¡¾·ì϶¹«¸æ¡¿Apache Any23 Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-40146£©
°ä²¼¹¦·ò 2021-09-130x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-40146 | ʱ ¼ä | 2021-09-11 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Any23 < 2.5 |
¹¥»÷¸´ÔÓ¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ·ì϶ÏêÇé

Apache Everything To Triples (Any23) ÊÇÒ»¸ö¿â¡¢Web ·þÎñºÍºÅÁîÐй¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚ´Ó¸÷Àà Web ÎĵµÖÐÌáÈ¡ RDF ÌåʽµÄ½á¹¹»¯Êý¾Ý¡£¡£¡£¡£¡£
2021Äê9ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Apache°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËApache Any23ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-40146£©£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶´æÔÚÓÚAny23 YAMLExtractor.javaÖУ¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓô˷ì϶ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÔÚAny23µÄStreamUtils.javaÎļþÖз¢ÏÖÒ»¸öXML±í²¿ÊµÌ壨XXE£©×¢Èë·ì϶£¨CVE-2021-38555£©£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶×ÌÈÅÀûÓ÷¨Ê½¶ÔXMLµÄ´¦Ö㬣¬£¬£¬£¬£¬£¬£¬ÊµÏֲ鿴ÀûÓ÷þÎñÆ÷ÎļþϵͳÉϵÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓëÀûÓ÷¨Ê½×ÔÉíÄܹ»½Ó¼ûµÄÈκκó¶Ë»ò±í²¿ÏµÍ³½øÐн»»¥¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
Apache Any23°æ±¾ < 2.5
0x02 ´ëÖý¨Òé
ĿǰÉÏÊö·ì϶ÒÑÔÚApache Any23 2.5°æ±¾Öн¨¸´£¨ÒѰ䲼£©£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üС£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
http://any23.apache.org/download.html
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202109.mbox/%3Cpony-b7497055821405926d63668ab1112e0f108e2346-24b556bb9c8200804abff20daacf3205f453d88d@announce.apache.org%3E
http://mail-archives.apache.org/mod_mbox/www-announce/202109.mbox/%3Cpony-b7497055821405926d63668ab1112e0f108e2346-fc7885638697ea0fec1186b16e985c55e5d49a83@announce.apache.org%3E
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-09-13 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ