¡¾·ì϶¹«¸æ¡¿Apache OFBizËÁÒâÎļþÉÏ´«·ì϶ (CVE-2021-37608)

°ä²¼¹¦·ò 2021-08-12



0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-37608

ʱ      ¼ä

2021-08-11

Àà      ÐÍ

ÎļþÉÏ´«

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È


¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ


PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

 

Apache OFBizÊÇÒ»¿îÆóÒµÁ÷³Ì×Ô¶¯»¯Èí¼þ £¬Äܹ»Ô®ÊÖÓû§ÊµÏÔìóÒµÄÚÒµÎñµÄ×Ô¶¯»¯ £¬ËüΪÓû§ÌṩÁËÈçERPÆóÒµ×ÊÔ´¹æ»®¡¢CRM¿Í»§¹ØÏµÖÎÀíµÈ¶àÖÖÖÎÀíÖ°ÄÜ¡£

2021Äê8ÔÂ11ÈÕ £¬Apache°ä²¼°²È«²¼¸æ £¬¹«¿ªÁËOFBizÖеÄÒ»¸öËÁÒâÎļþÉÏ´«·ì϶£¨CVE-2021-37608£©¡£ÓÉÓÚApache OFBiz´æÔÚУÑéÃýÎó £¬¶ñÒâ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÉÏ´«ËÁÒâÎļþ £¬²¢Ô¶³ÌÖ´ÐжñÒâ´úÂë¡£

 

Ó°ÏìÁìÓò

Apache OFBiz < 17.12.08

 

0x02 ´ëÖý¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´¡£½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üе½17.12.08»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

http://ofbiz.apache.org/download.html#vulnerabilities

 

²¹¶¡Á´½Ó£º

https://issues.apache.org/jira/browse/OFBIZ-12297

 

0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202108.mbox/%3C40716d3e-150d-10d6-ee27-aca4ae0480fb@apache.org%3E

https://issues.apache.org/jira/browse/OFBIZ-12297

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37608

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-08-12

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ £¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png