¡¾Â©¶´Í¨¸æ¡¿Progress Telerik Report ServerÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2024-4358£©
Ðû²¼Ê±¼ä 2024-06-05Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Progress Telerik Report ServerÉí·ÝÑéÖ¤ÈÆ¹ý©¶´ | ||
CVE ID | CVE-2024-4358 | ||
©¶´ÀàÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | ·¢ÏÖʱ¼ä | 2024-06-05 |
©¶´ÆÀ·Ö | 9.8 | ©¶´Æ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Progress SoftwareµÄTelerik Report ServerÊÇÒ»¿î¹¦Ð§Ç¿´óµÄ±¨±í·þÎñÆ÷½â¾ö·½°¸£¬¾ß±¸È«ÃæµÄ³ÂËß¹ÜÀí¹¦Ð§£¬¿É×ÊÖú×éÖ¯´´½¨¡¢²¿Êð¡¢½»¸¶ºÍ¹ÜÀí³ÂËß¡£
2024Äê6ÔÂ5ÈÕ£¬¶¶È¦Îª¶Ä¶øÉú¼¯ÍÅVSRC¼à²âµ½Progress Telerik Report ServerÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2024-4358£©µÄ¼¼Êõϸ½Ú¼°PoCÔÚ»¥ÁªÍøÉϹûÈ»£¬ÍþвÕß¿É×éºÏÀûÓÃCVE-2024-4358ºÍCVE-2024-1800ʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬ÏêÇéÈçÏ£º
CVE-2024-4358£ºProgress Telerik Report ServerÉí·ÝÑéÖ¤ÈÆ¹ý©¶´
IISÉϵÄProgress Telerik Report Server 2024 Q1 (10.0.24.305) ¼°Ö®Ç°°æ±¾ÔÚRegisterÒªÁìµÄʵÏÖÖдæÔÚÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¬ÓÉÓÚȱÉÙ¶Ôµ±Ç°°²×°²½ÖèµÄÑéÖ¤£¬¿ÉÄܵ¼ÖÂÔ¶³ÌÍþвÕßÈÆ¹ýÉí·ÝÑéÖ¤·ÃÎÊTelerik Report Server ÊÜÏÞ¹¦Ð§£¬Î´ÊÚȨ´´½¨¹ÜÀíÔ±ÕÊ»§¡£
CVE-2024-1800£ºProgress Telerik Report Server·´ÐòÁл¯Â©¶´
Progress Telerik Report Server 2024 Q1 (10.0.24.130)¼°Ö®Ç°°æ±¾ÔÚObjectReader ÀàÖдæÔÚ·´ÐòÁл¯Â©¶´£¬ÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦ÕýÈ·ÑéÖ¤£¬¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓøÃ©¶´ÔÚÊÜÓ°ÏìµÄ Progress Telerik Report Server °²×°ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£
¶þ¡¢Ó°Ï췶Χ
CVE-2024-4358
Progress Software Telerik Report Server <= 2024 Q1 (10.0.24.305)
CVE-2024-1800
Progress Software Telerik Report Server <= 2024 Q1 (10.0.24.130)
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
ĿǰÕâЩ©¶´ÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º
CVE-2024-4358
Progress Software Telerik Report Server >= 2024 Q2 (10.1.24.514)
CVE-2024-1800
Progress Software Telerik Report Server >= 2024 Q1 (10.0.24.305)
ÏÂÔØÁ´½Ó£º
https://www.telerik.com/report-server
3.2 ÁÙʱ´ëÊ©
¿ÉÒÔͨ¹ýÒÔÏ·½Ê½¼ì²ìËùÔËÐеİ汾ÊÇ·ñÊÜÓ°Ï죺
1.·ÃÎÊReport Server web UI½çÃæ²¢Ê¹ÓþßÓйÜÀíԱȨÏÞµÄÕË»§µÇ¼¡£
2.´ò¿ªÅäÖÃÒ³Ãæ£¨root-uri/Configuration/Index£©¡£
3.Ñ¡Ôñ ¡°About¡±Ñ¡Ï£¬°æ±¾ºÅ½«ÏÔʾÔÚÓҲര¸ñÖС£
Õë¶ÔCVE-2024-4358£¬ÈçÎÞ·¨Á¢¼´Éý¼¶£¬¿ÉʵʩURL RewriteÒÔÏû³ý IIS ÖеĹ¥»÷ÃæÀ´ÁÙʱ»º½â¸Ã©¶´£º
1.´Ë»º½â´ëÊ©ÐèÒªURL Rewrite IIS Ä£¿é¡£Èç¹ûÉÐδ°²×°¿ÉÏÂÔØ°²×°£¨°²×°ºóÖØÐÂÆô¶¯ IIS ¹ÜÀíÆ÷£©£¬ÏÂÔØÁ´½Ó£º
https://www.iis.net/downloads/microsoft/url-rewrite
2. ´ò¿ª IIS ¹ÜÀíÆ÷²¢Ñ¡ÔñTelerik Report ServerÕ¾µã¡£
3.Ñ¡Ôñ URL Rewrite Ä£¿é²¢Ö´ÐÐÒÔϲ½Ö裺
a) µã»÷¡°Add Rules¡±
b) Ñ¡Ôñ¡°Request Blocking¡±¹æÔò¡£
c) ¶ÔÓÚ¡°Block Access Based On¡±, Ñ¡Ôñ¡°URL Path¡±¡£
d) ¶ÔÓÚ¡°Pattern¡±£¬ÊäÈëÖµ: startup/register
e) µ¥»÷¡° OK¡±Éú´æ²¢¼¤»î¹æÔò¡£
ÈçÏÂͼËùʾ£º
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358
https://docs.telerik.com/report-server/knowledge-base/deserialization-vulnerability-cve-2024-1800
https://summoning.team/blog/progress-report-server-rce-cve-2024-4358-cve-2024-1800/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-06-05 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é
¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º