XStream¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-03-15

0x00 ·ì϶¸ÅÊö

XStreamÊÇÒ»¸öJava¶ÔÏóºÍXMLÏ໥ת»»µÄ¹¤¾ß£¬ÔÚ½«JavaBeanÐòÁл¯¡¢»ò½«XMLÎļþ·´ÐòÁл¯Ê±£¬Ëü²»±ØÒªÆäËü¸¨ÖúÀàºÍÓ³ÉäÎļþ£¬ÕâʹµÃXMLÐòÁл¯²»ÔÙ·±Ëö¡£

2021Äê03ÔÂ15ÈÕ£¬XStream¹Ù·½°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËXStreamÖеÄ11¸ö°²È«·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Ôì³É»Ø¾ø·þÎñ¡¢SSRF¡¢É¾³ýËÁÒâÎļþ¡¢Ô¶³ÌÖ´ÐÐËÁÒâºÅÁî»ò´úÂë¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

±¾´Î¹«¿ªµÄ11¸ö·ì϶ÈçÏ£º

CVE-ID

ÀàÐÍ

ÏêÇé

CVE-2021-21341

»Ø¾ø·þÎñ

XStream¿ÉÄܵ¼Ö»ؾø·þÎñ¡£

CVE-2021-21342

SSRF

XStreamÖдæÔÚSSRF·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûÀ´×ÔÄÚ²¿Íø»ò±¾µØÖ÷»úÖÐ×ÊÔ´µÄËÁÒâURLµÄÊý¾ÝÁ÷¡£

CVE-2021-21343

ËÁÒâÎļþɾ³ý

µ±È¡µÞÐòÁл¯Ê±£¬Ö»ÓÐִǰ¹ý³ÌÓµÓÐ×㹻ȨÏÞ£¬XStream´æÔÚ±¾µØÖ÷»úËÁÒâÎļþɾ³ý·ì϶¡£

CVE-2021-21344

ËÁÒâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£

CVE-2021-21345

Ô¶³ÌºÅÁîÖ´ÐÐ

XStreamÒ×ÊÜÔ¶³ÌºÅÁîÖ´Ðй¥»÷¡£

CVE-2021-21346

ËÁÒâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£

CVE-2021-21347

ËÁÒâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£

CVE-2021-21348

ReDos

XStreamÒ×ÊÜʹÓÃÕýÔò±í°×ʽµÄ»Ø¾ø·þÎñ£¨ReDos£©¹¥»÷¡£

CVE-2021-21349

SSRF

XStreamÖдæÔÚSSRF·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûÀ´×ÔÄÚ²¿Íø»ò±¾µØÖ÷»úÖÐ×ÊÔ´µÄËÁÒâURLµÄÊý¾ÝÁ÷¡£

CVE-2021-21350

ËÁÒâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£

CVE-2021-21351

ËÁÒâ´úÂëÖ´ÐÐ

XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£

 

XStreamËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-21344£©

ÔÚ·´ÐòÁл¯Ê±´¦ÖõÄÁ÷Ô̺¬ÀàÐÍÐÅÏ¢ÒÔ³Áд´½¨ÒÔǰдÈëµÄ¶ÔÏó£¬XStream»ùÓÚÕâЩÀàÐÍÐÅÏ¢´´½¨ÐµÄÊ·ý¡£¹¥»÷ÕßÄܹ»°Ñ³Ö´¦ÖúóµÄÊäÈëÁ÷²¢´úÌæ»ò×¢Èë¶ÔÏ󣬴Ӷøµ¼ÖÂÖ´ÐдÓÔ¶³Ì·þÎñÆ÷¼ÓÔØµÄËÁÒâ´úÂë¡£

 

Ó°ÏìÁìÓò

XStream <= 1.4.15

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´£¬½¨ÒéÉý¼¶ÖÁ1.4.16»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://x-stream.github.io/download.html

 

0x03 ²Î¿¼Á´½Ó

https://x-stream.github.io/security.html#workaround

https://x-stream.github.io/CVE-2021-21348.html

https://nvd.nist.gov/vuln/detail/CVE-2021-21341

 

0x04 ¹¦·òÏß

2021-03-15  XStream°ä²¼°²È«²¼¸æ

2021-03-15  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png