Zimbra Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-18

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º

ZimbraCollaboration Server 8.8.11 ֮ǰµÄ°æ±¾¶¼Êܵ½Ó°Ïì¡£¡£¡£ ¡£¡£ÏêϸÀ´Ëµ£º

1. Zimbra < 8.7.11 °æ±¾ÖУ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÎÞÐèµÇ¼µÄÇéÐÎÏ£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

2. Zimbra < 8.8.11 °æ±¾ÖУ¬£¬£¬£¬£¬ÔÚЧÀͶËʹÓà Memcached ×ö»º´æµÄÇéÐÎÏ£¬£¬£¬£¬£¬¾­ÓɵǼÈÏÖ¤ºóµÄ¹¥»÷Õß¿ÉÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ


Îó²î¸ÅÊö


Zimbra ÊÇÒ»¼ÒÌṩרҵµÄµç×ÓÓʼþÈí¼þ¿ª·¢¹©Ó¦ÉÌ£¬£¬£¬£¬£¬Ö÷ÒªÌṩ Zimbra Collaboration Server Э×÷ЧÀÍÆ÷Ì×¼þ¡¢Zimbra Desktop ÓʼþÖÎÀíÈí¼þµÈÓʼþ·½ÃæµÄÈí¼þ¡£¡£¡£ ¡£¡£


3 Ô 13 ÈÕ£¬£¬£¬£¬£¬ ÍâÑóÇå¾²Ñо¿Ô± tint0 Ðû²¼ÁËһƪ²©¿Í£¬£¬£¬£¬£¬Ö¸³ö Zimbra Collaboration Server ϵͳȫ°æ±¾±£´æÒ»ÏµÁÐÎó²î£¬£¬£¬£¬£¬Í¨¹ý¶ñÒâʹÓÿÉÒÔµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£¡£


Îó²îϸ½Ú


µ± Zimbra ±£´æÏñí§ÒâÎļþ¶ÁÈ¡¡¢XXE£¨XML ÍⲿʵÌå×¢È룩 ÕâÖÖÎó²îʱ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î¶ÁÈ¡ localconfig.xml ÉèÖÃÎļþ£¬£¬£¬£¬£¬»ñÈ¡µ½ zimbra admin ldap password£¬£¬£¬£¬£¬²¢Í¨¹ý 7071 admin ¶Ë¿Ú¾ÙÐÐ SOAP AuthRequest ÈÏÖ¤£¬£¬£¬£¬£¬»ñµÃ admin authtoken£¬£¬£¬£¬£¬È»ºó¾Í¿ÉÒÔʹÓà admin authtoken ¾ÙÐÐí§ÒâÎļþÉÏ´«£¬£¬£¬£¬£¬´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄΣº¦¡£¡£¡£ ¡£¡£


¶ø tint0 ²©¿ÍÎÄÕÂÀïÖ¸³ö£¬£¬£¬£¬£¬×ÝÈ»ÔÚ 7071 admin ¶Ë¿Ú×öÁË·À»ðǽÉèÖá¢²î³ØÍ⿪·ÅµÄÇéÐÎÏ£¬£¬£¬£¬£¬Ò²¿ÉÒÔʹÓñ£´æÓÚ 443 ͨË×Óû§¶Ë¿ÚЧÀÍÀïÉí·ÝÈÏÖ¤µÄÒ»¸öÌØÕ÷£¬£¬£¬£¬£¬ÅäºÏ ProxyServlet.doProxy() ÒªÁìÀïµÄ SSRF£¬£¬£¬£¬£¬Í¬ÑùÒ²ÄÜÍê³É admin SOAP AuthRequest ÈÏÖ¤£¬£¬£¬£¬£¬»ñµÃ admin authtoken¡£¡£¡£ ¡£¡£


ÏÂͼΪÅäºÏʹÓà XXE ºÍ ProxyServlet SSRF Îó²îÄõ½ admin authtoken ºó£¬£¬£¬£¬£¬Í¨¹ýÎļþÉÏ´«ÔÚЧÀͶËÖ´ÐÐí§Òâ´úÂëµÄÍâµØ²âÊÔ½ØÍ¼£º


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



³ý´ËÖ®Í⣬£¬£¬£¬£¬ÔÚ ZimbraЧÀͶËʹÓà Memcached ×ö»º´æÐ§ÀÍʱ£¬£¬£¬£¬£¬»¹¿ÉÒÔʹÓà SSRF ¹¥»÷ Memcached »º´æÐ§ÀÍ£¬£¬£¬£¬£¬Í¨¹ý·´ÐòÁл¯ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ ¡£¡£²»¹ýÓÉÓÚ Zimbra µÄ×°ÖÃÀú³ÌÖÐµÄ bug£¬£¬£¬£¬£¬µ¼Öµ¥Ð§ÀÍÆ÷µÄÇéÐÎÏ£¬£¬£¬£¬£¬Memcached Ö»¹Ü»áÆô¶¯£¬£¬£¬£¬£¬µ«²¢²»»áʹÓ㬣¬£¬£¬£¬Òò´Ë SSRF ¹¥»÷ Memcached ·´ÐòÁл¯µÄʹÓó¡¾°½ÏÁ¿ÓÐÏÞ¡£¡£¡£ ¡£¡£


ÐÞ¸´½¨Òé


¸üйٷ½Ðû²¼µÄÇå¾²²¹¶¡»òÉý¼¶ Zimbra µ½×îа棺https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories¡£¡£¡£ ¡£¡£


²Î¿¼Á´½Ó


https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories