Apache Struts2ÎļþÉÏ´«·ì϶£¨CVE-2024-53677£©À´Ï®£¬£¬OG¶«·½ÌüÌṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2024-12-18

Struts2¿ò¼ÜÊÇÒ»¸öÓÃÓÚ¿ª·¢Java EEÍøÂçÀûÓ÷¨Ê½µÄÊ¢¿ªÔ´´úÂëÍøÒ³ÀûÓ÷¨Ê½¼Ü¹¹¡£¡£ËüÀûÓò¢ÑÓ³¤ÁËJava Servlet API£¬£¬¼¤Àø¿ª·¢ÕßѡȡMVC¼Ü¹¹¡£¡£Apache Struts 2´æÔÚÒ»¸öÑÏÖØµÄÎļþÉÏ´«µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶S2-067£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷ÕßÄܹ»°Ñ³ÖÎļþÉÏ´«²ÎÊýÀ´ÆôÓÃõè¾¶±éÀú£¬£¬¿Éµ¼ÖÂÉÏ´«¿ÉÓÃÓÚÖ´ÐÐÔ¶³Ì´úÂëµÄ¶ñÒâÎļþ¡£¡£


2024Äê12Ô£¬£¬OG¶«·½Ìü¼à¿Øµ½Apache¹Ù·½°ä²¼·ì϶·çÏÕ¹«¸æ£¬£¬ÔÚÔ¶³Ì·þÎñÆ÷´úÂëÖÐʹÓÃÁËFileUploadInterceptor×÷ΪÎļþÉÏ´«×é¼þʱ£¬£¬Apache StrutsÔÚÎļþÉÏ´«Âß¼­ÉÏ´æÔÚ·ì϶¡£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶½øÐÐõè¾¶±éÀú£¬£¬³É¹¦ÀûÓø÷ì϶Äܹ»Ê¹¹¥»÷Õß¿ÉÄÜÉÏ´«¶ñÒâÎļþ£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£


±í1.png


·ì϶¸´ÏÖ½ØÍ¼


ͼ1.png


Ó°Ïì°æ±¾


2.0.0 <= Apache Struts <= 2.3.37 (EOL)

2.5.0 <= Apache Struts <= 2.5.33

6.0.0 <= Apache Struts <= 6.3.0.2

°ÑÎÈ£º£º²»Ê¹ÓÃFileUploadInterceptorÄ£¿ £¿éµÄÀûÓò»Êܸ÷ì϶ӰÏì¡£¡£


ÐÞ¸´½¨Òé


Ò»¡¢¹Ù·½ÐÞ¸´¹æ»®


Ŀǰ¹Ù·½ÒÑÓпɸüа汾£¬£¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶ÖÁ×îа汾£º£º

Éý¼¶µ½ Struts 6.4.0 »ò¸ü¸ß°æ±¾²¢Ç¨á㵽еÄÎļþÉÏ´«»úÖÆ¡£¡£


¹Ù·½ÏÂÔØµØÖ·£º£º

https://struts.apache.org/download.cgi


ÎļþÉÏ´«»úÖÆÇ¨áãÁ´½Ó£º£º

https://struts.apache.org/core-developers/file-upload


¶þ¡¢OG¶«·½Ìü¹æ»®


1¡¢OG¶«·½Ìü¼ì²âÀà²úÆ·¹æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEB°²È«ÀûÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬£¬Éý¼¶µ½×îа汾¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ£¬£¬ÊÂÎñ¿âÏÂÔØµØÖ·£º£º


ÊÂÎñ¿âÏÂÔØµØÖ·£º£ºhttps://venustech.download.venuscloud.cn/


2¡¢OG¶«·½Ìü©ɨ²úÆ·¹æ»®


£¨1£©¡°OG¶«·½Ìü·ì϶ɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè¡£¡£

 

ͼ2.png


£¨2£©OG¶«·½Ìü·ì϶ɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè


ͼ3.png

 

3¡¢OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®


OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬£¬¶ÔÈë¿â×ʲúApache Struts2ÎļþÉÏ´«·ì϶£¨CVE-2024-53677£©½øÐÐÖÎÀí¡£¡£


ͼ4.png

 

4¡¢OG¶«·½Ìü°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®


Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬½øÐйØÁªÕ½ÊõÅäÖ㬣¬½áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬£¬´Ó¶ø·¢ÏÖ¡°Apache Struts2ÎļþÉÏ´«·ì϶¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£¡£


1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°Apache Struts2ÎļþÉÏ´«·ì϶¡±·ì϶ɨÃ蹤×÷£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄÖØÒª×ʲú£»

 

ͼ5.png


2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿ £¿éÖУ¬£¬Ôö³¤¡°L2_Apache Struts2ÎļþÉÏ´«·ì϶¡±£¬£¬Í¨¹ýOG¶«·½Ìü¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ£º£º


ͼ6.png

 

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_Apache Struts2ÎļþÉÏ´«·ì϶"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬£¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓã»


3£©Ôö³¤¡°L3_Apache Struts2ÎļþÉÏ´«·ì϶¡±£¬£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÈÓÚ»òÔ̺¬¡°L2_Apache Struts2ÎļþÉÏ´«·ì϶¡±£¬£¬¹¥»÷Á˾ֵÈÓÚ¡°¹¥»÷³É¹¦¡±£¬£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶÈ¡£¡£


ͼ7.png