¡¾Îó²îͨ¸æ¡¿CVE-2020-13959 Apache Velocity XSSÎó²î
Ðû²¼Ê±¼ä 2021-01-180x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-13959 | ʱ ¼ä | 2021-01-18 |
Àà ÐÍ | XSS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache Velocity Tools ËùÓа汾 |
0x01 Îó²îÏêÇé

Apache VelocityÊÇ»ùÓÚJavaµÄÄ£°åÒýÇæ£¬£¬£¬£¬£¬¿ª·¢Ö°Ô±¿ÉʹÓÃÆäÔÚModel-View-Controller£¨MVC£©¼Ü¹¹ÖÐÉè¼ÆÊÓͼ¡£¡£¡£¡£¡£¡£¡£¡£Velocity ToolsÊÇÒ»¸öÓÉÀà×é³ÉµÄ×ÓÏîÄ¿£¬£¬£¬£¬£¬Ëü½øÒ»²½¼ò»¯ÁËVelocityÔÚ±ê×¼ºÍÍøÂçÓ¦ÓÃÖеɡ£¡£¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬Apache Velocity ToolsÖÐÒ»¸öδ¹ûÕæµÄXSSÎó²î£¨CVE-2020-13959£©±»Åû¶£¬£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìÆäËùÓа汾¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¸ÃÎó²îÉÐδ¹ûÕæ£¬£¬£¬£¬£¬µ«ÆäÐÞ¸´³ÌÐòÔÚ2020Äê11ÔÂ05ÈÕ¾ÍÒÑÔÚGitHubÉÏÐû²¼¡£¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²îΪ·´ÉäÐÍXSS£¬£¬£¬£¬£¬µ±»á¼ûÎÞЧµÄURLʱ£¬£¬£¬£¬£¬"template not found"µÄ¹ýÊ§Ò³Ãæ½«URLµÄ×ÊԴ·¾¶²¿·Ö°´ÔÑù·´Ó¦³öÀ´£¬£¬£¬£¬£¬¶ø²î³ØÆä¾ÙÐÐתÒå¡£¡£¡£¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓÕÆÊܺ¦Õßµ¥»÷ÕâÑùµÄURL£¬£¬£¬£¬£¬´Ó¶ø½«Êܺ¦ÕßÖ¸µ¼ÖÁ±»¸ü¸ÄµÄÍøÂç´¹ÂÚÒ³ÃæÐ¹Â¶ÆäµÇ¼»á»°ÐÅÏ¢£¬£¬£¬£¬£¬»òÕßÍøÂçÒѵÇÈÎÃü»§µÄ»á»°Cookie£¬£¬£¬£¬£¬²¢Ð®ÖÆÆä»á»°¡£¡£¡£¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬£¬£¬¶à¸öÕþ¸®ÍøÕ¾£¨Èç* .nasa.gov ºÍ* .gov.au£©ÕýÔÚʹÓÃÊÜÓ°ÏìµÄApache Velocity Tools¡£¡£¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬£¬£¬¸ÃÎó²îµÄÐÞ¸´³ÌÐòÒѾÐû²¼¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://github.com/apache/velocity-tools/pull/9
0x03 ²Î¿¼Á´½Ó
http://velocity.apache.org/download.cgi#tools
https://www.bleepingcomputer.com/news/security/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13959
0x04 ʱ¼äÏß
2021-01-15 BleepingComputerÅû¶Îó²î
2021-01-18 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ