¡¾·ì϶¹«¸æ¡¿Apache Struts XWork ×é¼þ XXE ·ì϶(CVE-2025-68493)

°ä²¼¹¦·ò 2026-01-12

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Apache Struts XWork ×é¼þ XXE ·ì϶

CVE   ID

CVE-2025-68493

·ì϶ÀàÐÍ

XXE

·¢ÏÖ¹¦·ò

2026-1-12

·ì϶ÆÀ·Ö

9.8

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Apache StrutsÊÇÒ»¸ö»ùÓÚJavaµÄ¿ªÔ´WebÀûÓÿª·¢¿ò¼Ü£¬Ñ¡È¡MVC£¨Ä£ÐÍ-ÊÓͼ-½ÚÔìÆ÷£©¼Ü¹¹Ä£Ê½£¬ÖØÒªÓÃÓÚ¹¹½¨ÆóÒµ¼¶WebÀûÓá£Strutsͨ¹ýÇ峺·Ö²ã£¬½«ÒµÎñÂß¼­¡¢Ò³ÃæÕ¹Ê¾ºÍÒªÇó½ÚÔì½âñÌáÉýÀûÓõĿÉÊØ»¤ÐÔÓë¿ÉÀ©´óÐÔ¡£ÆäÖ÷Ìâ×é¼þÔ̺¬Struts Core¡¢XWorkºÍOGNL£¬Ö§³Ö±íµ¥´¦ÖᢲÎÊý°ó¶¨¡¢À¹½ØÆ÷»úÔì¼°½Ã½ÝµÄÅäÖ÷½Ê½¡£Apache StrutsÔøÔÚJava WebÁìÓò±»¿í·ºÀûÓ㬵«Òòº¹ÇàÉÏÂŴγöÏÖ¸ßΣ°²È«·ì϶£¬µ±Ç°Ê¹ÓÃÖÐÐè³ö¸ñÆ÷³Á°æ±¾¸üÐÂÓ밲ȫ¼Ó¹Ì¡£


2026Äê1ÔÂ12ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Apache Struts¿ò¼ÜÖÐXWork×é¼þ´æÔÚµÄÒ»´¦XML±í²¿ÊµÌå×¢È루XXE£©·ì϶¡£¸Ã·ì϶ԴÓÚXWorkÔÚ½âÎöXMLÅäÖÃÎļþʱ£¬Î´¶ÔXML±í²¿ÊµÌå½øÐгä·ÖУÑéÓëÏÞ¶È£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâXMLÄÚÈÝ´¥°ä·¢²¿ÊµÌå½âÎö¡£³É¹¦ÀûÓú󣬿ÉÄÜÔì³ÉÃô¸ÐÊý¾Ýй¶¡¢»Ø¾ø·þÎñ£¨DoS£©ÒÔ¼°·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©µÈ°²È«Ó°Ïì¡£·ì϶ÆÀ·Ö9.8·Ö£¬·ì϶¼¶±ðÑϳÁ¡£


¶þ¡¢Ó°ÏìÁìÓò


2.0.0 <= Apache Struts <= 2.3.37£¨2.3.x ·ÖÖ§ÒÑÖÕ³¡ÊØ»¤£©
2.5.0 <= Apache Struts <= 2.5.33£¨2.5.x ·ÖÖ§ÒÑÖÕ³¡ÊØ»¤£©
6.0.0 <= Apache Struts <= 6.1.0


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬ÒÔ½¨¸´¸Ã·ì϶¡£
Apache Struts >= 6.1.1


ÏÂÔØÁ´½Ó£ºhttps://struts.apache.org/download.cgi/


3.2 һʱ´ëÊ©


×Ô½ç˵SAXParserFactory£ºÍ¨¹ýÉèÖÃxwork.saxParserFactory=Ö¸Ïò×Ô½ç˵¹¤³§À࣬ĬÈϽûÓÃ±í²¿ÊµÌå½âÎö¡£
JVM²ãÃæ½ûÓÃ±í²¿ÊµÌ壺Æô¶¯²ÎÊý²ÎÓ루ÖÿտÉ×è¶ÏËùÓкÍ̸£©£º
-Djavax.xml.accessExternalDTD=
-Djavax.xml.accessExternalSchema=
-Djavax.xml.accessExternalStylesheet=¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://cwiki.apache.org/confluence/display/WW/S2-069/