Zimbra Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-18

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º

ZimbraCollaboration Server 8.8.11 ֮ǰµÄ°æ±¾¶¼Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£º

1. Zimbra < 8.7.11 °æ±¾ÖУ¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÎÞÐèµÇ¼µÄÇéÐÎÏ£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

2. Zimbra < 8.8.11 °æ±¾ÖУ¬£¬£¬£¬ÔÚЧÀͶËʹÓà Memcached ×ö»º´æµÄÇéÐÎÏ£¬£¬£¬£¬¾­ÓɵǼÈÏÖ¤ºóµÄ¹¥»÷Õß¿ÉÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ


Îó²î¸ÅÊö


Zimbra ÊÇÒ»¼ÒÌṩרҵµÄµç×ÓÓʼþÈí¼þ¿ª·¢¹©Ó¦ÉÌ£¬£¬£¬£¬Ö÷ÒªÌṩ Zimbra Collaboration Server Э×÷ЧÀÍÆ÷Ì×¼þ¡¢Zimbra Desktop ÓʼþÖÎÀíÈí¼þµÈÓʼþ·½ÃæµÄÈí¼þ¡£¡£¡£¡£¡£¡£¡£


3 Ô 13 ÈÕ£¬£¬£¬£¬ ÍâÑóÇå¾²Ñо¿Ô± tint0 Ðû²¼ÁËһƪ²©¿Í£¬£¬£¬£¬Ö¸³ö Zimbra Collaboration Server ϵͳȫ°æ±¾±£´æÒ»ÏµÁÐÎó²î£¬£¬£¬£¬Í¨¹ý¶ñÒâʹÓÿÉÒÔµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£


Îó²îϸ½Ú


µ± Zimbra ±£´æÏñí§ÒâÎļþ¶ÁÈ¡¡¢XXE£¨XML ÍⲿʵÌå×¢È룩 ÕâÖÖÎó²îʱ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î¶ÁÈ¡ localconfig.xml ÉèÖÃÎļþ£¬£¬£¬£¬»ñÈ¡µ½ zimbra admin ldap password£¬£¬£¬£¬²¢Í¨¹ý 7071 admin ¶Ë¿Ú¾ÙÐÐ SOAP AuthRequest ÈÏÖ¤£¬£¬£¬£¬»ñµÃ admin authtoken£¬£¬£¬£¬È»ºó¾Í¿ÉÒÔʹÓà admin authtoken ¾ÙÐÐí§ÒâÎļþÉÏ´«£¬£¬£¬£¬´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄΣº¦¡£¡£¡£¡£¡£¡£¡£


¶ø tint0 ²©¿ÍÎÄÕÂÀïÖ¸³ö£¬£¬£¬£¬×ÝÈ»ÔÚ 7071 admin ¶Ë¿Ú×öÁË·À»ðǽÉèÖá¢²î³ØÍ⿪·ÅµÄÇéÐÎÏ£¬£¬£¬£¬Ò²¿ÉÒÔʹÓñ£´æÓÚ 443 ͨË×Óû§¶Ë¿ÚЧÀÍÀïÉí·ÝÈÏÖ¤µÄÒ»¸öÌØÕ÷£¬£¬£¬£¬ÅäºÏ ProxyServlet.doProxy() ÒªÁìÀïµÄ SSRF£¬£¬£¬£¬Í¬ÑùÒ²ÄÜÍê³É admin SOAP AuthRequest ÈÏÖ¤£¬£¬£¬£¬»ñµÃ admin authtoken¡£¡£¡£¡£¡£¡£¡£


ÏÂͼΪÅäºÏʹÓà XXE ºÍ ProxyServlet SSRF Îó²îÄõ½ admin authtoken ºó£¬£¬£¬£¬Í¨¹ýÎļþÉÏ´«ÔÚЧÀͶËÖ´ÐÐí§Òâ´úÂëµÄÍâµØ²âÊÔ½ØÍ¼£º


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



³ý´ËÖ®Í⣬£¬£¬£¬ÔÚ ZimbraЧÀͶËʹÓà Memcached ×ö»º´æÐ§ÀÍʱ£¬£¬£¬£¬»¹¿ÉÒÔʹÓà SSRF ¹¥»÷ Memcached »º´æÐ§ÀÍ£¬£¬£¬£¬Í¨¹ý·´ÐòÁл¯ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£²»¹ýÓÉÓÚ Zimbra µÄ×°ÖÃÀú³ÌÖÐµÄ bug£¬£¬£¬£¬µ¼Öµ¥Ð§ÀÍÆ÷µÄÇéÐÎÏ£¬£¬£¬£¬Memcached Ö»¹Ü»áÆô¶¯£¬£¬£¬£¬µ«²¢²»»áʹÓ㬣¬£¬£¬Òò´Ë SSRF ¹¥»÷ Memcached ·´ÐòÁл¯µÄʹÓó¡¾°½ÏÁ¿ÓÐÏÞ¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


¸üйٷ½Ðû²¼µÄÇå¾²²¹¶¡»òÉý¼¶ Zimbra µ½×îа棺https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories