¡¾Îó²îͨ¸æ¡¿CVE-2020-13959 Apache Velocity XSSÎó²î

Ðû²¼Ê±¼ä 2021-01-18

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-13959

ʱ   ¼ä

2021-01-18

Àà   ÐÍ

XSS

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Velocity Tools

ËùÓа汾

 

0x01 Îó²îÏêÇé

image.png

 

Apache VelocityÊÇ»ùÓÚJavaµÄÄ£°åÒýÇæ£¬£¬£¬£¬£¬£¬£¬¿ª·¢Ö°Ô±¿ÉʹÓÃÆäÔÚModel-View-Controller£¨MVC£©¼Ü¹¹ÖÐÉè¼ÆÊÓͼ¡£¡£¡£ ¡£¡£¡£Velocity ToolsÊÇÒ»¸öÓÉÀà×é³ÉµÄ×ÓÏîÄ¿£¬£¬£¬£¬£¬£¬£¬Ëü½øÒ»²½¼ò»¯ÁËVelocityÔÚ±ê×¼ºÍÍøÂçÓ¦ÓÃÖеÉ¡£¡£¡£ ¡£¡£¡£

¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬Apache Velocity ToolsÖÐÒ»¸öδ¹ûÕæµÄXSSÎó²î£¨CVE-2020-13959£©±»Åû¶£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìÆäËùÓа汾¡£¡£¡£ ¡£¡£¡£Ö»¹Ü¸ÃÎó²îÉÐδ¹ûÕæ£¬£¬£¬£¬£¬£¬£¬µ«ÆäÐÞ¸´³ÌÐòÔÚ2020Äê11ÔÂ05ÈÕ¾ÍÒÑÔÚGitHubÉÏÐû²¼¡£¡£¡£ ¡£¡£¡£

¸ÃÎó²îΪ·´ÉäÐÍXSS£¬£¬£¬£¬£¬£¬£¬µ±»á¼ûÎÞЧµÄURLʱ£¬£¬£¬£¬£¬£¬£¬"template not found"µÄ¹ýÊ§Ò³Ãæ½«URLµÄ×ÊԴ·¾¶²¿·Ö°´Ô­Ñù·´Ó¦³öÀ´£¬£¬£¬£¬£¬£¬£¬¶ø²î³ØÆä¾ÙÐÐתÒå¡£¡£¡£ ¡£¡£¡£

¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÓÕÆ­Êܺ¦Õßµ¥»÷ÕâÑùµÄURL£¬£¬£¬£¬£¬£¬£¬´Ó¶ø½«Êܺ¦ÕßÖ¸µ¼ÖÁ±»¸ü¸ÄµÄÍøÂç´¹ÂÚÒ³ÃæÐ¹Â¶ÆäµÇ¼»á»°ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»òÕßÍøÂçÒѵÇÈÎÃü»§µÄ»á»°Cookie£¬£¬£¬£¬£¬£¬£¬²¢Ð®ÖÆÆä»á»°¡£¡£¡£ ¡£¡£¡£

ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬¶à¸öÕþ¸®ÍøÕ¾£¨Èç* .nasa.gov ºÍ* .gov.au£©ÕýÔÚʹÓÃÊÜÓ°ÏìµÄApache Velocity Tools¡£¡£¡£ ¡£¡£¡£

image.png

image.png

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄÐÞ¸´³ÌÐòÒѾ­Ðû²¼¡£¡£¡£ ¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/apache/velocity-tools/pull/9

 

0x03 ²Î¿¼Á´½Ó

http://velocity.apache.org/download.cgi#tools

https://www.bleepingcomputer.com/news/security/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13959

 

0x04 ʱ¼äÏß

2021-01-15  BleepingComputerÅû¶Îó²î

2021-01-18  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png