¡¾Îó²îͨ¸æ¡¿CVE-2020-13959 Apache Velocity XSSÎó²î

Ðû²¼Ê±¼ä 2021-01-18

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-13959

ʱ   ¼ä

2021-01-18

Àà   ÐÍ

XSS

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Velocity Tools

ËùÓа汾

 

0x01 Îó²îÏêÇé

image.png

 

Apache VelocityÊÇ»ùÓÚJavaµÄÄ£°åÒýÇæ£¬£¬£¬£¬¿ª·¢Ö°Ô±¿ÉʹÓÃÆäÔÚModel-View-Controller£¨MVC£©¼Ü¹¹ÖÐÉè¼ÆÊÓͼ¡£¡£ ¡£¡£¡£Velocity ToolsÊÇÒ»¸öÓÉÀà×é³ÉµÄ×ÓÏîÄ¿£¬£¬£¬£¬Ëü½øÒ»²½¼ò»¯ÁËVelocityÔÚ±ê×¼ºÍÍøÂçÓ¦ÓÃÖеÉ¡£¡£ ¡£¡£¡£

¿ËÈÕ£¬£¬£¬£¬Apache Velocity ToolsÖÐÒ»¸öδ¹ûÕæµÄXSSÎó²î£¨CVE-2020-13959£©±»Åû¶£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìÆäËùÓа汾¡£¡£ ¡£¡£¡£Ö»¹Ü¸ÃÎó²îÉÐδ¹ûÕæ£¬£¬£¬£¬µ«ÆäÐÞ¸´³ÌÐòÔÚ2020Äê11ÔÂ05ÈÕ¾ÍÒÑÔÚGitHubÉÏÐû²¼¡£¡£ ¡£¡£¡£

¸ÃÎó²îΪ·´ÉäÐÍXSS£¬£¬£¬£¬µ±»á¼ûÎÞЧµÄURLʱ£¬£¬£¬£¬"template not found"µÄ¹ýÊ§Ò³Ãæ½«URLµÄ×ÊԴ·¾¶²¿·Ö°´Ô­Ñù·´Ó¦³öÀ´£¬£¬£¬£¬¶ø²î³ØÆä¾ÙÐÐתÒå¡£¡£ ¡£¡£¡£

¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓÕÆ­Êܺ¦Õßµ¥»÷ÕâÑùµÄURL£¬£¬£¬£¬´Ó¶ø½«Êܺ¦ÕßÖ¸µ¼ÖÁ±»¸ü¸ÄµÄÍøÂç´¹ÂÚÒ³ÃæÐ¹Â¶ÆäµÇ¼»á»°ÐÅÏ¢£¬£¬£¬£¬»òÕßÍøÂçÒѵÇÈÎÃü»§µÄ»á»°Cookie£¬£¬£¬£¬²¢Ð®ÖÆÆä»á»°¡£¡£ ¡£¡£¡£

ÏÖÔÚ£¬£¬£¬£¬¶à¸öÕþ¸®ÍøÕ¾£¨Èç* .nasa.gov ºÍ* .gov.au£©ÕýÔÚʹÓÃÊÜÓ°ÏìµÄApache Velocity Tools¡£¡£ ¡£¡£¡£

image.png

image.png

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬£¬¸ÃÎó²îµÄÐÞ¸´³ÌÐòÒѾ­Ðû²¼¡£¡£ ¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/apache/velocity-tools/pull/9

 

0x03 ²Î¿¼Á´½Ó

http://velocity.apache.org/download.cgi#tools

https://www.bleepingcomputer.com/news/security/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13959

 

0x04 ʱ¼äÏß

2021-01-15  BleepingComputerÅû¶Îó²î

2021-01-18  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png