Apache OFBizÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ðû²¼Ê±¼ä 2021-03-22

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-26295

ʱ   ¼ä

2021-03-22

Àà   ÐÍ

 RCE

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache OFBiz < 17.12.06

 

0x01 Îó²îÏêÇé

image.png

 

OFBizÊÇÒ»¸öÖøÃûµÄµç×ÓÉÌÎñƽ̨£¬£¬£¬ £¬£¬£¬ÏÖÒѳÉΪApache¶¥¼¶ÏîÄ¿¡£¡£¡£¡£¡£ ¡£¡£ËüÌṩÁ˽¨Éè»ùÓÚ×îÐÂJ2EE/XML¹æ·¶ºÍÊÖÒÕ±ê×¼£¬£¬£¬ £¬£¬£¬Ö÷ÒªÓÃÓÚ¹¹½¨´óÖÐÐÍÆóÒµ¼¶¡¢¿çƽ̨¡¢¿çÊý¾Ý¿â¡¢¿çÓ¦ÓÃЧÀÍÆ÷µÄ¶à²ã¡¢ÂþÑÜʽµç×ÓÉÌÎñÀàWEBÓ¦ÓÃϵͳµÄ¿ò¼Ü¡£¡£¡£¡£¡£ ¡£¡£

2021Äê03ÔÂ21ÈÕ£¬£¬£¬ £¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬ £¬£¬£¬¹ûÕæÁËApache OFBizÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26295£©¡£¡£¡£¡£¡£ ¡£¡£ÓÉÓÚʹÓÃJava RMI£¨JavaÔ¶³ÌÒªÁìŲÓ㩵¼Ö²»Çå¾²µÄ·´ÐòÁл¯£¬£¬£¬ £¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔ¶³ÌÖ´ÐдúÂ룬£¬£¬ £¬£¬£¬×îÖÕ¿ØÖÆApache OFBiz¡£¡£¡£¡£¡£ ¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î£¬£¬£¬ £¬£¬£¬½¨ÒéÉý¼¶ÖÁApache OFBiz 17.12.06¡£¡£¡£¡£¡£ ¡£¡£

ÏÂÔØÁ´½Ó£º

https://ofbiz.apache.org/download.html

 

0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202103.mbox/%3Cf8a84478-af53-adb1-21c7-db3174e81b7b@apache.org%3E

https://ofbiz.apache.org/release-notes-17.12.06.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26295

 

0x04 ʱ¼äÏß

2021-03-21  ApacheÐû²¼Ç徲ͨ¸æ

2021-03-22  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png