XStream¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-03-150x00 ·ì϶¸ÅÊö
XStreamÊÇÒ»¸öJava¶ÔÏóºÍXMLÏ໥ת»»µÄ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÔÚ½«JavaBeanÐòÁл¯¡¢»ò½«XMLÎļþ·´ÐòÁл¯Ê±£¬£¬£¬£¬£¬£¬£¬Ëü²»±ØÒªÆäËü¸¨ÖúÀàºÍÓ³ÉäÎļþ£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃXMLÐòÁл¯²»ÔÙ·±Ëö¡£¡£¡£¡£¡£¡£¡£¡£
2021Äê03ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬XStream¹Ù·½°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬¹«¿ªÁËXStreamÖеÄ11¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Ôì³É»Ø¾ø·þÎñ¡¢SSRF¡¢É¾³ýËÁÒâÎļþ¡¢Ô¶³ÌÖ´ÐÐËÁÒâºÅÁî»ò´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

±¾´Î¹«¿ªµÄ11¸ö·ì϶ÈçÏ£º
CVE-ID | ÀàÐÍ | ÏêÇé |
CVE-2021-21341 | »Ø¾ø·þÎñ | XStream¿ÉÄܵ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21342 | SSRF | XStreamÖдæÔÚSSRF·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûÀ´×ÔÄÚ²¿Íø»ò±¾µØÖ÷»úÖÐ×ÊÔ´µÄËÁÒâURLµÄÊý¾ÝÁ÷¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21343 | ËÁÒâÎļþɾ³ý | µ±È¡µÞÐòÁл¯Ê±£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐִǰ¹ý³ÌÓµÓÐ×㹻ȨÏÞ£¬£¬£¬£¬£¬£¬£¬XStream´æÔÚ±¾µØÖ÷»úËÁÒâÎļþɾ³ý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21344 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21345 | Ô¶³ÌºÅÁîÖ´ÐÐ | XStreamÒ×ÊÜÔ¶³ÌºÅÁîÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21346 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21347 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21348 | ReDos | XStreamÒ×ÊÜʹÓÃÕýÔò±í°×ʽµÄ»Ø¾ø·þÎñ£¨ReDos£©¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21349 | SSRF | XStreamÖдæÔÚSSRF·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûÀ´×ÔÄÚ²¿Íø»ò±¾µØÖ÷»úÖÐ×ÊÔ´µÄËÁÒâURLµÄÊý¾ÝÁ÷¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21350 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ |
CVE-2021-21351 | ËÁÒâ´úÂëÖ´ÐÐ | XStreamÒ×ÊÜËÁÒâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ |
XStreamËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-21344£©
ÔÚ·´ÐòÁл¯Ê±´¦ÖõÄÁ÷Ô̺¬ÀàÐÍÐÅÏ¢ÒÔ³Áд´½¨ÒÔǰдÈëµÄ¶ÔÏ󣬣¬£¬£¬£¬£¬£¬XStream»ùÓÚÕâЩÀàÐÍÐÅÏ¢´´½¨ÐµÄÊ·ý¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»°Ñ³Ö´¦ÖúóµÄÊäÈëÁ÷²¢´úÌæ»ò×¢Èë¶ÔÏ󣬣¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÖ´ÐдÓÔ¶³Ì·þÎñÆ÷¼ÓÔØµÄËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
XStream <= 1.4.15
0x02 ´ëÖý¨Òé
ĿǰÕâЩ·ì϶ÒѾ½¨¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ1.4.16»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://x-stream.github.io/download.html
0x03 ²Î¿¼Á´½Ó
https://x-stream.github.io/security.html#workaround
https://x-stream.github.io/CVE-2021-21348.html
https://nvd.nist.gov/vuln/detail/CVE-2021-21341
0x04 ¹¦·òÏß
2021-03-15 XStream°ä²¼°²È«²¼¸æ
2021-03-15 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ