΢ÐÅÖ§¸¶SDK XXE·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-03·ì϶±àºÅºÍ¼¶±ð
ÎÞ ¸ßΣ
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
JAVA SDK£¬WxPayAPI_JAVA_v3
·ì϶¸ÅÊö
΢ÐÅÔÚJAVA°æ±¾µÄSDKÖÐÌṩcallback»Øµ÷Ö°ÄÜ£¬ÓÃÀ´Ô®ÊÖÉ̼ҽӹÜÒì²½¸¶¿îÁ˾֣¬¸Ã½Ó¿Ú½ÓÊÜXMLÌåʽµÄÊý¾Ý£¬¹¥»÷ÕßÄܹ»»ú¹Ø¶ñÒâµÄ»Øµ÷Êý¾Ý£¨XMLÌåʽ£©À´ÇÔÈ¡É̼ҷþÎñÆ÷ÉϵÄÈκÎÐÅÏ¢¡£Ò»µ©¹¥»÷Õß»ñµÃÁ˹ؼüÖ§¸¶µÄ°²È«ÃÜÔ¿£¨md5-keyºÍÉ̼ÒÐÅÏ¢£©£¬½«Äܹ»Ö±½ÓʵÏÖ0ÔªÖ§¸¶²É°ìÈκÎÉÌÆ·¡£µ±XMLÔÊÐíÒýÓÃ±í²¿ÊµÌåʱ£¬ºÚ¿ÍÄܹ»Í¨¹ý»ú¹Ø¶ñÒâXMLʵÌåÎļþ£¬ÊµÏÖÔ¶³Ì¶ÁÈ¡ËÁÒâϵͳÎļþ¡¢Ô¶³ÌÖ´ÐÐϵͳºÅÁîµÈһϵÁÐΣÏÕ²Ù×÷£¬ÑϳÁ·çÏÕÉ̼ҷþÎñÆ÷µÄϵͳ°²È«¡£
XXE (XML External Entity Injection) ·ì϶²úÉúÔÚÀûÓ÷¨Ê½½âÎö XML ÊäÈëʱ£¬Ã»Óв»ÈÝ±í²¿ÊµÌåµÄ¼ÓÔØ¡£ÊÇÒ»ÖÖÕë¶ÔʹÓÃXML½»»¥µÄWebÀûÓ÷¨Ê½µÄ¹¥»÷²½Öè¡£
Ŀǰ£¬Î¢ÐŹٷ½ÉÐδ¶ÔSDK½øÐн¨¸´£¬µ«·ì϶ÀûÓÃÐÅÏ¢ÒÔ¼°¹¥»÷·½Ê½Òѱ»¹«¿ª£¬Ó°ÏìÁìÓò¾Þ´ó£¨ÒѾÅû¶³öµÄÓÐİİ¡¢vivoÈ·ÈÏ´æÔڸ÷ì϶£©£¬½¨ÒéÓõ½Î¢ÐÅÖ§¸¶JAVA SDKµÄÆóÒµÂíÉÏ·¢Õ¹×Բ鲢¹Ø×¢Î¢ÐŹٷ½°²È«¹«¸æ¡£
2018Äê7ÔÂ2ºÅ£¬¸Ã·ì϶ÔÚ¹ú±í·ì϶ÅûÂ¶ÍøÕ¾³õ´Î°ä²¼£º

±¾µØÑéÖ¤½ØÍ¼£º

½¨¸´½¨Òé
ÆÚ´ý΢ÐŹٷ½Éý¼¶¹æ»®¡£
Óû§¿ÉʹÓÿª·¢Ëµ»°ÌṩµÄ½ûÓÃ±í²¿ÊµÌåµÄ²½Öè¡£java½ûÓÃ±í²¿ÊµÌåµÄ´úÂëÈçÏ£º
dbf.setExpandEntityReferences(false);
²Î¿¼Á´½Ó
http://seclists.org/fulldisclosure/2018/Jul/3¡£


¾©¹«Íø°²±¸11010802024551ºÅ