Apache OFBizÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2021-03-220x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-26295 | ʱ ¼ä | 2021-03-22 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache OFBiz < 17.12.06 |
0x01 Îó²îÏêÇé
OFBizÊÇÒ»¸öÖøÃûµÄµç×ÓÉÌÎñƽ̨£¬£¬£¬£¬£¬£¬ÏÖÒѳÉΪApache¶¥¼¶ÏîÄ¿¡£¡£¡£¡£¡£¡£¡£ËüÌṩÁ˽¨Éè»ùÓÚ×îÐÂJ2EE/XML¹æ·¶ºÍÊÖÒÕ±ê×¼£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚ¹¹½¨´óÖÐÐÍÆóÒµ¼¶¡¢¿çƽ̨¡¢¿çÊý¾Ý¿â¡¢¿çÓ¦ÓÃЧÀÍÆ÷µÄ¶à²ã¡¢ÂþÑÜʽµç×ÓÉÌÎñÀàWEBÓ¦ÓÃϵͳµÄ¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£
2021Äê03ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬¹ûÕæÁËApache OFBizÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26295£©¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚʹÓÃJava RMI£¨JavaÔ¶³ÌÒªÁìŲÓ㩵¼Ö²»Çå¾²µÄ·´ÐòÁл¯£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬×îÖÕ¿ØÖÆApache OFBiz¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁApache OFBiz 17.12.06¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://ofbiz.apache.org/download.html
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202103.mbox/%3Cf8a84478-af53-adb1-21c7-db3174e81b7b@apache.org%3E
https://ofbiz.apache.org/release-notes-17.12.06.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26295
0x04 ʱ¼äÏß
2021-03-21 ApacheÐû²¼Ç徲ͨ¸æ
2021-03-22 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/