¡¾·ì϶¹«¸æ¡¿Apache Tika XMLÍⲿʵÌå×¢Èë·ì϶(CVE-2025-66516)
°ä²¼¹¦·ò 2025-12-09Ò»¡¢¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Apache Tika XMLÍⲿʵÌå×¢Èë·ì϶ | ||
CVE ID | CVE-2025-66516 | ||
·ì϶ÀàÐÍ | XXE | ·¢ÏÖ¹¦·ò | 2025-12-9 |
·ì϶ÆÀ·Ö | 10 | ·ì϶µÈ¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache TikaÊÇÒ»¸ö¿ªÔ´µÄÄÚÈÝ·ÖÎö¹¤¾ß£¬£¬£¬ÓÃÓÚ´Ó¸÷ÀàÎĵµÌåʽÖÐÌáÈ¡Îı¾ºÍÔªÊý¾Ý¡£ËüÖ§³Ö¶àÖÖÎļþÀàÐÍ£¬£¬£¬Ô̺¬PDF¡¢¡¢Microsoft OfficeÎĵµ¡¢¡¢HTML¡¢¡¢XMLµÈ¡£TikaµÄÖ÷ÌâÄ£¿£¿£¿éÌṩͳһµÄAPI£¬£¬£¬Äܹ»ÇáËɼ¯³Éµ½ÆäËûÀûÓÃÖУ¬£¬£¬Ô®ÊÖ¿ª·¢ÈËÔ±×Ô¶¯»¯ÄÚÈÝÌáÈ¡¹ý³Ì¡£Í¨¹ýʹÓÃTika£¬£¬£¬Óû§Äܹ»¶Ô´ó¹æÄ£Îĵµ½øÐзÖÎöºÍË÷Òý£¬£¬£¬¿í·ºÀûÓÃÓÚÊý¾ÝÍÚ¾ò¡¢¡¢ËÑË÷ÒýÇæºÍÄÚÈÝÖÎÀíϵͳµÈÁìÓò¡£
2025Äê12ÔÂ9ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Ò»¸öÑÏÖØµÄXMLÍⲿʵÌå×¢È루XXE£©·ì϶£¬£¬£¬Ó°ÏìApache TikaÖ÷ÌâÄ£¿£¿£¿é¡¢¡¢Tika½âÎöÆ÷Ä£¿£¿£¿éºÍTika PDF½âÎöÄ£¿£¿£¿é¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚPDFÎļþÖÐǶÈ뾫ÐÄ»ú¹ØµÄXFAÎļþ£¬£¬£¬ÀûÓø÷ì϶ִÐжñÒâµÄÍⲿʵÌåŲÓ㬣¬£¬´Ó¶øÔì³ÉÐÅϢй¶»òÔ¶³Ì´úÂëÖ´ÐеÈÑÏÖØ°²È«·çÏÕ¡£¸Ã·ì϶µÄÑÏÖØÐÔÔÚÓÚ£¬£¬£¬Ëü¿ÉÄÜͨ¹ý¶ñÒâµÄXMLÎļþ´¥·¢ÍⲿʵÌå×¢È룬£¬£¬¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶»òϵͳ±»Ô¶³Ì½ÚÖÆ£¬£¬£¬¸øÓû§ºÍϵͳ´øÀ´ÖØ´óµÄ°²È«Íþв¡£¡£
¶þ¡¢¡¢Ó°ÏìÁìÓò
Èý¡¢¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://tika.apache.org/download.html/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ