΢ÐÅÖ§¸¶SDK XXE·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-03·ì϶±àºÅºÍ¼¶±ð
ÎÞ ¸ßΣ
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
JAVA SDK£¬£¬£¬£¬£¬£¬WxPayAPI_JAVA_v3
·ì϶¸ÅÊö
΢ÐÅÔÚJAVA°æ±¾µÄSDKÖÐÌṩcallback»Øµ÷Ö°ÄÜ£¬£¬£¬£¬£¬£¬ÓÃÀ´Ô®ÊÖÉ̼ҽӹÜÒì²½¸¶¿îÁ˾֣¬£¬£¬£¬£¬£¬¸Ã½Ó¿Ú½ÓÊÜXMLÌåʽµÄÊý¾Ý£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»»ú¹Ø¶ñÒâµÄ»Øµ÷Êý¾Ý£¨XMLÌåʽ£©À´ÇÔÈ¡É̼ҷþÎñÆ÷ÉϵÄÈκÎÐÅÏ¢¡£¡£¡£¡£¡£¡£Ò»µ©¹¥»÷Õß»ñµÃÁ˹ؼüÖ§¸¶µÄ°²È«ÃÜÔ¿£¨md5-keyºÍÉ̼ÒÐÅÏ¢£©£¬£¬£¬£¬£¬£¬½«Äܹ»Ö±½ÓʵÏÖ0ÔªÖ§¸¶²É°ìÈκÎÉÌÆ·¡£¡£¡£¡£¡£¡£µ±XMLÔÊÐíÒýÓÃ±í²¿ÊµÌåʱ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÄܹ»Í¨¹ý»ú¹Ø¶ñÒâXMLʵÌåÎļþ£¬£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì¶ÁÈ¡ËÁÒâϵͳÎļþ¡¢Ô¶³ÌÖ´ÐÐϵͳºÅÁîµÈһϵÁÐΣÏÕ²Ù×÷£¬£¬£¬£¬£¬£¬ÑϳÁ·çÏÕÉ̼ҷþÎñÆ÷µÄϵͳ°²È«¡£¡£¡£¡£¡£¡£
XXE (XML External Entity Injection) ·ì϶²úÉúÔÚÀûÓ÷¨Ê½½âÎö XML ÊäÈëʱ£¬£¬£¬£¬£¬£¬Ã»Óв»ÈÝ±í²¿ÊµÌåµÄ¼ÓÔØ¡£¡£¡£¡£¡£¡£ÊÇÒ»ÖÖÕë¶ÔʹÓÃXML½»»¥µÄWebÀûÓ÷¨Ê½µÄ¹¥»÷²½Öè¡£¡£¡£¡£¡£¡£
Ŀǰ£¬£¬£¬£¬£¬£¬Î¢ÐŹٷ½ÉÐδ¶ÔSDK½øÐн¨¸´£¬£¬£¬£¬£¬£¬µ«·ì϶ÀûÓÃÐÅÏ¢ÒÔ¼°¹¥»÷·½Ê½Òѱ»¹«¿ª£¬£¬£¬£¬£¬£¬Ó°ÏìÁìÓò¾Þ´ó£¨ÒѾÅû¶³öµÄÓÐİİ¡¢vivoÈ·ÈÏ´æÔڸ÷ì϶£©£¬£¬£¬£¬£¬£¬½¨ÒéÓõ½Î¢ÐÅÖ§¸¶JAVA SDKµÄÆóÒµÁ¢¿Ì·¢Õ¹×Բ鲢¹Ø×¢Î¢ÐŹٷ½°²È«¹«¸æ¡£¡£¡£¡£¡£¡£
2018Äê7ÔÂ2ºÅ£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÔÚ¹ú±í·ì϶ÅûÂ¶ÍøÕ¾³õ´Î°ä²¼£º

±¾µØÑéÖ¤½ØÍ¼£º

½¨¸´½¨Òé
ÆÚ´ý΢ÐŹٷ½Éý¼¶¹æ»®¡£¡£¡£¡£¡£¡£
Óû§¿ÉʹÓÿª·¢Ëµ»°ÌṩµÄ½ûÓÃ±í²¿ÊµÌåµÄ²½Öè¡£¡£¡£¡£¡£¡£java½ûÓÃ±í²¿ÊµÌåµÄ´úÂëÈçÏ£º
dbf.setExpandEntityReferences(false);
²Î¿¼Á´½Ó
http://seclists.org/fulldisclosure/2018/Jul/3¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ