¡¾·ì϶¹«¸æ¡¿CVE-2020-13959 Apache Velocity XSS·ì϶

°ä²¼¹¦·ò 2021-01-18

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-13959

ʱ   ¼ä

2021-01-18

Àà   ÐÍ

XSS

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Apache Velocity Tools

ËùÓа汾

 

0x01 ·ì϶ÏêÇé

image.png

 

Apache VelocityÊÇ»ùÓÚJavaµÄÄ£°åÒýÇæ£¬¿ª·¢ÈËÔ±¿ÉʹÓÃÆäÔÚModel-View-Controller£¨MVC£©¼Ü¹¹ÖÐÉè¼ÆÊÓͼ ¡£Velocity ToolsÊÇÒ»¸öÓÉÀà×é³ÉµÄ×ÓÏîÄ¿£¬Ëü½øÒ»²½¼ò»¯ÁËVelocityÔڳ߶ȺÍÍøÂçÀûÓÃÖеÉ ¡£

½üÈÕ£¬Apache Velocity ToolsÖÐÒ»¸öδ¹«¿ªµÄXSS·ì϶£¨CVE-2020-13959£©±»Åû¶£¬¸Ã·ì϶»áÓ°ÏìÆäËùÓа汾 ¡£Ö»¹Ü¸Ã·ì϶ÉÐδ¹«¿ª£¬µ«Æä½¨¸´·¨Ê½ÔÚ2020Äê11ÔÂ05ÈÕ¾ÍÒÑÔÚGitHubÉϰ䲼 ¡£

¸Ã·ì϶Ϊ·´ÉäÐÍXSS£¬µ±½Ó¼ûÎÞЧµÄURLʱ£¬"template not found"µÄÃýÎóÒ³Ãæ½«URLµÄ×ÊÔ´õè¾¶²¿ÃŰ´Ô­Ñù·´Ó³³öÀ´£¬¶ø²»ºÏÆä½øÐÐתÒå ¡£

¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÓÕÆ­Êܺ¦Õßµ¥»÷ÕâÑùµÄURL£¬´Ó¶ø½«Êܺ¦ÕßÊèµ¼ÖÁ±»¸ü¸ÄµÄÍøÂç´¹µöÒ³ÃæÐ¹Â¶ÆäµÇ¼»á»°ÐÅÏ¢£¬»òÕßÍøÂçÒѵǼÓû§µÄ»á»°Cookie£¬²¢½Ù³Ôìä»á»° ¡£

Ŀǰ£¬¶à¸öµ±¾ÖÍøÕ¾£¨Èç* .nasa.gov ºÍ* .gov.au£©ÔÚʹÓÃÊÜÓ°ÏìµÄApache Velocity Tools ¡£

image.png

image.png

 

 

0x02 ´ëÖý¨Òé

Ŀǰ£¬¸Ã·ì϶µÄ½¨¸´·¨Ê½ÒѾ­°ä²¼ ¡£

ÏÂÔØÁ´½Ó£º

https://github.com/apache/velocity-tools/pull/9

 

0x03 ²Î¿¼Á´½Ó

http://velocity.apache.org/download.cgi#tools

https://www.bleepingcomputer.com/news/security/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13959

 

0x04 ¹¦·òÏß

2021-01-15  BleepingComputerÅû¶·ì϶

2021-01-18  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png