¡¾Îó²îͨ¸æ¡¿Spring SecurityÇå¾²ÈÆ¹ýÎó²î£¨CVE-2023-34034£©

Ðû²¼Ê±¼ä 2023-08-10

Ò»¡¢Îó²î¸ÅÊö

CVE   ID

CVE-2023-34034

·¢Ã÷ʱ¼ä

2023-07-18

Àà    ÐÍ

Çå¾²ÈÆ¹ý

µÈ    ¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÖØÆ¯ºó

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ֪

 

Spring SecurityÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢ÇҸ߶ȿɶ¨ÖƵÄÉí·ÝÑéÖ¤ºÍ»á¼û¿ØÖÆ¿ò¼Ü¡£¡£¡£Spring WebFlux ÊÇSpring Framework 5.0 ÖÐÒýÈëµÄÒ»ÖÖÏìӦʽWeb¿ò¼Ü£¬£¬£¬£¬Æä½¹µãÖ¼ÔÚ´¦Öóͷ£Òì²½¡¢·ÇÛÕ±ÕºÍÏìӦʽ±à³Ì¹æ·¶¡£¡£¡£

8ÔÂ10ÈÕ£¬£¬£¬£¬¼øºÚµ£±£ÍøVSRC¼à²âµ½Spring SecurityÇå¾²ÈÆ¹ýÎó²î£¨CVE-2023-34034£©µÄϸ½Ú¼°PoCÔÚ»¥ÁªÍøÉϹûÕæ£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·Ö×î¸ßΪ9.8¡£¡£¡£

ÔÚSpring WebFlux Ó¦ÓóÌÐòµÄSpring SecurityÉèÖÃÖÐʹÓÃÎÞǰ׺˫ͨÅä·ûģʽ£¨¡°**¡±£©»áµ¼ÖÂSpring SecurityºÍSpring WebFluxÖ®¼äµÄģʽ²»Æ¥Å䣬£¬£¬£¬¿ÉÄܵ¼ÖÂÇå¾²ÈÆ¹ý£¬£¬£¬£¬¿ÉʹÓøÃÎó²îÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎÏ»á¼ûÌØÈ¨¶Ëµã¡£¡£¡£

 

¶þ¡¢Ó°Ïì¹æÄ£

Spring Security 6.1.0 - 6.1.1

Spring Security 6.0.0 - 6.0.4

Spring Security 5.8.0 - 5.8.4

Spring Security 5.7.0 - 5.7.9

Spring Security 5.6.0 - 5.6.11

×¢£ºÇкÏÒÔÏÂÌõ¼þµÄÓ¦ÓóÌÐòÒ×ÊܸÃÎó²î¹¥»÷£º

l  Web Ó¦ÓóÌÐòʹÓÃSpring WebFlux ¿ò¼Ü£¨Ê¹ÓýϾɵÄSpring MVC¿ò¼ÜµÄÓ¦ÓóÌÐò²»ÊÜÓ°Ï죩¡£¡£¡£

l  ¸ÃWeb Ó¦ÓóÌÐòʹÓÃÁËÉÏÊö±£´æÎó²îµÄSpring Security °æ±¾¡£¡£¡£

l  webÓ¦ÓóÌÐòʹÓà URL ·¾¶¹ýÂËÉèÖà Spring Security»á¼û¹æÔò¡£¡£¡£URL ·¾¶Ä£Ê½²»ÒÔÕýб¸Ü×Ö·û (/) ¿ªÍ·¡£¡£¡£ÈôÊÇ URL ·¾¶°üÀ¨¶à¶ÎͨÅä·û ( **)£¬£¬£¬£¬Ôò»áÔöÌíÎó²îµÄÑÏÖØÐÔ¡£¡£¡£ÀýÈ磬£¬£¬£¬ÓÉÓÚ¸ÃÎó²î£¬£¬£¬£¬¡°admin/**¡±¹æÔò²»»áÆ¥ÅäÈκΠURL£¬£¬£¬£¬ÓÉÓÚËüµÄ¿ªÍ·È±ÉÙб¸Ü/£¬£¬£¬£¬µ¼ÖÂÈκÎÈ˶¼¿ÉÒÔ»á¼û admin/ ϵÄËùÓÐÍøÒ³¡£¡£¡£


Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º

Spring Security >= 6.1.2

Spring Security >= 6.0.5

Spring Security >= 5.8.5

Spring Security >= 5.7.10

Spring Security >= 5.6.12

ÒÔÉϰ汾ÐèÒªSpring Framework °æ±¾£º

Spring Framework >= 6.0.11

Spring Framework >= 5.3.29

Spring Framework >= 5.2.25

ÏÂÔØÁ´½Ó£º

https://spring.io/projects

3.2 ÔÝʱ²½·¥

¿ÉÔÚ Spring Security ÖÐʹÓõÄÈκΠURL ¹ýÂËÆ÷ÖÐÌí¼Óǰµ¼Õýб¸Ü/À´»º½â¸ÃÎó²î£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬½«pathMatchers("admin/**") Ìæ»»Îª pathMatchers("/admin/**")¡£¡£¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://spring.io/security/cve-2023-34034

https://jfrog.com/blog/spring-webflux-cve-2023-34034-write-up-and-proof-of-concept/


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-08-10

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£

5.2 ¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png