CVE-2020-11998 | Apache ActiveMQÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2020-09-140x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-11998 | ʱ ¼ä | 2020-09-14 |
Àà ÐÍ | Ô¶³Ì´úÂëÖ´ÐÐ | µÈ ¼¶ | ÖÐΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | ½öApache ActiveMQ 5.15.12°æ±¾¡£ |
2020Äê09ÔÂ10ÈÕ£¬ApacheÈí¼þ»ù½ð»áÐû²¼ActiveMQÐÂÎÅÖÐÐļþÖб£´æÒ»¸öÇå¾²Îó²î£¬Îó²î¸ú×ÙΪCVE-2020-11998¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£
0x01 Îó²îÏêÇé

Apache ActiveMQÊÇApacheÈí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬ËüÊÇÒ»¸ö»ùÓÚÐÂÎŵÄͨѶÖÐÐļþ£¬²¢Ö§³ÖJavaÐÂÎÅ·þÎñ¡¢¼¯Èº¡¢Spring FrameworkµÈ¡£
ActiveMQÊÇJMSµÄÒ»¸öÏêϸʵÏÖ£¬Ö§³ÖJMSµÄÁ½ÖÖÐÂÎÅÄ£×Ó¡£Ëü×ñÕÕJMS1.1¹æ·¶£¨Java Message Service£©£¬ÊÇÐÂÎÅÇý¶¯ÖÐÐļþÈí¼þ£¨MOM£©¡£ËüΪÆóÒµÐÂÎÅת´ïÌṩ¸ß¿ÉÓᢾ«²ÊÐÔÄÜ¡¢¿ÉÀ©Õ¹¡¢Îȹ̺ÍÇå¾²°ü¹Ü¡£
ActiveMQʹÓÃApacheÔÊÐíÐÒé¡£Òò´Ë£¬ÈκÎÈ˶¼¿ÉÒÔʹÓúÍÐÞ¸ÄËü¶ø²»±Ø·´ÏìÈκθı䡣Õâ¹ØÓÚÉÌÒµÉϽ«ActiveMQÓÃÔÚÖ÷ÒªÓÃ;µÄÈËÓÈΪҪº¦¡£ActiveMQµÄÄ¿µÄÊÇÔÚ¾¡¿ÉÄܶàµÄƽ̨ºÍÓïÑÔÉÏÌṩһ¸ö±ê×¼µÄ£¬ÐÂÎÅÇý¶¯µÄÓ¦Óü¯³É¡£
CVE-2020-11998Îó²îÐγɵÄÔÓÉÓÚ£º
1. ÔÚÌá½»±ÜÃâJMX(Java Management Extensions£¬¼´JavaÖÎÀíÀ©Õ¹,ÊÇÒ»¸öΪӦÓóÌÐò¡¢×°±¸¡¢ÏµÍ³µÈÖ²ÈëÖÎÀí¹¦Ð§µÄ¿ò¼Ü)ÖØÐ°ó¶¨ÖÐÒýÈëÁËregression¡£
2. ½«Ò»¸ö¿ÕµÄÇéÐÎÓ³Éä¶ø²»ÊǰüÀ¨Éí·ÝÑé֤ƾ֤µÄÓ³Éäת´ïµ½RMIConnectorServer»áʹµÃActiveMQÈÝÒ×Êܵ½ÒÔϹ¥»÷£º
https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html¡£
3. ÔÚûÓÐÇå¾²ÖÎÀíÆ÷µÄÇéÐÎÏ£¬Ô¶³Ì¿Í»§¶Ë¿ÉÒÔ½¨ÉèÒ»¸öjavax.management.loading.MLet MBean£¬²¢Ê¹ÓÃËü´Óí§ÒâURL½¨ÉèеÄMBean£¬Õâ¿ÉÄܻᵼÖ¶ñÒâµÄÔ¶³Ì¿Í»§¶ËʹÓÃJavaÓ¦ÓóÌÐòÖ´ÐÐí§Òâ´úÂë¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚApache¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬½¨ÒéÉý¼¶µ½Apache ActiveMQ 5.15.13°æ±¾¡£
ÏÂÔØÁ´½Ó£º
http://activemq.apache.org/activemq-51513-release
0x03 Ïà¹ØÐÂÎÅ
https://www.secfree.com/vul-150408.html
0x04 ²Î¿¼Á´½Ó
http://activemq.apache.org/security-advisories.data/CVE-2020-11998-announcement.txt
https://nvd.nist.gov/vuln/detail/CVE-2020-11998
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11998
0x05 ʱ¼äÏß
2020-09-10 ApacheÐû²¼Ç徲ͨ¸æ
2020-09-14 VSRCÐû²¼Ç徲ͨ¸æ



¾©¹«Íø°²±¸11010802024551ºÅ