¡¾Îó²îͨ¸æ¡¿ownCloud graphapiÐÅϢй¶Îó²î£¨CVE-2023-49103£©

Ðû²¼Ê±¼ä 2023-11-24

 

Ò»¡¢Îó²î¸ÅÊö

CVE   ID

CVE-2023-49103

·¢Ã÷ʱ¼ä

2023-11-24

Àà    ÐÍ

ÐÅϢй¶

µÈ    ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÖØÆ¯ºó

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ֪

 

ownCloud ÊÇÒ»ÖÖÆÕ±éʹÓõÄÓÃÓÚÎļþ¹²ÏíºÍÄÚÈÝЭ×÷µÄ¿ªÔ´Èí¼þ£¬£¬£¬£¬£¬ËüÖ§³ÖÔÚÏßÎĵµ±à¼­ÒÔ¼°ÈÕÀúºÍÁªÏµÈËͬ²½µÈÀ©Õ¹£¬£¬£¬£¬£¬Óû§¿ÉÒÔͨ¹ýÍøÂçä¯ÀÀÆ÷»òÖÖÖÖ¿Í»§¶ËÓ¦ÓóÌÐò»á¼ûÊý¾ÝºÍÎĵµ¡£¡£¡£¡£¡£

11ÔÂ24ÈÕ£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøVSRC¼à²âµ½ownCloud graphapiÖÐÐÞ¸´ÁËÒ»¸öÃô¸ÐÐÅϢй¶Îó²î£¨CVE-2023-49103£©£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ10.0¡£¡£¡£¡£¡£ÓÉÓÚgraphapi Ó¦ÓóÌÐòÖÐÒÀÀµµÚÈý·½ GetPhpInfo.php¿â£¬£¬£¬£¬£¬µ±»á¼û¸Ã URL ʱ£¬£¬£¬£¬£¬»áÏÔʾ PHP ÇéÐΣ¨phpinfo£©µÄÉèÖÃÏêÇ飬£¬£¬£¬£¬ÕâЩÐÅÏ¢°üÀ¨ÍøÂçЧÀÍÆ÷µÄËùÓÐÇéÐαäÁ¿£¬£¬£¬£¬£¬ÔÚÈÝÆ÷»¯°²ÅÅÖУ¬£¬£¬£¬£¬ÕâЩÇéÐαäÁ¿¿ÉÄܰüÀ¨Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ÈçownCloud ÖÎÀíÔ±ÃÜÂë¡¢ÓʼþЧÀÍÆ÷ƾ֤ºÍÔÊÐíÖ¤ÃÜÔ¿µÈ£¬£¬£¬£¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£

±ðµÄ£¬£¬£¬£¬£¬ownCloud oauth2Öл¹ÐÞ¸´ÁË×ÓÓòÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-49104£¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ9.0£©£¬£¬£¬£¬£¬µ±ÆôÓÃAllow Subdomainsʱ£¬£¬£¬£¬£¬ÍþвÕß¿ÉÒÔ´«ÈëÈÆ¹ýÑéÖ¤µÄÌØÖÆÖØ¶¨Ïòurl£¬£¬£¬£¬£¬´Ó¶øÔÊÐíÍþвÕß½«»Øµ÷ÖØ¶¨Ïòµ½Æä¿ØÖƵĶ¥¼¶Óò£»£»£»£»£»ÒÔ¼°ÐÞ¸´ÁËWebDAV API Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-49105£¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ9.8£©£¬£¬£¬£¬£¬¿ÉʹÓÃÔ¤ÊðÃûURLÈÆ¹ýWebDAV Api Éí·ÝÑéÖ¤£¬£¬£¬£¬£¬ÈôÊÇÒÑÖªÊܺ¦ÕßµÄÓû§Ãû²¢ÇÒÊܺ¦ÕßûÓÐÉèÖÃÊðÃûÃÜÔ¿£¨ÕâÊÇĬÈÏÉèÖã©£¬£¬£¬£¬£¬ÔòÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼û¡¢Ð޸Ļòɾ³ýÈκÎÎļþ¡£¡£¡£¡£¡£

 

¶þ¡¢Ó°Ïì¹æÄ£

CVE-2023-49103

ownCloud/graphapi 0.2.x < 0.2.1

ownCloud/graphapi 0.3.x < 0.3.1

CVE-2023-49104

ownCloud/oauth2 < 0.6.1

CVE-2023-49105

10.6.0 <=ownCloud/core< 10.13.1

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ¹Ù·½ÒÑÐû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½×îа汾¡£¡£¡£¡£¡£

ownCloud/graphapiÏÂÔØÁ´½Ó£º

https://marketplace.owncloud.com/apps/graphapi

3.2 ÔÝʱ²½·¥

CVE-2023-49103£º

1.½ö½ûÓà graphapi Ó¦ÓóÌÐò²¢²»¿ÉÏû³ý¸ÃÎó²î£¬£¬£¬£¬£¬¿Éɾ³ýÎļþ owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php¡£¡£¡£¡£¡£

2. ¿É½ûÓà docker-containers ÖÐµÄ phpinfo ¹¦Ð§¡£¡£¡£¡£¡£

3. ½¨Òé¸ü¸ÄÒªº¦Æ¾Ö¤£¬£¬£¬£¬£¬°üÀ¨ownCloud ÖÎÀíÔ±ÃÜÂë¡¢ÓʼþЧÀÍÆ÷ƾ֤¡¢Êý¾Ý¿âƾ֤¡¢¹¤¾ß´æ´¢/S3 »á¼ûÃÜÔ¿µÈ¡£¡£¡£¡£¡£

CVE-2023-49104£º

1.ÔöÇ¿oauth2Ó¦ÓóÌÐòÖеÄÑéÖ¤´úÂë¡£¡£¡£¡£¡£

2. ½ûÓá°Allow Subdomains¡±Ñ¡ÏîÀ´»º½â¸ÃÎó²î¡£¡£¡£¡£¡£

CVE-2023-49105£º

ÈôÊÇûÓÐΪÎļþËùÓÐÕßÉèÖÃÊðÃûÃÜÔ¿£¬£¬£¬£¬£¬Ôò¾Ü¾øÊ¹ÓÃÔ¤ÊðÃûURL¡£¡£¡£¡£¡£

 

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/

https://owncloud.com/security-advisories/subdomain-validation-bypass/

https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-11-24

Ê×´ÎÐû²¼

 


Îå¡¢¸½Â¼

5.1 ¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

5.2 ¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png