XStream¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-03-15

0x00 Îó²î¸ÅÊö

XStreamÊÇÒ»¸öJava¹¤¾ßºÍXMLÏ໥ת»»µÄ¹¤¾ß£¬£¬£¬£¬£¬ÔÚ½«JavaBeanÐòÁл¯¡¢»ò½«XMLÎļþ·´ÐòÁл¯Ê±£¬£¬£¬£¬£¬Ëü²»ÐèÒªÆäËü¸¨ÖúÀàºÍÓ³ÉäÎļþ£¬£¬£¬£¬£¬ÕâʹµÃXMLÐòÁл¯²»ÔÙ·±Ëö¡£¡£¡£

2021Äê03ÔÂ15ÈÕ£¬£¬£¬£¬£¬XStream¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬¹ûÕæÁËXStreamÖеÄ11¸öÇå¾²Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÔì³É¾Ü¾øÐ§ÀÍ¡¢SSRF¡¢É¾³ýí§ÒâÎļþ¡¢Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî»ò´úÂë¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

±¾´Î¹ûÕæµÄ11¸öÎó²îÈçÏ£º

CVE-ID

ÀàÐÍ

ÏêÇé

CVE-2021-21341

¾Ü¾øÐ§ÀÍ

XStream¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£

CVE-2021-21342

SSRF

XStreamÖб£´æSSRFÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»á¼ûÀ´×ÔÄÚ²¿Íø»òµ±ÌïÖ÷»úÖÐ×ÊÔ´µÄí§ÒâURLµÄÊý¾ÝÁ÷¡£¡£¡£

CVE-2021-21343

í§ÒâÎļþɾ³ý

µ±×÷·ÏÐòÁл¯Ê±£¬£¬£¬£¬£¬Ö»ÒªÖ´ÐÐÀú³Ì¾ßÓÐ×㹻ȨÏÞ£¬£¬£¬£¬£¬XStream±£´æµ±ÌïÖ÷»úí§ÒâÎļþɾ³ýÎó²î¡£¡£¡£

CVE-2021-21344

í§Òâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£

CVE-2021-21345

Ô¶³ÌÏÂÁîÖ´ÐÐ

XStreamÒ×ÊÜÔ¶³ÌÏÂÁîÖ´Ðй¥»÷¡£¡£¡£

CVE-2021-21346

í§Òâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£

CVE-2021-21347

í§Òâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£

CVE-2021-21348

ReDos

XStreamÒ×ÊÜʹÓÃÕýÔò±í´ïʽµÄ¾Ü¾øÐ§ÀÍ£¨ReDos£©¹¥»÷¡£¡£¡£

CVE-2021-21349

SSRF

XStreamÖб£´æSSRFÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»á¼ûÀ´×ÔÄÚ²¿Íø»òµ±ÌïÖ÷»úÖÐ×ÊÔ´µÄí§ÒâURLµÄÊý¾ÝÁ÷¡£¡£¡£

CVE-2021-21350

í§Òâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£

CVE-2021-21351

í§Òâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£

 

XStreamí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21344£©

ÔÚ·´ÐòÁл¯Ê±´¦Öóͷ£µÄÁ÷°üÀ¨ÀàÐÍÐÅÏ¢ÒÔÖØÐ½¨ÉèÒÔǰдÈëµÄ¹¤¾ß£¬£¬£¬£¬£¬XStream»ùÓÚÕâЩÀàÐÍÐÅÏ¢½¨ÉèеÄʵÀý¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓô¦Öóͷ£ºóµÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÖ´ÐдÓÔ¶³ÌЧÀÍÆ÷¼ÓÔØµÄí§Òâ´úÂë¡£¡£¡£

 

Ó°Ïì¹æÄ£

XStream <= 1.4.15

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ1.4.16»ò¸ü¸ß°æ±¾¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://x-stream.github.io/download.html

 

0x03 ²Î¿¼Á´½Ó

https://x-stream.github.io/security.html#workaround

https://x-stream.github.io/CVE-2021-21348.html

https://nvd.nist.gov/vuln/detail/CVE-2021-21341

 

0x04 ʱ¼äÏß

2021-03-15  XStreamÐû²¼Ç徲ͨ¸æ

2021-03-15  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png