Apache Axis Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-04-12·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0227£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÊÜÓ°ÏìµÄ°æ±¾
Apache Axis Version = 1.4
²»ÊÜÓ°Ïì°æ±¾
Apache Axis2 ËùÓа汾£¨Ä¿Ç°ÁÙʱûÓз¢ÏÖAxis2µÄ·þÎñ´æÔÚ±íÁª¾°Ïó£©
·ì϶¸ÅÊö
Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·Ô̺¬ÁËJavaºÍC++˵»°ÊµÏÖµÄSOAP·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÒÔ¼°¸÷À๫Ó÷þÎñ¼°API£¬£¬£¬£¬£¬£¬ÒÔÌìÉúºÍ²¿ÊðWeb·þÎñÀûÓᣡ£¡£¡£¡£¡£¡£¡£
Axis¸½´øµÄĬÈÏ·þÎñStockQuoteService.jwsÔ̺¬Ò»¸öÓ²±àÂëµÄHTTP URL£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ´¥·¢HTTPÒªÇ󡣡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÓòÃû£¨www.xmltoday.com£©ÊÕÊÜ»òÕßͨ¹ýARPºýŪ·þÎñÆ÷´Ó¶øÖ´ÐÐMITM¹¥»÷£¬£¬£¬£¬£¬£¬²¢½«HTTPÒªÇó³Á¶¨Ïòµ½¶ñÒâWeb·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÔÚApache Axis·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂ루CVE-2019-0227£©¡£¡£¡£¡£¡£¡£¡£¡£
ĿǰΪÁËÔ¤·ÀÓòÃûwww.xmltoday.com±»¶ñÒâ¹¥»÷ÕßÀûÓ㬣¬£¬£¬£¬£¬ÒѾÓа×ñ×Ó½«Æä²É°ì¡£¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
POC£ºhttps://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2019-0227¡£¡£¡£¡£¡£¡£¡£¡£
²é¿´AxisÔ´ÖеÄXMLutils£¬£¬£¬£¬£¬£¬Äܹ»¿´µ½¡°setInstanceFollowRedirects¡±ÊôÐÔÉèÖÃΪ¡°true¡±¡£¡£¡£¡£¡£¡£¡£¡£Õâ֤ʵÁË¡°XMLUtils.newDocument¡±ÏÖʵÉÏ»á×ñѳÁ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£¡£
Õ¼ÓдËÓò²¢²»ÊÇÀÄÓá°StockQuoteService.jws¡±»òÀ´×ÔAxis·þÎñÆ÷µÄÈÎºÎÆäËûHTTPÒªÇóµÄΨһ²½Öè¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÒªÇóÊÇͨ¹ýHTTP½øÐе쬣¬£¬£¬£¬£¬ÕâÒâζ×ÅÈôÊÇÄúÓëAxis·þÎñÆ÷λÓÚÍ³Ò»ÍøÂçÉÏ£¬£¬£¬£¬£¬£¬ÔòÄܹ»Ö´ÐÐÕë¶Ô¸Ã·þÎñÆ÷µÄÖÐÑëÈ˹¥»÷£¬£¬£¬£¬£¬£¬¶øºóʹÓá°StockQuoteService.jws¡±´¥·¢Æ÷»òÆÚ´ýHTTPÒªÇó²¢Ôٴν«´ËÒªÇó³Á¶¨Ïòµ½localhostÒÔÀûÓÃSSRF¼¼ÇÉ¡£¡£¡£¡£¡£¡£¡£¡£ÀûÓÃËüµÄ²½ÖèÈçÏ£ºARPÖж¾Ö¸±êAxis·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
½«ÈκÎHTTPÁ÷Á¿³Á¶¨Ïòµ½Äú×Ô¼ºµÄWeb·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
³Á¶¨Ïòµ½ÌØÔìµÄlocalhost URL£¬£¬£¬£¬£¬£¬¸ÃURLÔÚAxisÖÐÆô¶¯·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£
´¥·¢HTTPÒªÇóÒÔ³Á¶¨ÏòÒªÇó¡°StockQuoteService.jws¡±¡£¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
È·±£ÔÚAxis»òAxis2ÖÐÔËÐеÄÈκοâ»ò·þÎñ²»´æÔÚ±íÁªµÄHTTP/HTTPSÒªÇ󡣡£¡£¡£¡£¡£¡£¡£
Apache Axis2µÄÏÂÔØµØÖ·Îª£º
http://axis.apache.org/axis2/java/core/download.html
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ