¡¾Îó²îͨ¸æ¡¿Spring SecurityÇå¾²ÈÆ¹ýÎó²î£¨CVE-2023-34034£©
Ðû²¼Ê±¼ä 2023-08-10Ò»¡¢Îó²î¸ÅÊö
CVE ID | CVE-2023-34034 | ·¢Ã÷ʱ¼ä | 2023-07-18 |
Àà ÐÍ | Çå¾²ÈÆ¹ý | µÈ ¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
¹¥»÷ÖØÆ¯ºó | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ֪ |
Spring SecurityÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢ÇҸ߶ȿɶ¨ÖƵÄÉí·ÝÑéÖ¤ºÍ»á¼û¿ØÖÆ¿ò¼Ü¡£¡£¡£¡£¡£¡£Spring WebFlux ÊÇSpring Framework 5.0 ÖÐÒýÈëµÄÒ»ÖÖÏìӦʽWeb¿ò¼Ü£¬£¬£¬Æä½¹µãÖ¼ÔÚ´¦Öóͷ£Òì²½¡¢·ÇÛÕ±ÕºÍÏìӦʽ±à³Ì¹æ·¶¡£¡£¡£¡£¡£¡£
8ÔÂ10ÈÕ£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨VSRC¼à²âµ½Spring SecurityÇå¾²ÈÆ¹ýÎó²î£¨CVE-2023-34034£©µÄϸ½Ú¼°PoCÔÚ»¥ÁªÍøÉϹûÕæ£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·Ö×î¸ßΪ9.8¡£¡£¡£¡£¡£¡£
ÔÚSpring WebFlux Ó¦ÓóÌÐòµÄSpring SecurityÉèÖÃÖÐʹÓÃÎÞǰ׺˫ͨÅä·ûģʽ£¨¡°**¡±£©»áµ¼ÖÂSpring SecurityºÍSpring WebFluxÖ®¼äµÄģʽ²»Æ¥Å䣬£¬£¬¿ÉÄܵ¼ÖÂÇå¾²ÈÆ¹ý£¬£¬£¬¿ÉʹÓøÃÎó²îÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏ»á¼ûÌØÈ¨¶Ëµã¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Spring Security 6.1.0 - 6.1.1
Spring Security 6.0.0 - 6.0.4
Spring Security 5.8.0 - 5.8.4
Spring Security 5.7.0 - 5.7.9
Spring Security 5.6.0 - 5.6.11
×¢£ºÇкÏÒÔÏÂÌõ¼þµÄÓ¦ÓóÌÐòÒ×ÊܸÃÎó²î¹¥»÷£º
l Web Ó¦ÓóÌÐòʹÓÃSpring WebFlux ¿ò¼Ü£¨Ê¹ÓýϾɵÄSpring MVC¿ò¼ÜµÄÓ¦ÓóÌÐò²»ÊÜÓ°Ï죩¡£¡£¡£¡£¡£¡£
l ¸ÃWeb Ó¦ÓóÌÐòʹÓÃÁËÉÏÊö±£´æÎó²îµÄSpring Security °æ±¾¡£¡£¡£¡£¡£¡£
l webÓ¦ÓóÌÐòʹÓà URL ·¾¶¹ýÂËÉèÖà Spring Security»á¼û¹æÔò¡£¡£¡£¡£¡£¡£URL ·¾¶Ä£Ê½²»ÒÔÕýб¸Ü×Ö·û (/) ¿ªÍ·¡£¡£¡£¡£¡£¡£ÈôÊÇ URL ·¾¶°üÀ¨¶à¶ÎͨÅä·û ( **)£¬£¬£¬Ôò»áÔöÌíÎó²îµÄÑÏÖØÐÔ¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬ÓÉÓÚ¸ÃÎó²î£¬£¬£¬¡°admin/**¡±¹æÔò²»»áÆ¥ÅäÈκΠURL£¬£¬£¬ÓÉÓÚËüµÄ¿ªÍ·È±ÉÙб¸Ü/£¬£¬£¬µ¼ÖÂÈκÎÈ˶¼¿ÉÒÔ»á¼û admin/ ϵÄËùÓÐÍøÒ³¡£¡£¡£¡£¡£¡£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º
Spring Security >= 6.1.2
Spring Security >= 6.0.5
Spring Security >= 5.8.5
Spring Security >= 5.7.10
Spring Security >= 5.6.12
ÒÔÉϰ汾ÐèÒªSpring Framework °æ±¾£º
Spring Framework >= 6.0.11
Spring Framework >= 5.3.29
Spring Framework >= 5.2.25
ÏÂÔØÁ´½Ó£º
https://spring.io/projects
3.2 ÔÝʱ²½·¥
¿ÉÔÚ Spring Security ÖÐʹÓõÄÈκΠURL ¹ýÂËÆ÷ÖÐÌí¼Óǰµ¼Õýб¸Ü/À´»º½â¸ÃÎó²î£¬£¬£¬ÀýÈ磬£¬£¬½«pathMatchers("admin/**") Ìæ»»Îª pathMatchers("/admin/**")¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://spring.io/security/cve-2023-34034
https://jfrog.com/blog/spring-webflux-cve-2023-34034-write-up-and-proof-of-concept/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-08-10 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 c7c7ÓéÀÖÆ½Ì¨¼ò½é
c7c7ÓéÀÖÆ½Ì¨½¨ÉèÓÚ1996Ä꣬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°c7c7ÓéÀÖÆ½Ì¨´óÏ㬣¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£
5.2 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨
c7c7ÓéÀÖÆ½Ì¨Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ