¡¾Îó²îͨ¸æ¡¿CVE-2020-13959 Apache Velocity XSSÎó²î
Ðû²¼Ê±¼ä 2021-01-180x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-13959 | ʱ ¼ä | 2021-01-18 |
Àà ÐÍ | XSS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache Velocity Tools ËùÓа汾 |
0x01 Îó²îÏêÇé

Apache VelocityÊÇ»ùÓÚJavaµÄÄ£°åÒýÇæ£¬£¬£¬£¬¿ª·¢Ö°Ô±¿ÉʹÓÃÆäÔÚModel-View-Controller£¨MVC£©¼Ü¹¹ÖÐÉè¼ÆÊÓͼ¡£¡£¡£¡£¡£Velocity ToolsÊÇÒ»¸öÓÉÀà×é³ÉµÄ×ÓÏîÄ¿£¬£¬£¬£¬Ëü½øÒ»²½¼ò»¯ÁËVelocityÔÚ±ê×¼ºÍÍøÂçÓ¦ÓÃÖеɡ£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬Apache Velocity ToolsÖÐÒ»¸öδ¹ûÕæµÄXSSÎó²î£¨CVE-2020-13959£©±»Åû¶£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìÆäËùÓа汾¡£¡£¡£¡£¡£Ö»¹Ü¸ÃÎó²îÉÐδ¹ûÕæ£¬£¬£¬£¬µ«ÆäÐÞ¸´³ÌÐòÔÚ2020Äê11ÔÂ05ÈÕ¾ÍÒÑÔÚGitHubÉÏÐû²¼¡£¡£¡£¡£¡£
¸ÃÎó²îΪ·´ÉäÐÍXSS£¬£¬£¬£¬µ±»á¼ûÎÞЧµÄURLʱ£¬£¬£¬£¬"template not found"µÄ¹ýÊ§Ò³Ãæ½«URLµÄ×ÊԴ·¾¶²¿·Ö°´ÔÑù·´Ó¦³öÀ´£¬£¬£¬£¬¶ø²î³ØÆä¾ÙÐÐתÒå¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓÕÆÊܺ¦Õßµ¥»÷ÕâÑùµÄURL£¬£¬£¬£¬´Ó¶ø½«Êܺ¦ÕßÖ¸µ¼ÖÁ±»¸ü¸ÄµÄÍøÂç´¹ÂÚÒ³ÃæÐ¹Â¶ÆäµÇ¼»á»°ÐÅÏ¢£¬£¬£¬£¬»òÕßÍøÂçÒѵÇÈÎÃü»§µÄ»á»°Cookie£¬£¬£¬£¬²¢Ð®ÖÆÆä»á»°¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬£¬¶à¸öÕþ¸®ÍøÕ¾£¨Èç* .nasa.gov ºÍ* .gov.au£©ÕýÔÚʹÓÃÊÜÓ°ÏìµÄApache Velocity Tools¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬£¬¸ÃÎó²îµÄÐÞ¸´³ÌÐòÒѾÐû²¼¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://github.com/apache/velocity-tools/pull/9
0x03 ²Î¿¼Á´½Ó
http://velocity.apache.org/download.cgi#tools
https://www.bleepingcomputer.com/news/security/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13959
0x04 ʱ¼äÏß
2021-01-15 BleepingComputerÅû¶Îó²î
2021-01-18 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ