¡¾Â©¶´Í¨¸æ¡¿Apache Commons FileUpload¾Ü¾ø·þÎñ©¶´£¨CVE-2023-24998£©

Ðû²¼Ê±¼ä 2023-02-21


0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2023-24998

·¢ÏÖʱ¼ä

2023-02-21

Àà    ÐÍ

Dos

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÅÓ´ó¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

Apache CommonsÊÇÒ»¸öרעÓÚ¿ÉÖØÓÃJava×é¼þ¿ª·¢µÄ Apache ÏîÄ¿£¬¸ÃÏîÄ¿ÓÉCommons Proper¡¢The Commons SandboxºÍThe Commons DormantÈý¸ö²¿ÃÅ×é³É¡£Apache Commons-FileUploadÊÇCommons ProperÖеÄÒ»¸ö×é¼þ£¬Ö¼ÔÚʵÏÖÎļþÉÏ´«¡£

2ÔÂ20ÈÕ£¬ApacheÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËApache Commons FileUploadÖеľܾø·þÎñ©¶´£¨CVE-2023-24998£©¡£ÓÉÓÚApache Commons FileUpload°æ±¾1.5֮ǰδÏÞÖÆÒª´¦ÖõÄÇëÇó²¿ÃŵÄÊýÁ¿£¬µ¼Ö¿ÉÒÔͨ¹ý¶ñÒâÉÏ´«»òһϵÁÐÉÏ´«À´´¥·¢¾Ü¾ø·þÎñ¡£

´ËÍ⣬ÓÉÓÚApache TomcatʹÓÃApache Commons FileUploadµÄ´ò°üÖØÃüÃû¸±Ô­À´ÌṩJakarta Servlet¹æ·¶Öнç˵µÄÎļþÉÏ´«¹¦Ð§£¬Òò´ËApache TomcatÒ²ÈÝÒ×Êܵ½¸Ã©¶´Ó°Ïì¡£

 

Ó°Ï췶Χ

Apache Commons FileUpload£º°æ±¾1.0-beta-1 - 1.4

Apache Tomcat£º

Apache Tomcat °æ±¾11.0.0-M1

Apache Tomcat °æ±¾10.1.0-M1 - 10.1.4

Apache Tomcat °æ±¾9.0.0-M1 - 9.0.70

Apache Tomcat °æ±¾8.5.0 - 8.5.84

 

0x02 Äþ¾²½¨Òé

Ŀǰ¸Ã©¶´ÒѾ­ÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿É¼°Ê±Éý¼¶µ½ÒÔϰ汾£º

Apache Commons FileUpload£º°æ±¾ >= 1.5

ÏÂÔØÁ´½Ó£º

https://commons.apache.org/proper/commons-fileupload/download_fileupload.cgi

Apache Tomcat£º

Apache Tomcat °æ±¾ >= 11.0.0-M3

Apache Tomcat °æ±¾ >= 10.1.5

Apache Tomcat °æ±¾ >= 9.0.71

Apache Tomcat °æ±¾ >= 8.5.85

ÏÂÔØÁ´½Ó£º

https://tomcat.apache.org/index.html

×¢£ºApache Tomcat 11.0.0-M2 δÐû²¼¡£

¸Ã©¶´ÒÑÔÚApache Commons FileUpload°æ±¾ >= 1.5ÖÐÐÞ¸´£¬µ«ÐÂÅäÖÃÑ¡Ïî(FileUploadBase#setFileCountMax) ĬÈÏÇé¿öÏÂδÆôÓ㬱ØÐëÃ÷È·ÅäÖá£


0x03 ²Î¿¼Á´½Ó

https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy

https://commons.apache.org/proper/commons-fileupload/security-reports.html

https://tomcat.apache.org/security-10.html

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2023-02-21

Ê×´ÎÐû²¼

 

 

0x05 ¸½Â¼

¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png