Apache Struts2 ¸ßΣÎó²îÀ´Ï® £¬×ðÁú¿­¹ÙÍøÈë¿ÚÌṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2023-12-08

12ÔÂ7ÈÕ £¬Apache Struts2¹Ù·½¸üÐÂÁËÒ»¸ö±£´æÓÚApache Struts2ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-50164£©¡£¸ÃÎó²îÔ´ÓÚÎļþÉÏ´«Âß¼­ÓÐȱÏÝ £¬¹¥»÷Õß¿ÉÒÔʹÓÃÎļþÉÏÔØ²ÎÊýÒÔÆôÓ÷¾¶±éÀú £¬ÔÚijЩÇéÐÎÏ £¬Õâ¿ÉÄܵ¼ÖÂÉÏÔØ¿ÉÓÃÓÚÖ´ÐÐÔ¶³Ì´úÂëÖ´ÐеĶñÒâÎļþ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ÏÖÔÚ¸ÃÎó²îPOC£¨¿´·¨ÑéÖ¤´úÂ룩δ¹ûÕæ £¬ËæÊ±±£´æ±»ÍøÂçºÚ²úʹÓþÙÐÐÍÚ¿óľÂíºÍ½©Ê¬ÍøÂçµÈ¹¥»÷ÐÐΪµÄΣº¦¡£×ðÁú¿­¹ÙÍøÈë¿Ú±±Ú¤Êý¾ÝʵÑéÊÒÇå¾²Ñо¿ÍŶӱÈÕÕÆÊÎö±¾´Î¸üÐÂÓë¸üÐÂǰµÄÔ´Â루ÒÔ2.5.x°æ±¾ÎªÀý£©ÍƲâÎó²î³ÉÒò¿ÉÄÜΪHttpParametersÀàÒªÁì¶ÔHTTP²ÎÊýµü´úÆ÷µÄ²Ù×÷²»µ±µ¼ÖÂremove()ÒªÁìÎ´ÆÆËð²ÎÊýµü´úÆ÷µ¼Ö·¾¶±»±éÀú¡£



 ÐÞ¸´½¨Òé 



1¡¢Í¨Óý¨Òé


¢Ù °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬ïÔ̭ϵͳÎó²î £¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£


¢Ú ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬Ð޸ķÀ»ðǽսÂÔ £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬ ïÔÌ­½«Î£ÏÕ·þÎñ£¨Èç SSH¡¢RDP µÈ£©Ì»Â¶µ½¹«Íø £¬ïÔÌ­¹¥»÷Ãæ¡£


¢Û ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£


¢Ü ÔöǿϵͳÓû§ºÍȨÏÞ¹ÜÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨ ÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£


¢Ý ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


2¡¢Éý¼¶²¹¶¡


ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´ £¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½Apache Struts 2.5.33¡¢6.3.0.2»ò¸ü¸ß°æ±¾¡£ÏÂÔØÁ´½Ó£º

https://struts.apache.org/download.cg



×ðÁú¿­¹ÙÍøÈë¿Ú½â¾ö¼Æ»® 



½¨ÒéÒ»£º×ðÁú¿­¹ÙÍøÈë¿ÚÌ쾵ųÈõÐÔɨÃèÓë¹ÜÀíϵͳÉý¼¶×îа汾


1¡¢Â©É¨6075°æ±¾


×ðÁú¿­¹ÙÍøÈë¿ÚÌ쾵ųÈõÐÔɨÃèÓë¹ÜÀíϵͳ6075°æ±¾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü £¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐзÇÊÚȨɨÃè £¬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺


6070°æ±¾Éý¼¶°üΪ607000538 £¬Éý¼¶°üÏÂÔØµØÖ·£ºhttps://venustech.download.venuscloud.cn/


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!

Éý¼¶ºóÒÑÖ§³Ö¸ÃÎó²î


2¡¢Â©É¨6080°æ±¾


×ðÁú¿­¹ÙÍøÈë¿ÚÌ쾵ųÈõÐÔɨÃèÓë¹ÜÀíϵͳ6080°æ±¾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü £¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐзÇÊÚȨɨÃè £¬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺


6080°æ±¾Éý¼¶°üΪÖ÷»ú²å¼þ°ü608000097-S608000098.svs©ɨ²å¼þ°üÏÂÔØµØÖ·£ºhttps://venustech.download.venuscloud.cn/


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!

Éý¼¶ºóÒÑÖ§³Ö¸ÃÎó²î


3¡¢Â©É¨»ùÏߺ˲é


ͨ¹ý×ðÁú¿­¹ÙÍøÈë¿ÚÌ쾵ųÈõÐÔɨÃèÓë¹ÜÀíϵͳ-ÉèÖú˲éÄ£¿é¶Ô¸ÃÎó²îÓ°ÏìµÄApache Struts2°æ±¾¾ÙÐлñÈ¡ £¬Ê¹ÓÃÖÇÄÜ»¯ÆÊÎöÑÐÅлúÖÆÑéÖ¤¸ÃÎó²îÊÇ·ñ±£´æ £¬ÈôÊDZ£´æ¸ÃÎó²î½¨Òé¸üе½Çå¾²°æ±¾¡£ÈçͼËùʾ£º


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!

»ùÏߺ˲éÒÑÖ§³ÖApache Struts2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î¼ì²éÏî


ÇëʹÓÃ×ðÁú¿­¹ÙÍøÈë¿ÚÌ쾵ųÈõÐÔɨÃèÓë¹ÜÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾 £¬ÊµÊ±¶Ô¸ÃÎó²î¾ÙÐмì²â £¬ÒԱ㾡¿ì½ÓÄÉÌá·À²½·¥¡£


½¨Òé¶þ£º×ðÁú¿­¹ÙÍøÈë¿Ú×ʲúÓëųÈõÐÔ¹ÜÀíÆ½Ì¨(ASM)ÅŲéÊÜÓ°Ïì×ʲú


×ðÁú¿­¹ÙÍøÈë¿Ú×ʲúÓëųÈõÐÔ¹ÜÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢ £¬¶ÔÈë¿â×ʲúÎó²îApache Struts2ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-50164£©¾ÙÐйÜÀí £¬ÈçͼËùʾ£º


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!

Ç鱨¹ÜÀíÄ£¿éÒÑÈë¿âµÄApache Struts2ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î


×ʲúÓëųÈõÐÔ¹ÜÀíÆ½Ì¨Æ¾Ö¤Ç鱨ÐÅÏ¢¸üеÄÎó²îÊÜÓ°ÏìʵÌ广ÔòÒÔ¼°ÏÖ³¡×ʲú¹ÜÀíʵÀýµÄ°æ±¾ÐÅÏ¢¾ÙÐÐ×Ô¶¯»¯Åöײ £¬¿ÉµÚһʱ¼äÖÀÖÐÊܸÃÎó²îÓ°ÏìµÄ×ʲú £¬ÈçͼËùʾ£º


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!

Ç鱨ÖÀÖеÄ×ʲúÐÅÏ¢


½¨ÒéÈý£º»ùÓÚÇå¾²¹ÜÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨¾ÙÐйØÁªÆÊÎö


¿í´óÓû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²¹ÜÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ £¬¾ÙÐйØÁªÕ½ÂÔÉèÖà £¬ÍŽáÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø £¬´Ó¶ø·¢Ã÷¡°Apache Struts2 Ô¶³Ì´úÂëÖ´ÐС±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£


1£©ÔÚÌ©ºÏµÄƽ̨ÖÐ £¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Apache Struts2 Ô¶³Ì´úÂëÖ´ÐУ¨CVE-2023-50164£©¡±Îó²îɨÃèʹÃü £¬ÅŲé¹ÜÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú£»


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿éÖÐ £¬Ìí¼Ó¡°L2_Apache_Struts2Ô¶³Ì´úÂëÖ´ÐÐÎó²îʹÓá± £¬Í¨¹ý×ðÁú¿­¹ÙÍøÈë¿Ú¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾ £¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«Apache Struts2 Ô¶³Ì´úÂëÖ´ÐÐÎó²îʹÓõĿÉÒÉÐÐΪԴµØÖ·Ìí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖÐ £¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓã»


3£©Ìí¼Ó¡°L3_Apache_Struts2Ô¶³Ì´úÂëÖ´ÐÐÎó²îʹÓÃÀֳɡ± £¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ¡°L2_Apache_Struts2Ô¶³Ì´úÂëÖ´ÐÐÎó²îʹÓá± £¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ± £¬Ä¿µÄµØÖ·ÒýÓÃ×ʲúÎó²î»òÔ´µØÖ·Æ¥ÅäÍþвÇ鱨 £¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


½¨ÒéËÄ£ºATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé


1¡¢ATT&CK¹¥»÷Á´ÆÊÎö


ƾ֤¶ÔCVE-2023-50164Îó²îµÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö £¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒÕ½×¶Î £¬ÁýÕÖµÄTTP°üÀ¨£º

TA0001³õʼ»á¼û£ºT1190ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò

TA0002Ö´ÐУºT1059ÏÂÁîºÍ¾ç±¾Ú¹ÊÍÆ÷

TA0011ÏÂÁîºÍ¿ØÖÆ£ºT1105¹¤¾ß´«Êä


2¡¢´¦Öóͷ£¼Æ»®½¨æÅºÍSOAR¾ç±¾±àÅÅ


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ͨ¹ýÌ©ºÏÇå¾²¹ÜÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦ £¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾 £¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£


¹ØÓÚ±±Ú¤Êý¾ÝʵÑéÊÒ


±±Ú¤Êý¾ÝʵÑéÊÒÖÂÁ¦ÓÚÍøÂç¿Õ¼äÇ徲֪ʶ¹¤³ÌÑо¿ºÍϵͳ»¯½¨ÉèµÄרҵÍÅ¶Ó £¬ÓÉ×ðÁú¿­¹ÙÍøÈë¿Ú¼¯ÍÅÌì¾µÎó²îÑо¿ÍŶӡ¢Ì©ºÏ֪ʶ¹¤³ÌÍŶӡ¢´óÊý¾ÝʵÑéÊÒ£¨BDlab£©³¡¾°»¯ÆÊÎöÍŶÓÍŽá×é³É¡£ÊµÑéÊÒʼÖÕ±ü³ÖÒÔÐèÇóΪµ¼Ïò¡¢ÖªÊ¶¸³ÄܲúÆ·µÄ½¹µãÀíÄî £¬×¨×¢ÓÚÌá¹©ÍøÂç¿Õ¼äÇå¾²µÄ»ù´¡ÖªÊ¶Ñо¿ºÍ¿ª·¢ £¬Öƶ©ÍŽáÍþвºÍÎó²îÇ鱨¡¢ÍøÂç¿Õ¼ä×ʲúºÍÔÆÇå¾²¼à²âÊý¾ÝµÈ×ÛºÏÇ鱨ÒÔ¼°Óû§ÏÖʵ³¡¾°µÄÇå¾²ÆÊÎö·À»¤Õ½ÂÔ £¬¹¹½¨×Ô¶¯»¯ÊÓ²ìºÍ´¦Öóͷ£ÏìÓ¦²½·¥ £¬Ðγɳ¡¾°»¯¡¢½á¹¹»¯µÄ֪ʶ¹¤³Ìϵͳ £¬¶ÔÖÖÖÖÇå¾²²úÆ·¡¢Æ½Ì¨ºÍÇå¾²ÔËÓªÌṩ֪ʶ¸³ÄÜ¡£