Zimbra Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-18

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º

ZimbraCollaboration Server 8.8.11 ֮ǰµÄ°æ±¾¶¼Êܵ½Ó°Ïì¡£¾ßÌåÀ´Ëµ£º

1. Zimbra < 8.7.11 °æ±¾ÖÐ £¬¹¥»÷ÕßÄܹ»ÔÚÎÞÐèµÇ¼µÄÇé¿öÏ £¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

2. Zimbra < 8.8.11 °æ±¾ÖÐ £¬ÔÚ·þÎñ¶ËʹÓà Memcached ×ö»º´æµÄÇé¿öÏ £¬¾­¹ýµÇ¼ÈÏÖ¤ºóµÄ¹¥»÷ÕßÄܹ»ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ


·ì϶¸ÅÊö


Zimbra ÊÇÒ»¼ÒÌṩרҵµÄµç×ÓÓʼþÈí¼þ¿ª·¢¹©¸øÉÌ £¬ÖØÒªÌṩ Zimbra Collaboration Server ºÏ×÷·þÎñÆ÷Ì×¼þ¡¢Zimbra Desktop ÓʼþÖÎÀíÈí¼þµÅ×ʼþ·½ÃæµÄÈí¼þ¡£


3 Ô 13 ÈÕ £¬ ¹ú±í°²È«×êÑÐÔ± tint0 °ä²¼ÁËһƪ²©¿Í £¬Ö¸³ö Zimbra Collaboration Server ϵͳȫ°æ±¾´æÔÚһϵÁзì϶ £¬Í¨¹ý¶ñÒâÀûÓÃÄܹ»µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶¡£


·ì϶ϸ½Ú


µ± Zimbra ´æÔÚÏñËÁÒâÎļþ¶ÁÈ¡¡¢XXE£¨XML ±í²¿ÊµÌå×¢È룩 ÕâÖÖ·ì϶ʱ £¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶¶ÁÈ¡ localconfig.xml ÅäÖÃÎļþ £¬»ñÈ¡µ½ zimbra admin ldap password £¬²¢Í¨¹ý 7071 admin ¶Ë¿Ú½øÐÐ SOAP AuthRequest ÈÏÖ¤ £¬µÃµ½ admin authtoken £¬¶øºó¾ÍÄܹ»ÀûÓà admin authtoken ½øÐÐËÁÒâÎļþÉÏ´« £¬´Ó¶ø´ïµ½Ô¶³Ì´úÂëÖ´ÐеķçÏÕ¡£


¶ø tint0 ²©¿ÍÎÄÕÂÀïÖ¸³ö £¬¼´±ãÔÚ 7071 admin ¶Ë¿Ú×öÁË·À»ðǽÅäÖᢲ»ºÏ±íÊ¢¿ªµÄÇé¿öÏ £¬Ò²Äܹ»ÀûÓôæÔÚÓÚ 443 ͨ³£Óû§¶Ë¿Ú·þÎñÀïÉí·ÝÈÏÖ¤µÄÒ»¸ö¸öÐÔ £¬¹²Í¬ ProxyServlet.doProxy() ²½ÖèÀïµÄ SSRF £¬Í¬ÑùÒ²ÄÜʵÏÖ admin SOAP AuthRequest ÈÏÖ¤ £¬µÃµ½ admin authtoken¡£


ÏÂͼΪ¹²Í¬ÀûÓà XXE ºÍ ProxyServlet SSRF ·ì϶Äõ½ admin authtoken ºó £¬Í¨¹ýÎļþÉÏ´«ÔÚ·þÎñ¶ËÖ´ÐÐËÁÒâ´úÂëµÄ±¾µØ²âÊÔ½ØÍ¼£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



³ý´ËÖ®±í £¬ÔÚ Zimbra·þÎñ¶ËʹÓà Memcached ×ö»º´æ·þÎñʱ £¬»¹Äܹ»ÀûÓà SSRF ¹¥»÷ Memcached »º´æ·þÎñ £¬Í¨¹ý·´ÐòÁл¯ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£²»ÍâÓÉÓÚ Zimbra µÄ×°Öùý³ÌÖÐµÄ bug £¬µ¼Öµ¥·þÎñÆ÷µÄÇé¿öÏ £¬Memcached Ö»¹Ü»áÆô¶¯ £¬µ«²¢²»»áʹÓà £¬Òò¶ø SSRF ¹¥»÷ Memcached ·´ÐòÁл¯µÄÀûÓó¡¾°±ÈÁ¦ÓÐÏÞ¡£


½¨¸´½¨Òé


¸üйٷ½°ä²¼µÄ°²È«²¹¶¡»òÉý¼¶ Zimbra µ½×îа棺https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories¡£


²Î¿¼Á´½Ó


https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories