CVE-2020-11998 | Apache ActiveMQÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ðû²¼Ê±¼ä 2020-09-14

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2020-11998

ʱ    ¼ä

2020-09-14

Àà    ÐÍ

Ô¶³Ì´úÂëÖ´ÐÐ

µÈ    ¼¶

ÖÐΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

½öApache ActiveMQ 5.15.12°æ±¾¡£¡£¡£¡£¡£¡£¡£

    

    2020Äê09ÔÂ10ÈÕ£¬£¬£¬ApacheÈí¼þ»ù½ð»áÐû²¼ActiveMQÐÂÎÅÖÐÐļþÖб£´æÒ»¸öÇå¾²Îó²î£¬£¬£¬Îó²î¸ú×ÙΪCVE-2020-11998¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


0x01 Îó²îÏêÇé

image.png


    Apache ActiveMQÊÇApacheÈí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬£¬£¬ËüÊÇÒ»¸ö»ùÓÚÐÂÎŵÄͨѶÖÐÐļþ£¬£¬£¬²¢Ö§³ÖJavaÐÂÎÅЧÀÍ¡¢¼¯Èº¡¢Spring FrameworkµÈ¡£¡£¡£¡£¡£¡£¡£

    ActiveMQÊÇJMSµÄÒ»¸öÏêϸʵÏÖ£¬£¬£¬Ö§³ÖJMSµÄÁ½ÖÖÐÂÎÅÄ£×Ó¡£¡£¡£¡£¡£¡£¡£Ëü×ñÕÕJMS1.1¹æ·¶£¨Java Message Service£©£¬£¬£¬ÊÇÐÂÎÅÇý¶¯ÖÐÐļþÈí¼þ£¨MOM£©¡£¡£¡£¡£¡£¡£¡£ËüΪÆóÒµÐÂÎÅת´ïÌṩ¸ß¿ÉÓᢾ«²ÊÐÔÄÜ¡¢¿ÉÀ©Õ¹¡¢Îȹ̺ÍÇå¾²°ü¹Ü¡£¡£¡£¡£¡£¡£¡£

    ActiveMQʹÓÃApacheÔÊÐíЭÒé¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬ÈκÎÈ˶¼¿ÉÒÔʹÓúÍÐÞ¸ÄËü¶ø²»±Ø·´ÏìÈκθıä¡£¡£¡£¡£¡£¡£¡£Õâ¹ØÓÚÉÌÒµÉϽ«ActiveMQÓÃÔÚÖ÷ÒªÓÃ;µÄÈËÓÈΪҪº¦¡£¡£¡£¡£¡£¡£¡£ActiveMQµÄÄ¿µÄÊÇÔÚ¾¡¿ÉÄܶàµÄƽ̨ºÍÓïÑÔÉÏÌṩһ¸ö±ê×¼µÄ£¬£¬£¬ÐÂÎÅÇý¶¯µÄÓ¦Óü¯³É¡£¡£¡£¡£¡£¡£¡£

    CVE-2020-11998Îó²îÐγɵÄÔ­ÓÉÓÚ£º

    1. ÔÚÌá½»±ÜÃâJMX(Java Management Extensions£¬£¬£¬¼´JavaÖÎÀíÀ©Õ¹,ÊÇÒ»¸öΪӦÓóÌÐò¡¢×°±¸¡¢ÏµÍ³µÈÖ²ÈëÖÎÀí¹¦Ð§µÄ¿ò¼Ü)ÖØÐ°ó¶¨ÖÐÒýÈëÁËregression¡£¡£¡£¡£¡£¡£¡£

    2. ½«Ò»¸ö¿ÕµÄÇéÐÎÓ³Éä¶ø²»ÊǰüÀ¨Éí·ÝÑé֤ƾ֤µÄÓ³Éäת´ïµ½RMIConnectorServer»áʹµÃActiveMQÈÝÒ×Êܵ½ÒÔϹ¥»÷£º

    https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html¡£¡£¡£¡£¡£¡£¡£

    3. ÔÚûÓÐÇå¾²ÖÎÀíÆ÷µÄÇéÐÎÏ£¬£¬£¬Ô¶³Ì¿Í»§¶Ë¿ÉÒÔ½¨ÉèÒ»¸öjavax.management.loading.MLet MBean£¬£¬£¬²¢Ê¹ÓÃËü´Óí§ÒâURL½¨ÉèеÄMBean£¬£¬£¬Õâ¿ÉÄܻᵼÖ¶ñÒâµÄÔ¶³Ì¿Í»§¶ËʹÓÃJavaÓ¦ÓóÌÐòÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

0x02 ´¦Öóͷ£½¨Òé

    ÏÖÔÚApache¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬£¬½¨ÒéÉý¼¶µ½Apache ActiveMQ 5.15.13°æ±¾¡£¡£¡£¡£¡£¡£¡£

    ÏÂÔØÁ´½Ó£º

    http://activemq.apache.org/activemq-51513-release

0x03 Ïà¹ØÐÂÎÅ

    https://www.secfree.com/vul-150408.html

 

0x04 ²Î¿¼Á´½Ó

    http://activemq.apache.org/security-advisories.data/CVE-2020-11998-announcement.txt

    https://nvd.nist.gov/vuln/detail/CVE-2020-11998

    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11998

0x05 ʱ¼äÏß

    2020-09-10 ApacheÐû²¼Ç徲ͨ¸æ

    2020-09-14 VSRCÐû²¼Ç徲ͨ¸æ



image.png