¡¾Îó²îͨ¸æ¡¿CVE-2020-13959 Apache Velocity XSSÎó²î

Ðû²¼Ê±¼ä 2021-01-18

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-13959

ʱ   ¼ä

2021-01-18

Àà   ÐÍ

XSS

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Velocity Tools

ËùÓа汾

 

0x01 Îó²îÏêÇé

image.png

 

Apache VelocityÊÇ»ùÓÚJavaµÄÄ£°åÒýÇæ£¬£¬£¬£¬£¬¿ª·¢Ö°Ô±¿ÉʹÓÃÆäÔÚModel-View-Controller£¨MVC£©¼Ü¹¹ÖÐÉè¼ÆÊÓͼ¡£¡£¡£¡£¡£¡£¡£¡£Velocity ToolsÊÇÒ»¸öÓÉÀà×é³ÉµÄ×ÓÏîÄ¿£¬£¬£¬£¬£¬Ëü½øÒ»²½¼ò»¯ÁËVelocityÔÚ±ê×¼ºÍÍøÂçÓ¦ÓÃÖеÉ¡£¡£¡£¡£¡£¡£¡£¡£

¿ËÈÕ£¬£¬£¬£¬£¬Apache Velocity ToolsÖÐÒ»¸öδ¹ûÕæµÄXSSÎó²î£¨CVE-2020-13959£©±»Åû¶£¬£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìÆäËùÓа汾¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¸ÃÎó²îÉÐδ¹ûÕæ£¬£¬£¬£¬£¬µ«ÆäÐÞ¸´³ÌÐòÔÚ2020Äê11ÔÂ05ÈÕ¾ÍÒÑÔÚGitHubÉÏÐû²¼¡£¡£¡£¡£¡£¡£¡£¡£

¸ÃÎó²îΪ·´ÉäÐÍXSS£¬£¬£¬£¬£¬µ±»á¼ûÎÞЧµÄURLʱ£¬£¬£¬£¬£¬"template not found"µÄ¹ýÊ§Ò³Ãæ½«URLµÄ×ÊԴ·¾¶²¿·Ö°´Ô­Ñù·´Ó¦³öÀ´£¬£¬£¬£¬£¬¶ø²î³ØÆä¾ÙÐÐתÒå¡£¡£¡£¡£¡£¡£¡£¡£

¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓÕÆ­Êܺ¦Õßµ¥»÷ÕâÑùµÄURL£¬£¬£¬£¬£¬´Ó¶ø½«Êܺ¦ÕßÖ¸µ¼ÖÁ±»¸ü¸ÄµÄÍøÂç´¹ÂÚÒ³ÃæÐ¹Â¶ÆäµÇ¼»á»°ÐÅÏ¢£¬£¬£¬£¬£¬»òÕßÍøÂçÒѵÇÈÎÃü»§µÄ»á»°Cookie£¬£¬£¬£¬£¬²¢Ð®ÖÆÆä»á»°¡£¡£¡£¡£¡£¡£¡£¡£

ÏÖÔÚ£¬£¬£¬£¬£¬¶à¸öÕþ¸®ÍøÕ¾£¨Èç* .nasa.gov ºÍ* .gov.au£©ÕýÔÚʹÓÃÊÜÓ°ÏìµÄApache Velocity Tools¡£¡£¡£¡£¡£¡£¡£¡£

image.png

image.png

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬£¬£¬¸ÃÎó²îµÄÐÞ¸´³ÌÐòÒѾ­Ðû²¼¡£¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/apache/velocity-tools/pull/9

 

0x03 ²Î¿¼Á´½Ó

http://velocity.apache.org/download.cgi#tools

https://www.bleepingcomputer.com/news/security/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13959

 

0x04 ʱ¼äÏß

2021-01-15  BleepingComputerÅû¶Îó²î

2021-01-18  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png