XStream¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-03-150x00 Îó²î¸ÅÊö
XStreamÊÇÒ»¸öJava¹¤¾ßºÍXMLÏ໥ת»»µÄ¹¤¾ß£¬£¬£¬£¬£¬ÔÚ½«JavaBeanÐòÁл¯¡¢»ò½«XMLÎļþ·´ÐòÁл¯Ê±£¬£¬£¬£¬£¬Ëü²»ÐèÒªÆäËü¸¨ÖúÀàºÍÓ³ÉäÎļþ£¬£¬£¬£¬£¬ÕâʹµÃXMLÐòÁл¯²»ÔÙ·±Ëö¡£¡£¡£
2021Äê03ÔÂ15ÈÕ£¬£¬£¬£¬£¬XStream¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬¹ûÕæÁËXStreamÖеÄ11¸öÇå¾²Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÔì³É¾Ü¾øÐ§ÀÍ¡¢SSRF¡¢É¾³ýí§ÒâÎļþ¡¢Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî»ò´úÂë¡£¡£¡£
0x01 Îó²îÏêÇé
±¾´Î¹ûÕæµÄ11¸öÎó²îÈçÏ£º
CVE-ID | ÀàÐÍ | ÏêÇé |
CVE-2021-21341 | ¾Ü¾øÐ§ÀÍ | XStream¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£ |
CVE-2021-21342 | SSRF | XStreamÖб£´æSSRFÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»á¼ûÀ´×ÔÄÚ²¿Íø»òµ±ÌïÖ÷»úÖÐ×ÊÔ´µÄí§ÒâURLµÄÊý¾ÝÁ÷¡£¡£¡£ |
CVE-2021-21343 | í§ÒâÎļþɾ³ý | µ±×÷·ÏÐòÁл¯Ê±£¬£¬£¬£¬£¬Ö»ÒªÖ´ÐÐÀú³Ì¾ßÓÐ×㹻ȨÏÞ£¬£¬£¬£¬£¬XStream±£´æµ±ÌïÖ÷»úí§ÒâÎļþɾ³ýÎó²î¡£¡£¡£ |
CVE-2021-21344 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£ |
CVE-2021-21345 | Ô¶³ÌÏÂÁîÖ´ÐÐ | XStreamÒ×ÊÜÔ¶³ÌÏÂÁîÖ´Ðй¥»÷¡£¡£¡£ |
CVE-2021-21346 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£ |
CVE-2021-21347 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£ |
CVE-2021-21348 | ReDos | XStreamÒ×ÊÜʹÓÃÕýÔò±í´ïʽµÄ¾Ü¾øÐ§ÀÍ£¨ReDos£©¹¥»÷¡£¡£¡£ |
CVE-2021-21349 | SSRF | XStreamÖб£´æSSRFÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»á¼ûÀ´×ÔÄÚ²¿Íø»òµ±ÌïÖ÷»úÖÐ×ÊÔ´µÄí§ÒâURLµÄÊý¾ÝÁ÷¡£¡£¡£ |
CVE-2021-21350 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£ |
CVE-2021-21351 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£ |
XStreamí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21344£©
ÔÚ·´ÐòÁл¯Ê±´¦Öóͷ£µÄÁ÷°üÀ¨ÀàÐÍÐÅÏ¢ÒÔÖØÐ½¨ÉèÒÔǰдÈëµÄ¹¤¾ß£¬£¬£¬£¬£¬XStream»ùÓÚÕâЩÀàÐÍÐÅÏ¢½¨ÉèеÄʵÀý¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓô¦Öóͷ£ºóµÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÖ´ÐдÓÔ¶³ÌЧÀÍÆ÷¼ÓÔØµÄí§Òâ´úÂë¡£¡£¡£
Ó°Ïì¹æÄ£
XStream <= 1.4.15
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ1.4.16»ò¸ü¸ß°æ±¾¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://x-stream.github.io/download.html
0x03 ²Î¿¼Á´½Ó
https://x-stream.github.io/security.html#workaround
https://x-stream.github.io/CVE-2021-21348.html
https://nvd.nist.gov/vuln/detail/CVE-2021-21341
0x04 ʱ¼äÏß
2021-03-15 XStreamÐû²¼Ç徲ͨ¸æ
2021-03-15 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/