XStream¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-03-150x00 Îó²î¸ÅÊö
XStreamÊÇÒ»¸öJava¹¤¾ßºÍXMLÏ໥ת»»µÄ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÔÚ½«JavaBeanÐòÁл¯¡¢»ò½«XMLÎļþ·´ÐòÁл¯Ê±£¬£¬£¬£¬£¬£¬£¬Ëü²»ÐèÒªÆäËü¸¨ÖúÀàºÍÓ³ÉäÎļþ£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃXMLÐòÁл¯²»ÔÙ·±Ëö¡£¡£¡£¡£
2021Äê03ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬XStream¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬¹ûÕæÁËXStreamÖеÄ11¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÔì³É¾Ü¾øÐ§ÀÍ¡¢SSRF¡¢É¾³ýí§ÒâÎļþ¡¢Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî»ò´úÂë¡£¡£¡£¡£
0x01 Îó²îÏêÇé

±¾´Î¹ûÕæµÄ11¸öÎó²îÈçÏ£º
CVE-ID | ÀàÐÍ | ÏêÇé |
CVE-2021-21341 | ¾Ü¾øÐ§ÀÍ | XStream¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£ |
CVE-2021-21342 | SSRF | XStreamÖб£´æSSRFÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»á¼ûÀ´×ÔÄÚ²¿Íø»òµ±ÌïÖ÷»úÖÐ×ÊÔ´µÄí§ÒâURLµÄÊý¾ÝÁ÷¡£¡£¡£¡£ |
CVE-2021-21343 | í§ÒâÎļþɾ³ý | µ±×÷·ÏÐòÁл¯Ê±£¬£¬£¬£¬£¬£¬£¬Ö»ÒªÖ´ÐÐÀú³Ì¾ßÓÐ×㹻ȨÏÞ£¬£¬£¬£¬£¬£¬£¬XStream±£´æµ±ÌïÖ÷»úí§ÒâÎļþɾ³ýÎó²î¡£¡£¡£¡£ |
CVE-2021-21344 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£ |
CVE-2021-21345 | Ô¶³ÌÏÂÁîÖ´ÐÐ | XStreamÒ×ÊÜÔ¶³ÌÏÂÁîÖ´Ðй¥»÷¡£¡£¡£¡£ |
CVE-2021-21346 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£ |
CVE-2021-21347 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£ |
CVE-2021-21348 | ReDos | XStreamÒ×ÊÜʹÓÃÕýÔò±í´ïʽµÄ¾Ü¾øÐ§ÀÍ£¨ReDos£©¹¥»÷¡£¡£¡£¡£ |
CVE-2021-21349 | SSRF | XStreamÖб£´æSSRFÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»á¼ûÀ´×ÔÄÚ²¿Íø»òµ±ÌïÖ÷»úÖÐ×ÊÔ´µÄí§ÒâURLµÄÊý¾ÝÁ÷¡£¡£¡£¡£ |
CVE-2021-21350 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£ |
CVE-2021-21351 | í§Òâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£ |
XStreamí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21344£©
ÔÚ·´ÐòÁл¯Ê±´¦Öóͷ£µÄÁ÷°üÀ¨ÀàÐÍÐÅÏ¢ÒÔÖØÐ½¨ÉèÒÔǰдÈëµÄ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬XStream»ùÓÚÕâЩÀàÐÍÐÅÏ¢½¨ÉèеÄʵÀý¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓô¦Öóͷ£ºóµÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÖ´ÐдÓÔ¶³ÌЧÀÍÆ÷¼ÓÔØµÄí§Òâ´úÂë¡£¡£¡£¡£
Ó°Ïì¹æÄ£
XStream <= 1.4.15
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ1.4.16»ò¸ü¸ß°æ±¾¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://x-stream.github.io/download.html
0x03 ²Î¿¼Á´½Ó
https://x-stream.github.io/security.html#workaround
https://x-stream.github.io/CVE-2021-21348.html
https://nvd.nist.gov/vuln/detail/CVE-2021-21341
0x04 ʱ¼äÏß
2021-03-15 XStreamÐû²¼Ç徲ͨ¸æ
2021-03-15 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ