Apache Struts2ÎļþÉÏ´«Îó²î£¨CVE-2024-53677£©À´Ï®£¬×ðÁú¿­Ê±Ìṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2024-12-18

Struts2¿ò¼ÜÊÇÒ»¸öÓÃÓÚ¿ª·¢Java EEÍøÂçÓ¦ÓóÌÐòµÄ¿ª·ÅÔ´´úÂëÍøÒ³Ó¦ÓóÌÐò¼Ü¹¹¡£ËüʹÓò¢ÑÓÉìÁËJava Servlet API£¬ÃãÀø¿ª·¢Õß½ÓÄÉMVC¼Ü¹¹¡£Apache Struts 2±£´æÒ»¸öÑÏÖØµÄÎļþÉÏ´«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²îS2-067£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÎļþÉÏ´«²ÎÊýÀ´ÆôÓ÷¾¶±éÀú£¬¿Éµ¼ÖÂÉÏ´«¿ÉÓÃÓÚÖ´ÐÐÔ¶³Ì´úÂëµÄ¶ñÒâÎļþ¡£


2024Äê12Ô£¬×ðÁú¿­Ê±¼à¿Øµ½Apache¹Ù·½Ðû²¼Îó²îΣº¦Í¨¸æ£¬ÔÚÔ¶³Ì·þÎñÆ÷´úÂëÖÐʹÓÃÁËFileUploadInterceptor×÷ΪÎļþÉÏ´«×é¼þʱ£¬Apache StrutsÔÚÎļþÉÏ´«Âß¼­Éϱ£´æÎó²î¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î¾ÙÐз¾¶±éÀú£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔʹ¹¥»÷ÕßÄܹ»ÉÏ´«¶ñÒâÎļþ£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£


±í1.png


Îó²î¸´ÏÖ½ØÍ¼


ͼ1.png


Ó°Ïì°æ±¾


2.0.0 <= Apache Struts <= 2.3.37 (EOL)

2.5.0 <= Apache Struts <= 2.5.33

6.0.0 <= Apache Struts <= 6.3.0.2

×¢ÖØ£º²»Ê¹ÓÃFileUploadInterceptorÄ£¿éµÄÓ¦Óò»ÊܸÃÎó²îÓ°Ïì¡£


ÐÞ¸´½¨Òé


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®


ÏÖÔÚ¹Ù·½ÒÑÓпɸüа汾£¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾£º

Éý¼¶µ½ Struts 6.4.0 »ò¸ü¸ß°æ±¾²¢Ç¨á㵽еÄÎļþÉÏ´«»úÖÆ¡£


¹Ù·½ÏÂÔØµØµã£º

https://struts.apache.org/download.cgi


ÎļþÉÏ´«»úÖÆÇ¨áãÁ´½Ó£º

https://struts.apache.org/core-developers/file-upload


¶þ¡¢×ðÁú¿­Ê±¼Æ»®


1¡¢×ðÁú¿­Ê±¼ì²âÀà²úÆ·¼Æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEBÇå¾²Ó¦ÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬Éý¼¶µ½×îа汾¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦£¬ÊÂÎñ¿âÏÂÔØµØµã£º


ÊÂÎñ¿âÏÂÔØµØµã£ºhttps://venustech.download.venuscloud.cn/


2¡¢×ðÁú¿­Ê±Â©É¨²úÆ·¼Æ»®


£¨1£©¡°×ðÁú¿­Ê±Îó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£

 

ͼ2.png


£¨2£©×ðÁú¿­Ê±Îó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè


ͼ3.png

 

3¡¢×ðÁú¿­Ê±×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¼Æ»®


×ðÁú¿­Ê±×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬¶ÔÈë¿â×ʲúApache Struts2ÎļþÉÏ´«Îó²î£¨CVE-2024-53677£©¾ÙÐÐÖÎÀí¡£


ͼ4.png

 

4¡¢×ðÁú¿­Ê±Çå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬¾ÙÐйØÁªÕ½ÂÔÉèÖã¬ÍŽáÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬´Ó¶ø·¢Ã÷¡°Apache Struts2ÎļþÉÏ´«Îó²î¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£


1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Apache Struts2ÎļþÉÏ´«Îó²î¡±Îó²îɨÃèʹÃü£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú£»

 

ͼ5.png


2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿éÖУ¬Ìí¼Ó¡°L2_Apache Struts2ÎļþÉÏ´«Îó²î¡±£¬Í¨¹ý×ðÁú¿­Ê±¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º


ͼ6.png

 

̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_Apache Struts2ÎļþÉÏ´«Îó²î"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓã»


3£©Ìí¼Ó¡°L3_Apache Struts2ÎļþÉÏ´«Îó²î¡±£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_Apache Struts2ÎļþÉÏ´«Îó²î¡±£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£


ͼ7.png