¡¾·ì϶¹«¸æ¡¿Apache Commons FileUpload»Ø¾ø·þÎñ·ì϶£¨CVE-2023-24998£©

°ä²¼¹¦·ò 2023-02-21


0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2023-24998

·¢ÏÖ¹¦·ò

2023-02-21

Àà    ÐÍ

Dos

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

ËùÐèȨÏÞ

ÎÞ

¹¥»÷¸´ÔÓ¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

Apache CommonsÊÇÒ»¸öרһÓڿɳÁÓÃJava×é¼þ¿ª·¢µÄ Apache ÏîÄ¿  £¬¸ÃÏîÄ¿ÓÉCommons Proper¡¢The Commons SandboxºÍThe Commons DormantÈý¸ö²¿ÃÅ×é³É¡£Apache Commons-FileUploadÊÇCommons ProperÖеÄÒ»¸ö×é¼þ  £¬Ö¼ÔÚʵÏÖÎļþÉÏ´«¡£

2ÔÂ20ÈÕ  £¬Apache°ä²¼°²È«²¼¸æ  £¬½¨¸´ÁËApache Commons FileUploadÖеĻؾø·þÎñ·ì϶£¨CVE-2023-24998£©¡£ÓÉÓÚApache Commons FileUpload°æ±¾1.5֮ǰδÏÞ¶ÈÒª´¦ÖõÄÒªÇó²¿ÃŵÄÊýÁ¿  £¬µ¼ÖÂÄܹ»Í¨¹ý¶ñÒâÉÏ´«»òһϵÁÐÉÏ´«À´´¥·¢»Ø¾ø·þÎñ¡£

´Ë±í  £¬ÓÉÓÚApache TomcatʹÓÃApache Commons FileUploadµÄ´ò°ü³Á¶¨Ãû¸±Õý±¾ÌṩJakarta Servlet¹æ·¶Öнç˵µÄÎļþÉÏ´«Ö°ÄÜ  £¬Òò¶øApache TomcatÒ²ÈÝÒ×Êܵ½¸Ã·ì϶ӰÏì¡£

 

Ó°ÏìÁìÓò

Apache Commons FileUpload£º°æ±¾1.0-beta-1 - 1.4

Apache Tomcat£º

Apache Tomcat °æ±¾11.0.0-M1

Apache Tomcat °æ±¾10.1.0-M1 - 10.1.4

Apache Tomcat °æ±¾9.0.0-M1 - 9.0.70

Apache Tomcat °æ±¾8.5.0 - 8.5.84

 

0x02 °²È«½¨Òé

Ŀǰ¸Ã·ì϶ÒѾ­½¨¸´  £¬ÊÜÓ°ÏìÓû§¿ÉʵʱÉý¼¶µ½ÒÔϰ汾£º

Apache Commons FileUpload£º°æ±¾ >= 1.5

ÏÂÔØÁ´½Ó£º

https://commons.apache.org/proper/commons-fileupload/download_fileupload.cgi

Apache Tomcat£º

Apache Tomcat °æ±¾ >= 11.0.0-M3

Apache Tomcat °æ±¾ >= 10.1.5

Apache Tomcat °æ±¾ >= 9.0.71

Apache Tomcat °æ±¾ >= 8.5.85

ÏÂÔØÁ´½Ó£º

https://tomcat.apache.org/index.html

×¢£ºApache Tomcat 11.0.0-M2 δ°ä²¼¡£

¸Ã·ì϶ÒÑÔÚApache Commons FileUpload°æ±¾ >= 1.5Öн¨¸´  £¬µ«ÐÂÅäÖÃÑ¡Ïî(FileUploadBase#setFileCountMax) ĬÈÏÇé¿öÏÂδÆôÓà  £¬±ØÐëÃ÷È·ÅäÖá£


0x03 ²Î¿¼Á´½Ó

https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy

https://commons.apache.org/proper/commons-fileupload/security-reports.html

https://tomcat.apache.org/security-10.html

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2023-02-21

³õ´Î°ä²¼

 

 

0x05 ¸½Â¼

GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Äê  £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏà  £¬¹«Ë¾Ô±¹¤6000ÓàÈË  £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö  £¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´  £¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ  £¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦  £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

 

¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ  £¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png