XStream¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-03-150x00 ·ì϶¸ÅÊö
XStreamÊÇÒ»¸öJava¶ÔÏóºÍXMLÏ໥ת»»µÄ¹¤¾ß£¬ÔÚ½«JavaBeanÐòÁл¯¡¢»ò½«XMLÎļþ·´ÐòÁл¯Ê±£¬Ëü²»±ØÒªÆäËü¸¨ÖúÀàºÍÓ³ÉäÎļþ£¬ÕâʹµÃXMLÐòÁл¯²»ÔÙ·±Ëö¡£
2021Äê03ÔÂ15ÈÕ£¬XStream¹Ù·½°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËXStreamÖеÄ11¸ö°²È«·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Ôì³É»Ø¾ø·þÎñ¡¢SSRF¡¢É¾³ýËÁÒâÎļþ¡¢Ô¶³ÌÖ´ÐÐËÁÒâºÅÁî»ò´úÂë¡£
0x01 ·ì϶ÏêÇé

±¾´Î¹«¿ªµÄ11¸ö·ì϶ÈçÏ£º
CVE-ID | ÀàÐÍ | ÏêÇé |
CVE-2021-21341 | »Ø¾ø·þÎñ | XStream¿ÉÄܵ¼Ö»ؾø·þÎñ¡£ |
CVE-2021-21342 | SSRF | XStreamÖдæÔÚSSRF·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûÀ´×ÔÄÚ²¿Íø»ò±¾µØÖ÷»úÖÐ×ÊÔ´µÄËÁÒâURLµÄÊý¾ÝÁ÷¡£ |
CVE-2021-21343 | ËÁÒâÎļþɾ³ý | µ±È¡µÞÐòÁл¯Ê±£¬Ö»ÓÐִǰ¹ý³ÌÓµÓÐ×㹻ȨÏÞ£¬XStream´æÔÚ±¾µØÖ÷»úËÁÒâÎļþɾ³ý·ì϶¡£ |
CVE-2021-21344 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£ |
CVE-2021-21345 | Ô¶³ÌºÅÁîÖ´ÐÐ | XStreamÒ×ÊÜÔ¶³ÌºÅÁîÖ´Ðй¥»÷¡£ |
CVE-2021-21346 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£ |
CVE-2021-21347 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£ |
CVE-2021-21348 | ReDos | XStreamÒ×ÊÜʹÓÃÕýÔò±í°×ʽµÄ»Ø¾ø·þÎñ£¨ReDos£©¹¥»÷¡£ |
CVE-2021-21349 | SSRF | XStreamÖдæÔÚSSRF·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûÀ´×ÔÄÚ²¿Íø»ò±¾µØÖ÷»úÖÐ×ÊÔ´µÄËÁÒâURLµÄÊý¾ÝÁ÷¡£ |
CVE-2021-21350 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£ |
CVE-2021-21351 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£ |
XStreamËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-21344£©
ÔÚ·´ÐòÁл¯Ê±´¦ÖõÄÁ÷Ô̺¬ÀàÐÍÐÅÏ¢ÒÔ³Áд´½¨ÒÔǰдÈëµÄ¶ÔÏó£¬XStream»ùÓÚÕâЩÀàÐÍÐÅÏ¢´´½¨ÐµÄÊ·ý¡£¹¥»÷ÕßÄܹ»°Ñ³Ö´¦ÖúóµÄÊäÈëÁ÷²¢´úÌæ»ò×¢Èë¶ÔÏ󣬴Ӷøµ¼ÖÂÖ´ÐдÓÔ¶³Ì·þÎñÆ÷¼ÓÔØµÄËÁÒâ´úÂë¡£
Ó°ÏìÁìÓò
XStream <= 1.4.15
0x02 ´ëÖý¨Òé
ĿǰÕâЩ·ì϶ÒѾ½¨¸´£¬½¨ÒéÉý¼¶ÖÁ1.4.16»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://x-stream.github.io/download.html
0x03 ²Î¿¼Á´½Ó
https://x-stream.github.io/security.html#workaround
https://x-stream.github.io/CVE-2021-21348.html
https://nvd.nist.gov/vuln/detail/CVE-2021-21341
0x04 ¹¦·òÏß
2021-03-15 XStream°ä²¼°²È«²¼¸æ
2021-03-15 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ