Apache Struts2 ¸ßΣÎó²îÀ´Ï®£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌṩ½â¾ö¼Æ»®
Ðû²¼Ê±¼ä 2023-12-0812ÔÂ7ÈÕ£¬Apache Struts2¹Ù·½¸üÐÂÁËÒ»¸ö±£´æÓÚApache Struts2ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-50164£©¡£¸ÃÎó²îÔ´ÓÚÎļþÉÏ´«Âß¼ÓÐȱÏÝ£¬¹¥»÷Õß¿ÉÒÔʹÓÃÎļþÉÏÔزÎÊýÒÔÆôÓ÷¾¶±éÀú£¬ÔÚijЩÇéÐÎÏ£¬Õâ¿ÉÄܵ¼ÖÂÉÏÔØ¿ÉÓÃÓÚÖ´ÐÐÔ¶³Ì´úÂëÖ´ÐеĶñÒâÎļþ¡£
ÏÖÔÚ¸ÃÎó²îPOC£¨¿´·¨ÑéÖ¤´úÂ룩δ¹ûÕ棬Ëæʱ±£´æ±»ÍøÂçºÚ²úʹÓþÙÐÐÍÚ¿óľÂíºÍ½©Ê¬ÍøÂçµÈ¹¥»÷ÐÐΪµÄΣº¦¡£ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø±±Ú¤Êý¾ÝʵÑéÊÒÇå¾²Ñо¿ÍŶӱÈÕÕÆÊÎö±¾´Î¸üÐÂÓë¸üÐÂÇ°µÄÔ´Â루ÒÔ2.5.x°æ±¾ÎªÀý£©ÍƲâÎó²î³ÉÒò¿ÉÄÜΪHttpParametersÀàÒªÁì¶ÔHTTP²ÎÊýµü´úÆ÷µÄ²Ù×÷²»µ±µ¼ÖÂremove()ÒªÁìδÆÆËð²ÎÊýµü´úÆ÷µ¼Ö·¾¶±»±éÀú¡£
ÐÞ¸´½¨Òé
1¡¢Í¨Óý¨Òé
¢Ù °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
¢Ú ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ ïÔ̽«Î£ÏÕ·þÎñ£¨Èç SSH¡¢RDP µÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
¢Û ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
¢Ü ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨ ÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
¢Ý ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
2¡¢Éý¼¶²¹¶¡
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½Apache Struts 2.5.33¡¢6.3.0.2»ò¸ü¸ß°æ±¾¡£ÏÂÔØÁ´½Ó£º
https://struts.apache.org/download.cg
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½â¾ö¼Æ»®
½¨ÒéÒ»£ºÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳÉý¼¶×îа汾
1¡¢Â©É¨6075°æ±¾
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ6075°æ±¾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐзÇÊÚȨɨÃ裬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺
6070°æ±¾Éý¼¶°üΪ607000538£¬Éý¼¶°üÏÂÔصص㣺https://venustech.download.venuscloud.cn/
Éý¼¶ºóÒÑÖ§³Ö¸ÃÎó²î
2¡¢Â©É¨6080°æ±¾
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ6080°æ±¾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐзÇÊÚȨɨÃ裬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺
6080°æ±¾Éý¼¶°üΪÖ÷»ú²å¼þ°ü608000097-S608000098.svs©ɨ²å¼þ°üÏÂÔصص㣺https://venustech.download.venuscloud.cn/
Éý¼¶ºóÒÑÖ§³Ö¸ÃÎó²î
3¡¢Â©É¨»ùÏߺ˲é
ͨ¹ýÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ-ÉèÖú˲éÄ£¿é¶Ô¸ÃÎó²îÓ°ÏìµÄApache Struts2°æ±¾¾ÙÐлñÈ¡£¬Ê¹ÓÃÖÇÄÜ»¯ÆÊÎöÑÐÅлúÖÆÑéÖ¤¸ÃÎó²îÊÇ·ñ±£´æ£¬ÈôÊDZ£´æ¸ÃÎó²î½¨Òé¸üе½Çå¾²°æ±¾¡£ÈçͼËùʾ£º
»ùÏߺ˲éÒÑÖ§³ÖApache Struts2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î¼ì²éÏî
ÇëʹÓÃÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ÊµÊ±¶Ô¸ÃÎó²î¾ÙÐмì²â£¬ÒԱ㾡¿ì½ÓÄÉÌá·À²½·¥¡£
½¨Òé¶þ£ºÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø×ʲúÓëųÈõÐÔÖÎÀíƽ̨(ASM)ÅŲéÊÜÓ°Ïì×ʲú
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø×ʲúÓëųÈõÐÔÖÎÀíƽ̨ʵʱÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬¶ÔÈë¿â×ʲúÎó²îApache Struts2ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-50164£©¾ÙÐÐÖÎÀí£¬ÈçͼËùʾ£º
Ç鱨ÖÎÀíÄ£¿éÒÑÈë¿âµÄApache Struts2ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î
×ʲúÓëųÈõÐÔÖÎÀíƽ̨ƾ֤Ç鱨ÐÅÏ¢¸üеÄÎó²îÊÜÓ°ÏìʵÌå¹æÔòÒÔ¼°ÏÖ³¡×ʲúÖÎÀíʵÀýµÄ°æ±¾ÐÅÏ¢¾ÙÐÐ×Ô¶¯»¯Åöײ£¬¿ÉµÚһʱ¼äÖÀÖÐÊܸÃÎó²îÓ°ÏìµÄ×ʲú£¬ÈçͼËùʾ£º
Ç鱨ÖÀÖеÄ×ʲúÐÅÏ¢
½¨ÒéÈý£º»ùÓÚÇå¾²ÖÎÀíºÍ̬ÊƸÐ֪ƽ̨¾ÙÐйØÁªÆÊÎö
¿í´óÓû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍ̬ÊƸÐ֪ƽ̨£¬¾ÙÐйØÁªÕ½ÂÔÉèÖã¬ÍŽáÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬´Ó¶ø·¢Ã÷¡°Apache Struts2 Ô¶³Ì´úÂëÖ´ÐС±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£
1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Apache Struts2 Ô¶³Ì´úÂëÖ´ÐУ¨CVE-2023-50164£©¡±Îó²îɨÃèʹÃü£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú£»
2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿éÖУ¬Ìí¼Ó¡°L2_Apache_Struts2Ô¶³Ì´úÂëÖ´ÐÐÎó²îʹÓá±£¬Í¨¹ýÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º
̫ͨ¹ýÎö¹æÔò×Ô¶¯½«Apache Struts2 Ô¶³Ì´úÂëÖ´ÐÐÎó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓã»
3£©Ìí¼Ó¡°L3_Apache_Struts2Ô¶³Ì´úÂëÖ´ÐÐÎó²îʹÓÃÀֳɡ±£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ¡°L2_Apache_Struts2Ô¶³Ì´úÂëÖ´ÐÐÎó²îʹÓá±£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶȡ£
½¨ÒéËÄ£ºATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé
1¡¢ATT&CK¹¥»÷Á´ÆÊÎö
ƾ֤¶ÔCVE-2023-50164Îó²îµÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒս׶Σ¬ÁýÕÖµÄTTP°üÀ¨£º
TA0001³õʼ»á¼û£ºT1190ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò
TA0002Ö´ÐУºT1059ÏÂÁîºÍ¾ç±¾Ú¹ÊÍÆ÷
TA0011ÏÂÁîºÍ¿ØÖÆ£ºT1105¹¤¾ß´«Êä
2¡¢´¦Öóͷ£¼Æ»®½¨æźÍSOAR¾ç±¾±àÅÅ
ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍ̬ÊƸÐ֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦£¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾£¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£
¹ØÓÚ±±Ú¤Êý¾ÝʵÑéÊÒ
±±Ú¤Êý¾ÝʵÑéÊÒÖÂÁ¦ÓÚÍøÂç¿Õ¼äÇ徲֪ʶ¹¤³ÌÑо¿ºÍϵͳ»¯½¨ÉèµÄרҵÍŶӣ¬ÓÉÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅÌì¾µÎó²îÑо¿ÍŶӡ¢Ì©ºÏ֪ʶ¹¤³ÌÍŶӡ¢´óÊý¾ÝʵÑéÊÒ£¨BDlab£©³¡¾°»¯ÆÊÎöÍŶÓÍŽá×é³É¡£ÊµÑéÊÒʼÖÕ±ü³ÖÒÔÐèÇóΪµ¼Ïò¡¢ÖªÊ¶¸³ÄܲúÆ·µÄ½¹µãÀíÄרעÓÚÌṩÍøÂç¿Õ¼äÇå¾²µÄ»ù´¡ÖªÊ¶Ñо¿ºÍ¿ª·¢£¬Öƶ©ÍŽáÍþвºÍÎó²îÇ鱨¡¢ÍøÂç¿Õ¼ä×ʲúºÍÔÆÇå¾²¼à²âÊý¾ÝµÈ×ÛºÏÇ鱨ÒÔ¼°Óû§ÏÖʵ³¡¾°µÄÇå¾²ÆÊÎö·À»¤Õ½ÂÔ£¬¹¹½¨×Ô¶¯»¯ÊÓ²ìºÍ´¦Öóͷ£ÏìÓ¦²½·¥£¬Ðγɳ¡¾°»¯¡¢½á¹¹»¯µÄ֪ʶ¹¤³Ìϵͳ£¬¶ÔÖÖÖÖÇå¾²²úÆ·¡¢Æ½Ì¨ºÍÇå¾²ÔËÓªÌṩ֪ʶ¸³ÄÜ¡£