Apache Axis Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-12Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0227£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÊÜÓ°ÏìµÄ°æ±¾
Apache Axis Version = 1.4
²»ÊÜÓ°Ïì°æ±¾
Apache Axis2 ËùÓа汾£¨ÏÖÔÚÔÝʱûÓз¢Ã÷Axis2µÄ·þÎñ±£´æÍâÁªÕ÷Ïó£©
Îó²î¸ÅÊö
Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°ÖÖÖÖ¹«Ó÷þÎñ¼°API£¬ÒÔÌìÉúºÍ°²ÅÅWeb·þÎñÓ¦Óá£
Axis¸½´øµÄĬÈÏ·þÎñStockQuoteService.jws°üÀ¨Ò»¸öÓ²±àÂëµÄHTTP URL£¬¿ÉÓÃÓÚ´¥·¢HTTPÇëÇó¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓòÃû£¨www.xmltoday.com£©½ÓÊÜ»òÕßͨ¹ýARPÓÕÆ·þÎñÆ÷´Ó¶øÖ´ÐÐMITM¹¥»÷£¬²¢½«HTTPÇëÇóÖØ¶¨Ïòµ½¶ñÒâWeb·þÎñÆ÷£¬ÔÚApache Axis·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂ루CVE-2019-0227£©¡£
ÏÖÔÚΪÁ˱ÜÃâÓòÃûwww.xmltoday.com±»¶ñÒâ¹¥»÷ÕßʹÓã¬ÒѾÓа×ñ×Ó½«Æä¹ºÖá£
Îó²îÑéÖ¤
POC£ºhttps://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2019-0227¡£
Éó²éAxisÔ´ÖеÄXMLutils£¬¿ÉÒÔ¿´µ½¡°setInstanceFollowRedirects¡±ÊôÐÔÉèÖÃΪ¡°true¡±¡£Õâ֤ʵÁË¡°XMLUtils.newDocument¡±ÏÖʵÉÏ»á×ñÕÕÖØ¶¨Ïò¡£
ÓµÓдËÓò²¢²»ÊÇÀÄÓá°StockQuoteService.jws¡±»òÀ´×ÔAxis·þÎñÆ÷µÄÈÎºÎÆäËûHTTPÇëÇóµÄΨһҪÁì¡£ÓÉÓÚÇëÇóÊÇͨ¹ýHTTP¾ÙÐеģ¬ÕâÒâζ×ÅÈôÊÇÄúÓëAxis·þÎñÆ÷λÓÚÍ³Ò»ÍøÂçÉÏ£¬Ôò¿ÉÒÔÖ´ÐÐÕë¶Ô¸Ã·þÎñÆ÷µÄÖÐÐÄÈ˹¥»÷£¬È»ºóʹÓá°StockQuoteService.jws¡±´¥·¢Æ÷»òÆÚ´ýHTTPÇëÇó²¢Ôٴν«´ËÇëÇóÖØ¶¨Ïòµ½localhostÒÔʹÓÃSSRF¼¼ÇÉ¡£Ê¹ÓÃËüµÄ°ì·¨ÈçÏ£ºARPÖж¾Ä¿µÄAxis·þÎñÆ÷¡£
½«ÈκÎHTTPÁ÷Á¿Öض¨Ïòµ½Äú×Ô¼ºµÄWeb·þÎñÆ÷¡£
ÖØ¶¨Ïòµ½ÌØÖƵÄlocalhost URL£¬¸ÃURLÔÚAxisÖÐÆô¶¯·þÎñ¡£
´¥·¢HTTPÇëÇóÒÔÖØ¶¨ÏòÇëÇó¡°StockQuoteService.jws¡±¡£
ÐÞ¸´½¨Òé
È·±£ÔÚAxis»òAxis2ÖÐÔËÐеÄÈκοâ»ò·þÎñ²»±£´æÍâÁªµÄHTTP/HTTPSÇëÇó¡£
Apache Axis2µÄÏÂÔØµØµãΪ£º
http://axis.apache.org/axis2/java/core/download.html
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ