Zimbra Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-03-18·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
ZimbraCollaboration Server 8.8.11 ֮ǰµÄ°æ±¾¶¼Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¾ßÌåÀ´Ëµ£º
1. Zimbra < 8.7.11 °æ±¾ÖУ¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚÎÞÐèµÇ¼µÄÇé¿öÏ£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ
2. Zimbra < 8.8.11 °æ±¾ÖУ¬£¬£¬£¬£¬ÔÚ·þÎñ¶ËʹÓà Memcached ×ö»º´æµÄÇé¿öÏ£¬£¬£¬£¬£¬¾¹ýµÇ¼ÈÏÖ¤ºóµÄ¹¥»÷ÕßÄܹ»ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ
·ì϶¸ÅÊö
Zimbra ÊÇÒ»¼ÒÌṩרҵµÄµç×ÓÓʼþÈí¼þ¿ª·¢¹©¸øÉÌ£¬£¬£¬£¬£¬ÖØÒªÌṩ Zimbra Collaboration Server ºÏ×÷·þÎñÆ÷Ì×¼þ¡¢Zimbra Desktop ÓʼþÖÎÀíÈí¼þµÅ×ʼþ·½ÃæµÄÈí¼þ¡£¡£¡£¡£¡£
3 Ô 13 ÈÕ£¬£¬£¬£¬£¬ ¹ú±í°²È«×êÑÐÔ± tint0 °ä²¼ÁËһƪ²©¿Í£¬£¬£¬£¬£¬Ö¸³ö Zimbra Collaboration Server ϵͳȫ°æ±¾´æÔÚһϵÁзì϶£¬£¬£¬£¬£¬Í¨¹ý¶ñÒâÀûÓÃÄܹ»µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£
·ì϶ϸ½Ú
µ± Zimbra ´æÔÚÏñËÁÒâÎļþ¶ÁÈ¡¡¢XXE£¨XML ±í²¿ÊµÌå×¢È룩 ÕâÖÖ·ì϶ʱ£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶¶ÁÈ¡ localconfig.xml ÅäÖÃÎļþ£¬£¬£¬£¬£¬»ñÈ¡µ½ zimbra admin ldap password£¬£¬£¬£¬£¬²¢Í¨¹ý 7071 admin ¶Ë¿Ú½øÐÐ SOAP AuthRequest ÈÏÖ¤£¬£¬£¬£¬£¬µÃµ½ admin authtoken£¬£¬£¬£¬£¬¶øºó¾ÍÄܹ»ÀûÓà admin authtoken ½øÐÐËÁÒâÎļþÉÏ´«£¬£¬£¬£¬£¬´Ó¶ø´ïµ½Ô¶³Ì´úÂëÖ´ÐеķçÏÕ¡£¡£¡£¡£¡£
¶ø tint0 ²©¿ÍÎÄÕÂÀïÖ¸³ö£¬£¬£¬£¬£¬¼´±ãÔÚ 7071 admin ¶Ë¿Ú×öÁË·À»ðǽÅäÖᢲ»ºÏ±íÊ¢¿ªµÄÇé¿öÏ£¬£¬£¬£¬£¬Ò²Äܹ»ÀûÓôæÔÚÓÚ 443 ͨ³£Óû§¶Ë¿Ú·þÎñÀïÉí·ÝÈÏÖ¤µÄÒ»¸ö¸öÐÔ£¬£¬£¬£¬£¬¹²Í¬ ProxyServlet.doProxy() ²½ÖèÀïµÄ SSRF£¬£¬£¬£¬£¬Í¬ÑùÒ²ÄÜʵÏÖ admin SOAP AuthRequest ÈÏÖ¤£¬£¬£¬£¬£¬µÃµ½ admin authtoken¡£¡£¡£¡£¡£
ÏÂͼΪ¹²Í¬ÀûÓà XXE ºÍ ProxyServlet SSRF ·ì϶Äõ½ admin authtoken ºó£¬£¬£¬£¬£¬Í¨¹ýÎļþÉÏ´«ÔÚ·þÎñ¶ËÖ´ÐÐËÁÒâ´úÂëµÄ±¾µØ²âÊÔ½ØÍ¼£º
³ý´ËÖ®±í£¬£¬£¬£¬£¬ÔÚ Zimbra·þÎñ¶ËʹÓà Memcached ×ö»º´æ·þÎñʱ£¬£¬£¬£¬£¬»¹Äܹ»ÀûÓà SSRF ¹¥»÷ Memcached »º´æ·þÎñ£¬£¬£¬£¬£¬Í¨¹ý·´ÐòÁл¯ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£²»ÍâÓÉÓÚ Zimbra µÄ×°Öùý³ÌÖÐµÄ bug£¬£¬£¬£¬£¬µ¼Öµ¥·þÎñÆ÷µÄÇé¿öÏ£¬£¬£¬£¬£¬Memcached Ö»¹Ü»áÆô¶¯£¬£¬£¬£¬£¬µ«²¢²»»áʹÓ㬣¬£¬£¬£¬Òò¶ø SSRF ¹¥»÷ Memcached ·´ÐòÁл¯µÄÀûÓó¡¾°±ÈÁ¦ÓÐÏÞ¡£¡£¡£¡£¡£
½¨¸´½¨Òé
¸üйٷ½°ä²¼µÄ°²È«²¹¶¡»òÉý¼¶ Zimbra µ½×îа棺https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories


¾©¹«Íø°²±¸11010802024551ºÅ