±¦ÔËÀ³¹Ù·½ÍøÕ¾Ìṩ·ì϶ɨÃèºÍÏû¿Ø¹æ»®

°ä²¼¹¦·ò 2023-02-22

Apache Tomcat¹Ù·½Åû¶1¸ö´æÔÚÓÚApache Commons FileUploadÖеĻؾø·þÎñ·ì϶£¬ÆäÖбàºÅCVE-2023-24998Ϊ¸ßΣ·ì϶¡£±¦ÔËÀ³¹Ù·½ÍøÕ¾µÚÒ»¹¦·ò¶ÔApache Commons FileUpload¹Ù·½°ä²¼µÄ°²È«²¼¸æ½øÐзÖÎöÑÐÅУ¬½áºÏÌ©ºÏÅÌ¹ÅÆ½Ì¨£¨THPangu-OS£©µÄµ××ùÄÜÁ¦£¬Îª¿í´óÓû§Ìṩ¸ø¼±´ëÖÃÖ¸Òý¹æ»®¡£


ÓÉÓÚ Apache Commons FileUpload °æ±¾ 1.5 ֮ǰδÏÞ¶ÈÒª´¦ÖõÄÒªÇó²¿ÃŵÄÊýÁ¿£¬µ¼ÖÂÄܹ»Í¨¹ý¶ñÒâÉÏ´«»òһϵÁÐÉÏ´«À´´¥·¢»Ø¾ø·þÎñ¡£²¢ÇÒ Apache Tomcat ʹÓà Apache Commons FileUpload µÄ´ò°ü³Á¶¨Ãû¸±Õý±¾Ìṩ Jakarta Servlet ¹æ·¶Öнç˵µÄÎļþÉÏ´«Ö°ÄÜ£¬Òò¶ø Apache Tomcat Ò×Êܵ½¸Ã·ì϶ӰÏì¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ŀǰ¸Ã·ì϶POC£¨¸ÅÏëÑéÖ¤´úÂ룩δ¹«¿ª£¬µ«ËæÊ±´æÔÚ±»ÍøÂçºÚ²ú·¢ÏÖ²¢Ôì×÷¹¥»÷ÐÐΪµÄ·çÏÕ¡£Apache Commons ÊÇÒ»¸öרһÓڿɳÁÓà Java ×é¼þ¿ª·¢µÄ Apache ÏîÄ¿£¬¸ÃÏîÄ¿ÓÉ Commons Proper¡¢The Commons Sandbox ºÍThe Commons DormantÈý¸ö²¿ÃÅ×é³É¡£Apache Commons-FileUpload ÊÇ Commons Proper ÖеÄÒ»¸ö×é¼þ£¬Ö¼ÔÚʵÏÖÎļþÉÏ´«¡£ÖÁ´Ë×ÛÊö¸Ã·ì϶µÄ×ÛºÏÆÀ¼¶Îª¡°¸ßΣ¡±¡£


 ½¨¸´½¨Òé 


¹Ù·½ÒѾ­Õë¶Ô·ì϶°ä²¼ÁËÈí¼þ¸üУ¬ÏÂÔØµØÖ·ÈçÏ£º

Apache Commons FileUpload£º

°æ±¾ >= 1.5

ÏÂÔØÁ´½Ó£º

https://commons.apache.org/proper/commons-fileupload/download_fileupload.cgi


Apache Tomcat£º

Apache Tomcat °æ±¾ >= 11.0.0-M3

Apache Tomcat °æ±¾ >= 10.1.5

Apache Tomcat °æ±¾ >= 9.0.71

Apache Tomcat °æ±¾ >= 8.5.85

ÏÂÔØÁ´½Ó£º

https://tomcat.apache.org/index.html


×¢£ºApache Tomcat 11.0.0-M2 δ°ä²¼¡£¸Ã·ì϶ÒÑÔÚ Apache Commons FileUpload °æ±¾ >= 1.5 Öн¨¸´£¬µ«ÐÂÅäÖÃÑ¡Ïî (FileUploadBase#setFileCountMax) ĬÈÏÇé¿öÏÂδÆôÓ㬱ØÐëÃ÷È·ÅäÖá£


 ±¦ÔËÀ³¹Ù·½ÍøÕ¾½â¾ö¹æ»® 


Ò»£º»ùÓÚ·ì϶ɨÃè²úÆ·¾¡¿ì¶Ô×ʲú½øÐзì϶ÆÀ¹À


±¦ÔËÀ³¹Ù·½ÍøÕ¾Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐÊÚȨɨÃ裬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃè¡£


6070°æ±¾Éý¼¶°üΪ607000488£¬Éý¼¶°üÏÂÔØµØÖ·£º

https://venustech.download.venuscloud.cn/


Éý¼¶ºóÒÑÖ§³Ö¸Ã·ì϶.png


ÇëʹÓñ¦ÔËÀ³¹Ù·½ÍøÕ¾Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£


¶þ£º±¦ÔËÀ³¹Ù·½ÍøÕ¾×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨(ASM)ÅŲéÊÜÓ°Ïì×ʲú


±¦ÔËÀ³¹Ù·½ÍøÕ¾×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬¶ÔÈë¿â×ʲú·ì϶Apache Commons FileUpload»Ø¾ø·þÎñ·ì϶£¨CVE-2023-24998£©½øÐÐÖÎÀí£¬ÈçͼËùʾ£º


µý±¨ÖÎÀíÄ£¿éÒÑÈë¿âµÄApache Commons FileUpload»Ø¾ø·þÎñ·ì϶.png


×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨Æ¾¾Ýµý±¨ÐÅÏ¢¸üеķì϶ÊÜÓ°ÏìʵÌ广¶¨ÒÔ¼°ÏÖ³¡×ʲúÖÎÀíÊ·ýµÄ°æ±¾ÐÅÏ¢½øÐÐ×Ô¶¯»¯Åöײ£¬¿ÉµÚÒ»¹¦·òÉäÖÐÊܸ÷ì϶ӰÏìµÄ×ʲú£¬ÈçͼËùʾ£º


µý±¨ÉäÖеÄ×ʲúÐÅÏ¢.png


Èý£º»ùÓÚ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨½øÐйØÁª·ÖÎö


¿í´óÓû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬½øÐйØÁªÕ½ÊõÅäÖ㬽áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°Apache Commons FileUpload»Ø¾ø·þÎñ¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£


ÔÚÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÖУ¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°Apache_Commons_FileUpload_»Ø¾ø·þÎñ·ì϶£¨CVE-2023-24998£©¡±Ö´Ðзì϶ɨÃ蹤×÷£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄ³ÁÒª×ʲú¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÔÚÆ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬Ôö³¤¡°L2_Apache_Commons_»Ø¾ø·þÎñ·ì϶ÀûÓá±£¬Í¨¹ý±¦ÔËÀ³¹Ù·½ÍøÕ¾¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖ±í²¿¹¥»÷ÐÐΪ£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«Apache Commons FileUpload»Ø¾ø·þÎñÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓã»


Ôö³¤¡°L3_Apache_Commons_»Ø¾ø·þÎñ·ì϶ÀûÓóɹ¦¡±£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÅ×Ú¡°L2_Apache_Commons_»Ø¾ø·þÎñ·ì϶ÀûÓá±£¬¹¥»÷Á˾ֵÅ×Ú¡°¹¥»÷³É¹¦¡±£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶÈ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ËÄ£ºATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé


1¡¢ATT&CK¹¥»÷Á´·ÖÎö


ƾ¾Ý¶ÔApache Commons FileUpload»Ø¾ø·þÎñ·ì϶µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬¹¥»÷Á´Éæ¼°µÄATT&CKÕ½ÊõºÍ¼¼Êõ½×¶ÎÔ̺¬£º

Ó°ÏìTA0040£º¶Ëµã»Ø¾ø·þÎñT1499


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2¡¢´ëÖù滮½¨ÒéºÍSOAR¾ç±¾±àÅÅ


ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬½øÐÐ×Ô¶¯»¯´ëÖá£