Apache Axis Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-12Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0227£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÊÜÓ°ÏìµÄ°æ±¾
Apache Axis Version = 1.4
²»ÊÜÓ°Ïì°æ±¾
Apache Axis2 ËùÓа汾£¨ÏÖÔÚÔÝʱûÓз¢Ã÷Axis2µÄЧÀͱ£´æÍâÁªÕ÷Ïó£©
Îó²î¸ÅÊö
Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWebЧÀͼܹ¹¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAPЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÖÖÖÖ¹«ÓÃЧÀͼ°API£¬£¬£¬£¬£¬£¬£¬ÒÔÌìÉúºÍ°²ÅÅWebЧÀÍÓ¦Óᣡ£¡£¡£¡£¡£¡£
Axis¸½´øµÄĬÈÏЧÀÍStockQuoteService.jws°üÀ¨Ò»¸öÓ²±àÂëµÄHTTP URL£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ´¥·¢HTTPÇëÇ󡣡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓòÃû£¨www.xmltoday.com£©½ÓÊÜ»òÕßͨ¹ýARPÓÕÆÐ§ÀÍÆ÷´Ó¶øÖ´ÐÐMITM¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢½«HTTPÇëÇóÖØ¶¨Ïòµ½¶ñÒâWebЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬ÔÚApache AxisЧÀÍÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂ루CVE-2019-0227£©¡£¡£¡£¡£¡£¡£¡£
ÏÖÔÚΪÁ˱ÜÃâÓòÃûwww.xmltoday.com±»¶ñÒâ¹¥»÷ÕßʹÓ㬣¬£¬£¬£¬£¬£¬ÒѾÓа×ñ×Ó½«Æä¹ºÖᣡ£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
POC£ºhttps://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2019-0227¡£¡£¡£¡£¡£¡£¡£
Éó²éAxisÔ´ÖеÄXMLutils£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ¿´µ½¡°setInstanceFollowRedirects¡±ÊôÐÔÉèÖÃΪ¡°true¡±¡£¡£¡£¡£¡£¡£¡£Õâ֤ʵÁË¡°XMLUtils.newDocument¡±ÏÖʵÉÏ»á×ñÕÕÖØ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£
ÓµÓдËÓò²¢²»ÊÇÀÄÓá°StockQuoteService.jws¡±»òÀ´×ÔAxisЧÀÍÆ÷µÄÈÎºÎÆäËûHTTPÇëÇóµÄΨһҪÁì¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÇëÇóÊÇͨ¹ýHTTP¾ÙÐе쬣¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÈôÊÇÄúÓëAxisЧÀÍÆ÷λÓÚÍ³Ò»ÍøÂçÉÏ£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔÖ´ÐÐÕë¶Ô¸ÃЧÀÍÆ÷µÄÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬£¬£¬£¬È»ºóʹÓá°StockQuoteService.jws¡±´¥·¢Æ÷»òÆÚ´ýHTTPÇëÇó²¢Ôٴν«´ËÇëÇóÖØ¶¨Ïòµ½localhostÒÔʹÓÃSSRF¼¼ÇÉ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃËüµÄ°ì·¨ÈçÏ£ºARPÖж¾Ä¿µÄAxisЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£
½«ÈκÎHTTPÁ÷Á¿Öض¨Ïòµ½Äú×Ô¼ºµÄWebЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£
ÖØ¶¨Ïòµ½ÌØÖƵÄlocalhost URL£¬£¬£¬£¬£¬£¬£¬¸ÃURLÔÚAxisÖÐÆô¶¯Ð§ÀÍ¡£¡£¡£¡£¡£¡£¡£
´¥·¢HTTPÇëÇóÒÔÖØ¶¨ÏòÇëÇó¡°StockQuoteService.jws¡±¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
È·±£ÔÚAxis»òAxis2ÖÐÔËÐеÄÈκοâ»òЧÀͲ»±£´æÍâÁªµÄHTTP/HTTPSÇëÇ󡣡£¡£¡£¡£¡£¡£
Apache Axis2µÄÏÂÔØµØµãΪ£º
http://axis.apache.org/axis2/java/core/download.html
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ