¡¾Â©¶´Í¨¸æ¡¿Spring Security Oauth2 ClientȨÏÞÌáÉý©¶´£¨CVE-2022-31690£©

Ðû²¼Ê±¼ä 2022-11-01

0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2022-31690

·¢ÏÖʱ¼ä

2022-11-01

Àà    ÐÍ

ȨÏÞÌáÉý

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

Spring SecurityÊÇÒ»¸ö¹¦Ð§Ç¿´óÇҸ߶ȿɶ¨ÖƵÄÉí·ÝÑéÖ¤ºÍ·ÃÎÊ¿ØÖÆ¿ò¼Ü¡£

10ÔÂ31ÈÕ £¬VMwareÐû²¼Äþ¾²Í¨¸æ £¬ÐÞ¸´ÁËSpring SecurityÖеÄÒ»¸öȨÏÞÌáÉý©¶´£¨CVE-2022-31690£© £¬¸Ã©¶´µÄCVSSv3»ù´¡ÆÀ·ÖΪ8.1¡£

¸Ã©¶´´æÔÚÓÚspring-security-oauth2-clientÖÐ £¬¶ñÒâÓû§¿ÉÒÔͨ¹ýÐ޸Ŀͻ§¶ËÏòÊÚȨ·þÎñÆ÷ÌᳫµÄÇëÇó £¬ÔÚÄ³Ð©ÌØ¶¨Çé¿öÏ¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£

´ËÍâ £¬Spring SecurityÖл¹ÐÞ¸´ÁËÁíÒ»¸öÊÚȨ¹æÔòÈÆ¹ý©¶´£¨CVE-2022-31692£© £¬ÊÜÓ°ÏìµÄSpring Security°æ±¾ÔÚÄ³Ð©ÌØ¶¨Çé¿öÏÂÈÝÒ×ͨ¹ýFORWARD»òINCLUDEµ÷ÖÎÈÆ¹ýÊÚȨ¹æÔò¡£

 

Ó°Ï췶Χ

Spring Security °æ±¾5.7.0 - 5.7.4

Spring Security °æ±¾5.6.0 - 5.6.8

ÒÔ¼°²»ÊÜÖ§³ÖµÄ¾É°æ±¾¡£


0x02 Äþ¾²½¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´ £¬ÊÜÓ°ÏìÓû§¿ÉÒÔÉý¼¶µ½ÒÔϰ汾£º

Spring Security °æ±¾5.7.x Óû§£ºÉý¼¶µ½ 5.7.5¡£

Spring Security °æ±¾5.6.x Óû§£ºÉý¼¶µ½ 5.6.9¡£

ÏÂÔØÁ´½Ó£º

https://github.com/spring-projects/spring-security/tags

 

0x03 ²Î¿¼Á´½Ó

https://tanzu.vmware.com/security/cve-2022-31690

https://spring.io/blog/2022/10/31/cve-2022-31690-privilege-escalation-in-spring-security-oauth2-client

https://spring.io/blog/2022/10/31/cve-2022-31692-authorization-rules-can-be-bypassed-via-forward-or-include-in-spring-security

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-11-01

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png