¡¾·ì϶¹«¸æ¡¿Apache Struts XWork ×é¼þ XXE ·ì϶(CVE-2025-68493)

°ä²¼¹¦·ò 2026-01-12

Ò»¡¢¡¢ ¡¢·ì϶¸ÅÊö


·ì϶Ãû³Æ

Apache Struts XWork ×é¼þ XXE ·ì϶

CVE   ID

CVE-2025-68493

·ì϶ÀàÐÍ

XXE

·¢ÏÖ¹¦·ò

2026-1-12

·ì϶ÆÀ·Ö

9.8

·ì϶µÈ¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Apache StrutsÊÇÒ»¸ö»ùÓÚJavaµÄ¿ªÔ´WebÀûÓÿª·¢¿ò¼Ü£¬£¬£¬Ñ¡È¡MVC£¨Ä£ÐÍ-ÊÓͼ-½ÚÖÆÆ÷£©¼Ü¹¹Ä£Ê½£¬£¬£¬ÖØÒªÓÃÓÚ¹¹½¨ÆóÒµ¼¶WebÀûÓᣡ£Strutsͨ¹ýÇ峺·Ö²ã£¬£¬£¬½«ÒµÎñÂß¼­¡¢¡¢ ¡¢Ò³ÃæÕ¹Ê¾ºÍÒªÇó½ÚÖÆ½âñ£¬£¬ÌáÉýÀûÓõĿÉÊØ»¤ÐÔÓë¿ÉÀ©´óÐÔ¡£¡£ÆäÖ÷Ìâ×é¼þÔ̺¬Struts Core¡¢¡¢ ¡¢XWorkºÍOGNL£¬£¬£¬Ö§³Ö±íµ¥´¦Öᢡ¢ ¡¢²ÎÊý°ó¶¨¡¢¡¢ ¡¢À¹½ØÆ÷»úÖÆ¼°½Ã½ÝµÄÅäÖ÷½Ê½¡£¡£Apache StrutsÔøÔÚJava WebÁìÓò±»¿í·ºÀûÓ㬣¬£¬µ«Òòº¹ÇàÉÏÂŴγöÏÖ¸ßΣ°²È«·ì϶£¬£¬£¬µ±Ç°Ê¹ÓÃÖÐÐè³ö¸ñÆ÷ÖØ°æ±¾¸üÐÂÓ밲ȫ¼Ó¹Ì¡£¡£


2026Äê1ÔÂ12ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Apache Struts¿ò¼ÜÖÐXWork×é¼þ´æÔÚµÄÒ»´¦XMLÍⲿʵÌå×¢È루XXE£©·ì϶¡£¡£¸Ã·ì϶ԴÓÚXWorkÔÚ½âÎöXMLÅäÖÃÎļþʱ£¬£¬£¬Î´¶ÔXMLÍⲿʵÌå½øÐгä·ÖУÑéÓëÏÞ¶È£¬£¬£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâXMLÄÚÈÝ´¥·¢ÍⲿʵÌå½âÎö¡£¡£³É¹¦ÀûÓú󣬣¬£¬¿ÉÄÜÔì³ÉÃô¸ÐÊý¾Ýй¶¡¢¡¢ ¡¢»Ø¾ø·þÎñ£¨DoS£©ÒÔ¼°·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©µÈ°²È«Ó°Ïì¡£¡£·ì϶ÆÀ·Ö9.8·Ö£¬£¬£¬·ì϶¼¶±ðÑÏÖØ¡£¡£


¶þ¡¢¡¢ ¡¢Ó°ÏìÁìÓò


2.0.0 <= Apache Struts <= 2.3.37£¨2.3.x ·ÖÖ§ÒÑÖÕ³¡ÊØ»¤£©
2.5.0 <= Apache Struts <= 2.5.33£¨2.5.x ·ÖÖ§ÒÑÖÕ³¡ÊØ»¤£©
6.0.0 <= Apache Struts <= 6.1.0


Èý¡¢¡¢ ¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼ÐÞ¸´²¹¶¡£¬£¬£¬ÒÔÐÞ¸´¸Ã·ì϶¡£¡£
Apache Struts >= 6.1.1


ÏÂÔØÁ´½Ó£ºhttps://struts.apache.org/download.cgi/


3.2 һʱ´ëÊ©


×Ô½ç˵SAXParserFactory£ºÍ¨¹ýÉèÖÃxwork.saxParserFactory=Ö¸Ïò×Ô½ç˵¹¤³§À࣬£¬£¬Ä¬ÈϽûÓÃÍⲿʵÌå½âÎö¡£¡£
JVM²ãÃæ½ûÓÃÍⲿʵÌ壺Æô¶¯²ÎÊý²ÎÓ루ÖÿտÉ×è¶ÏËùÓкÍ̸£©£º
-Djavax.xml.accessExternalDTD=
-Djavax.xml.accessExternalSchema=
-Djavax.xml.accessExternalStylesheet=¡£¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÖÆ£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬¹Ø±Õ·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢¡¢ ¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÖÆºÍ×îСȨÏÞ×¼Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£


3.4 ²Î¿¼Á´½Ó


https://cwiki.apache.org/confluence/display/WW/S2-069/