÊÇÒ»¸öÓÉÀà×é³ÉµÄ×ÓÏîÄ¿£¬£¬£¬Ëü½øÒ»²½¼ò»¯ÁËVelocityÔÚ±ê×¼ºÍÍøÂçÓ¦ÓÃÖеɡ£¡£¡£¡£
¿ËÈÕ£¬£¬£¬Apache Velocity ToolsÖÐÒ»¸öδ¹ûÕæµÄXSSÎó²î£¨CVE-2020-13959£©±»Åû¶£¬£¬£¬¸ÃÎó²î»áÓ°ÏìÆäËùÓа汾¡£¡£¡£¡£Ö»¹Ü¸ÃÎó²îÉÐδ¹ûÕæ£¬£¬£¬µ«ÆäÐÞ¸´³ÌÐòÔÚ2020Äê11ÔÂ05ÈÕ¾ÍÒÑÔÚGitHubÉÏÐû²¼¡£¡£¡£¡£
¸ÃÎó²îΪ·´ÉäÐÍXSS£¬£¬£¬µ±»á¼ûÎÞЧµÄURLʱ£¬£¬£¬"template not found"µÄ¹ýÊ§Ò³Ãæ½«URLµÄ×ÊԴ·¾¶²¿·Ö°´ÔÑù·´Ó¦³öÀ´£¬£¬£¬¶ø²î³ØÆä¾ÙÐÐתÒå¡£¡£¡£¡£
¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓÕÆÊܺ¦Õßµ¥»÷ÕâÑùµÄURL£¬£¬£¬´Ó¶ø½«Êܺ¦ÕßÖ¸µ¼ÖÁ±»¸ü¸ÄµÄÍøÂç´¹ÂÚÒ³ÃæÐ¹Â¶ÆäµÇ¼»á»°ÐÅÏ¢£¬£¬£¬»òÕßÍøÂçÒѵÇÈÎÃü»§µÄ»á»°Cookie£¬£¬£¬²¢Ð®ÖÆÆä»á»°¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬¶à¸öÕþ¸®ÍøÕ¾£¨Èç* .nasa.gov ºÍ* .gov.au£©ÕýÔÚʹÓÃÊÜÓ°ÏìµÄApache Velocity Tools¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬¸ÃÎó²îµÄÐÞ¸´³ÌÐòÒѾÐû²¼¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://github.com/apache/velocity-tools/pull/9
0x03 ²Î¿¼Á´½Ó
http://velocity.apache.org/download.cgi#tools
https://www.bleepingcomputer.com/news/security/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13959
0x04 ʱ¼äÏß
2021-01-15 BleepingComputerÅû¶Îó²î
2021-01-18 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/