Apache OFBiz Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-29200£©
Ðû²¼Ê±¼ä 2021-04-280x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-29200 | ʱ ¼ä | 2021-04-28 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | Apache OFBiz < 17.12.07 |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
OFBizÊÇÒ»¸öÖøÃûµÄµç×ÓÉÌÎñƽ̨£¬ÏÖÒѳÉΪApache¶¥¼¶ÏîÄ¿¡£ËüÌṩÁË´´½¨»ùÓÚ×îÐÂJ2EE/XML¹æ·¶ºÍ¼¼Êõ³ß¶È£¬Ö÷ÒªÓÃÓÚ¹¹½¨´óÖÐÐÍÆóÒµ¼¶¡¢¿çƽ̨¡¢¿çÊý¾Ý¿â¡¢¿çÓ¦Ó÷þÎñÆ÷µÄ¶à²ã¡¢ÂþÑÜʽµç×ÓÉÌÎñÀàWEBÓ¦ÓÃϵͳµÄ¿ò¼Ü¡£
2021Äê04ÔÂ27ÈÕ£¬Apache¹Ù·½Ðû²¼Äþ¾²Í¨¸æ£¬¹ûÈ»ÁËApache OFBizÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-29200£©ºÍÒ»¸ö·´ÐòÁл¯Â©¶´£¨CVE-2021-30128£©¡£
Apache OFBiz·´ÐòÁл¯Â©¶´£¨CVE-2021-30128£©
Apache OFBizÔÚ17.12.07֮ǰµÄ°æ±¾ÖдæÔÚ·´ÐòÁл¯Â©¶´¡£
Apache OFBizÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-29200£©
ÓÉÓÚʹÓÃRMI£¨Ô¶³ÌÒªÁìµ÷Ó㩵¼Ö²»Äþ¾²µÄ·´ÐòÁл¯£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÀûÓôË©¶´Ô¶³ÌÖ´ÐдúÂë¡£
0x02 ´¦Öý¨Òé
Ŀǰ¹Ù·½ÒÑÐÞ¸´ÁË´Ë©¶´£¬½¨ÒéÉý¼¶µ½Apache OFBiz 17.12.07»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://ofbiz.apache.org/download.html#vulnerabilities
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202104.mbox/%3Cfec5f041-0cc9-730f-478c-15926792b2a7@apache.org%3E
http://mail-archives.apache.org/mod_mbox/www-announce/202104.mbox/%3C74ac1d8c-ad68-3ceb-8445-624bce15087f@apache.org%3E
https://ofbiz.apache.org/release-notes-17.12.07.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30128
0x04 ʱ¼äÏß
2021-04-27 ApacheÐû²¼Äþ¾²Í¨¸æ
2021-04-28 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/