¶«É­Æ½Ì¨Ìṩ©¶´É¨ÃèºÍÏû¿Ø·½°¸

Ðû²¼Ê±¼ä 2023-02-22

Apache Tomcat¹Ù·½Åû¶1¸ö´æÔÚÓÚApache Commons FileUploadÖеľܾø·þÎñ©¶´£¬ÆäÖбàºÅCVE-2023-24998Ϊ¸ßΣ©¶´¡£¶«É­Æ½Ì¨µÚһʱ¼ä¶ÔApache Commons FileUpload¹Ù·½Ðû²¼µÄÄþ¾²Í¨¸æ½øÐзÖÎöÑÐÅУ¬½áºÏÌ©ºÏÅ̹Åƽ̨£¨THPangu-OS£©µÄµ××ùÄÜÁ¦£¬Îª¹ã´óÓû§ÌṩӦ¼±´¦ÖÃÖ¸Òý·½°¸¡£


ÓÉÓÚ Apache Commons FileUpload °æ±¾ 1.5 ֮ǰδÏÞÖÆÒª´¦ÖõÄÇëÇó²¿ÃŵÄÊýÁ¿£¬µ¼Ö¿ÉÒÔͨ¹ý¶ñÒâÉÏ´«»òһϵÁÐÉÏ´«À´´¥·¢¾Ü¾ø·þÎñ¡£¶øÇÒ Apache Tomcat ʹÓà Apache Commons FileUpload µÄ´ò°üÖØÃüÃû¸±Ô­À´Ìṩ Jakarta Servlet ¹æ·¶Öнç˵µÄÎļþÉÏ´«¹¦Ð§£¬Òò´Ë Apache Tomcat Ò×Êܵ½¸Ã©¶´Ó°Ïì¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ä¿Ç°¸Ã©¶´POC£¨¿´·¨ÑéÖ¤´úÂ룩δ¹ûÈ»£¬µ«Ëæʱ´æÔÚ±»ÍøÂçºÚ²ú·¢ÏÖ²¢ÖÆÔì¹¥»÷ÐÐΪµÄ·çÏÕ¡£Apache Commons ÊÇÒ»¸öרעÓÚ¿ÉÖØÓà Java ×é¼þ¿ª·¢µÄ Apache ÏîÄ¿£¬¸ÃÏîÄ¿ÓÉ Commons Proper¡¢The Commons Sandbox ºÍThe Commons DormantÈý¸ö²¿ÃÅ×é³É¡£Apache Commons-FileUpload ÊÇ Commons Proper ÖеÄÒ»¸ö×é¼þ£¬Ö¼ÔÚʵÏÖÎļþÉÏ´«¡£ÖÁ´Ë×ÛÊö¸Ã©¶´µÄ×ÛºÏÆÀ¼¶Îª¡°¸ßΣ¡±¡£


 ÐÞ¸´½¨Òé 


¹Ù·½ÒѾ­Õë¶Ô©¶´Ðû²¼ÁËÈí¼þ¸üУ¬ÏÂÔصØÖ·ÈçÏ£º

Apache Commons FileUpload£º

°æ±¾ >= 1.5

ÏÂÔØÁ´½Ó£º

https://commons.apache.org/proper/commons-fileupload/download_fileupload.cgi


Apache Tomcat£º

Apache Tomcat °æ±¾ >= 11.0.0-M3

Apache Tomcat °æ±¾ >= 10.1.5

Apache Tomcat °æ±¾ >= 9.0.71

Apache Tomcat °æ±¾ >= 8.5.85

ÏÂÔØÁ´½Ó£º

https://tomcat.apache.org/index.html


×¢£ºApache Tomcat 11.0.0-M2 δÐû²¼¡£¸Ã©¶´ÒÑÔÚ Apache Commons FileUpload °æ±¾ >= 1.5 ÖÐÐÞ¸´£¬µ«ÐÂÅäÖÃÑ¡Ïî (FileUploadBase#setFileCountMax) ĬÈÏÇé¿öÏÂδÆôÓ㬱ØÐëÃ÷È·ÅäÖá£


 ¶«É­Æ½Ì¨½â¾ö·½°¸ 


Ò»£º»ùÓÚ©¶´É¨Ãè²úÎᄀ¿ì¶Ô×ʲú½øÐЩ¶´ÆÀ¹À


¶«É­Æ½Ì¨Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳÒѽô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐÐÊÚȨɨÃ裬Óû§Éý¼¶³ß¶È©¶´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃè¡£


6070°æ±¾Éý¼¶°üΪ607000488£¬Éý¼¶°üÏÂÔصØÖ·£º

https://venustech.download.venuscloud.cn/


Éý¼¶ºóÒÑÖ§³Ö¸Ã©¶´.png


ÇëʹÓö«É­Æ½Ì¨Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ²úÎïµÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬¼°Ê±¶Ô¸Ã©¶´½øÐмì²â£¬ÒԱ㾡¿ì½ÓÄÉ·À·¶´ëÊ©¡£


¶þ£º¶«É­Æ½Ì¨×ʲúÓë´àÈõÐÔ¹ÜÀíƽ̨(ASM)ÅŲéÊÜÓ°Ïì×ʲú


¶«É­Æ½Ì¨×ʲúÓë´àÈõÐÔ¹ÜÀíƽ̨ʵʱÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬¶ÔÈë¿â×ʲú©¶´Apache Commons FileUpload¾Ü¾ø·þÎñ©¶´£¨CVE-2023-24998£©½øÐйÜÀí£¬ÈçͼËùʾ£º


Ç鱨¹ÜÀíÄ£¿éÒÑÈë¿âµÄApache Commons FileUpload¾Ü¾ø·þÎñ©¶´.png


×ʲúÓë´àÈõÐÔ¹ÜÀíƽ̨ƾ¾ÝÇ鱨ÐÅÏ¢¸üеĩ¶´ÊÜÓ°ÏìʵÌå¹æÔòÒÔ¼°ÏÖ³¡×ʲú¹ÜÀíʵÀýµÄ°æ±¾ÐÅÏ¢½øÐÐ×Ô¶¯»¯Åöײ£¬¿ÉµÚһʱ¼äÃüÖÐÊܸ鶴ӰÏìµÄ×ʲú£¬ÈçͼËùʾ£º


Ç鱨ÃüÖеÄ×ʲúÐÅÏ¢.png


Èý£º»ùÓÚÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨½øÐйØÁª·ÖÎö


¹ã´óÓû§¿ÉÒÔͨ¹ýÌ©ºÏÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨£¬½øÐйØÁª¼ÆıÅäÖ㬽áºÏʵ¼Ê»·¾³ÖÐϵͳÈÕÖ¾ºÍÄþ¾²É豸µÄ¸æ¾¯ÐÅÏ¢½øÐÐÁ¬Ðø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°Apache Commons FileUpload¾Ü¾ø·þÎñ¡±µÄ©¶´ÀûÓù¥»÷ÐÐΪ¡£


ÔÚÌ©ºÏÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨ÖУ¬Í¨¹ý´àÈõÐÔ·¢ÏÖ¹¦Ð§Õë¶Ô¡°Apache_Commons_FileUpload_¾Ü¾ø·þÎñ©¶´£¨CVE-2023-24998£©¡±Ö´ÐЩ¶´É¨ÃèÈÎÎñ£¬ÅŲé¹ÜÀíÍøÂçÖÐÊÜ´Ë©¶´Ó°ÏìµÄÖØÒª×ʲú¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚƽ̨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬Ìí¼Ó¡°L2_Apache_Commons_¾Ü¾ø·þÎñ©¶´ÀûÓá±£¬Í¨¹ý¶«É­Æ½Ì¨¼ì²âÉ豸¡¢Ä¿±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý·ÖÎö¹æÔò×Ô¶¯½«Apache Commons FileUpload¾Ü¾ø·þÎñÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ìí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ß·çÏÕÁ¬½Ó¡±ÖУ¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓà £»


Ìí¼Ó¡°L3_Apache_Commons_¾Ü¾ø·þÎñ©¶´ÀûÓÃÀֳɡ±£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ¡°L2_Apache_Commons_¾Ü¾ø·þÎñ©¶´ÀûÓá±£¬¹¥»÷½á¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬Ä¿µÄµØÖ·ÒýÓÃ×ʲú©¶´»òÔ´µØÖ·Æ¥ÅäÍþвÇ鱨£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ËÄ£ºATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´¦Öý¨Òé


1¡¢ATT&CK¹¥»÷Á´·ÖÎö


ƾ¾Ý¶ÔApache Commons FileUpload¾Ü¾ø·þÎñ©¶´µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬¹¥»÷Á´Éæ¼°µÄATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î°üÂÞ£º

Ó°ÏìTA0040£º¶Ëµã¾Ü¾ø·þÎñT1499


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2¡¢´¦Ö÷½°¸½¨ÒéºÍSOAR¾ç±¾±àÅÅ


ͨ¹ýÌ©ºÏÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦ÖÃÄÜÁ¦£¬Õë¶Ô¸Ã©¶´ÀûÓõĸ澯ʼþ±àÅž籾£¬½øÐÐ×Ô¶¯»¯´¦Öá£