¿ËÈÕ£¬Confluence¹Ù·½Ðû²¼ÁËSSRFÎó²î£¨CVE-2019-3395£©¼°Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-3396£©µÄÇ徲ͨ¸æ£¬¹¥»÷ÕßʹÓÃÎó²î¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐС¢·þÎñÆ÷¶ËÇëÇóαÔì¡£´Ë´Îͨ¸æµÄÎó²î»®·Ö±£´æÓÚWebDAV¡¢¼°WidgetÅþÁ¬Æ÷ÖС£
Îó²î¸ÅÊö
¿ËÈÕ£¬Confluence¹Ù·½Ðû²¼ÁËSSRFÎó²î£¨CVE-2019-3395£©¼°Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-3396£©µÄÇ徲ͨ¸æ£¬¹¥»÷ÕßʹÓÃÎó²î¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐС¢·þÎñÆ÷¶ËÇëÇóαÔì¡£´Ë´Îͨ¸æµÄÎó²î»®·Ö±£´æÓÚWebDAV¡¢¼°WidgetÅþÁ¬Æ÷ÖС£
CVE-2019-3395 WebDAV
2018Äê6ÔÂ18ÈÕǰÐû²¼µÄConfluence Server¼°Data Center¾ùÊÜ´ËÎó²îÓ°Ïì¡£´ËÎó²î±£´æÓÚWebDAV²å¼þÖУ¬¹¥»÷Õß¿ÉÔ¶³ÌʹÓôËÎó²îʹConfluence·þÎñÆ÷»òData Center·¢ËÍí§ÒâHTTP»òWebDAVÇëÇó£¬ÊµÏÖ·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©¡£
¹Ù·½ÒÑÕë¶Ô´ËÎó²îÐû²¼6.8.5¡¢6.9.3ÐÞ¸´°æ±¾¡£
CVE-2019-3396 Widget Connector
¸ÃÎó²îΪserver-side template injection·þÎñÆ÷¶ËÄ£°å×¢ÈëÎó²î£¬±£´æÓÚConfluence Server¼°Data CenterµÄWidget Connector²å¼þÖС£¹¥»÷ÕßÀÖ³ÉʹÓôËÎó²î¿ÉʵÏÖĿ¼´©Ô½¼°Ô¶³Ì´úÂëÖ´ÐС£
¹Ù·½ÒÑÕë¶Ô´ËÎó²îÐû²¼6.12.3¡¢6.13.3¡¢6.14.2ÐÞ¸´°æ±¾¡£
ÏÖÔÚPoCÒѾ¹ûÕæ£¬Îó²îʹÓÃÀֳɵĽØÍ¼ÈçÏ£º

²Î¿¼Á´½Ó£º
https://confluence.atlassian.com/doc/confluence-security-advisory-2019-03-20-966660264.html
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
-
Confluence 1.*.*¡¢*.*¡¢3.*.*¡¢4.*.*¡¢5.*.*
-
Confluence 6.0.*¡¢1.*¡¢6.2.*¡¢6.3.*¡¢6.4.*¡¢6.5.*
-
Confluence 6.6.* < 6.6.12
-
Confluence 6.7.*¡¢8.*¡¢6.9.*¡¢6.10.*¡¢6.11.*
-
Confluence 6.12.* < 6.12.3
-
Confluence 6.13.* < 6.13.3
-
Confluence 6.14.* < 6.14.2
²»ÊÜÓ°Ïì°æ±¾
-
Confluence >= 6.6.12
-
Confluence >= 6.12.3
-
Confluence >= 6.13.3
-
Confluence >= 6.14.2
-
Confluence 15.1
Confluence¹Ù·½Ö¸³öConfluence Cloud²»ÊÜ´Ë´Îͨ¸æÎó²îÓ°Ïì¡£
Ó°ÏìÅŲé
Óû§¿Éͨ¹ýÉó²éÄ¿½ñConfluence°æ±¾ÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬¶ÔÄ¿½ñ·þÎñÊÇ·ñÊÜ´ËÎó²îÓ°Ïì¾ÙÐÐÅŲ顣µã»÷

£¬Ñ¡Ôñ¡°¹ØÓÚConfluence¡±£¬¼´¿É¶ÔÄ¿½ñ°æ±¾¾ÙÐÐÉó²é¡£
ÐÞ¸´½¨Òé
¹Ù·½Éý¼¶
¹Ù·½½¨ÒéÓû§Éý¼¶ÖÁ×îа汾6.15.1£¬ÒÔ°ü¹Ü·þÎñµÄÇå¾²ÐÔ¼°ÎȹÌÐÔ¡£ÏÂÔØÁ´½ÓÈçÏ£º
https://www.atlassian.com/software/confluence/download/
https://atlassian.com/software/confluence/download/data-center
ÈôÎÞ·¨Éý¼¶ÖÁ×îа汾£¬¿É²Î¿¼ÏÂ±í£¬Éý¼¶ÖÁ¶ÔÓ¦ÐÞ¸´°æ±¾£º
|
Ä¿½ñ°æ±¾
|
ÐÞ¸´°æ±¾
|
|
6.12.0 6.12.1 6.12.2
|
6.12.3
|
|
6.14.0 6.14.1
|
6.14.2
|
|
6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.6.6 6.6.7 6.6.8 6.6.9 6.6.10 6.6.11
|
6.6.12
|
|
6.13.0 6.13.1 6.13.2
|
6.13.3
|
|
ÆäËûÔçÆÚ°æ±¾
|
¿ÉÉý¼¶ÖÁ6.14.2¡¢6.13.3¡¢6.6.12ÈÎÒ»°æ±¾¡£
|
-
Éý¼¶widgetconnector²å¼þÖÁÐÞ¸´°æ±¾
Óû§¿Éͨ¹ýÌæ»»widgetconnector-*.jarÎļþÖÁÐÞ¸´°æwidgetconnector-3.1.4£¬ÒÔʵÏÖ¶ÔÎó²îCVE-2019-3396µÄÐÞ¸´¡£Ïêϸ²Ù×÷°ì·¨ÈçÏ£º
-
ÕÒµ½²å¼þwidgetconnector-*.jarÎļþËùÔÚλÖã¬linuxϵͳÏ¿Éͨ¹ýÏÂÁÐÏÂÁî²éÕÒ£º
|
find / -name "widgetconnector-*"
|
-
½«Ä¿½ñwidgetconnector-*.jarÎļþÌæ»»ÎªÇå¾²°æ±¾£¬ÏÂÔØÁ´½ÓÈçÏ£º
https://packages.atlassian.com/maven-public/com/atlassian/confluence/extra/widgetconnector/widgetconnector/3.1.4/widgetconnector-3.1.4.jar
ÈôÔÝʱ²»Àû±ãÉý¼¶ÖÁÐÞ¸´°æ±¾£¬Ò²¿Éµã»÷¡°ÉèÖá± ->Manage apps/add-onsÑ¡ÔñSystem£¬½«ÏÂÁÐConfluence²å¼þ½ûÓá£
-
WebDAV plugin
-
Widget Connector

×¢£º
-
Èô½ûÓÃWidget Connector²å¼þ£¬ Widget Connector Ö¸Á²»¿ÉÓ㬸ÃÖ¸ÁîÊÇÓÃÓÚչʾYouTube¡¢Vimeo¼°ÍÆÌØÍøÕ¾ÄÚÈݵ쬽ûÓøÃÖ¸Áîºó£¬Óû§¿ÉÄÜ»áÓöµ½¡®unknown macro¡¯¹ýʧ¡£
-
Èô½ûÓÃWebDAV²å¼þ£¬½«ÎÞ·¨Ê¹ÓÃWebDAV¿Í»§¶ËÅþÁ¬ÖÁConfluence¡£½ûÓô˲å¼þÒ²½«×Ô¶¯½ûÓÃOffice Connector²å¼þ¡£
ÔÚÍê³ÉÉý¼¶ºó£¬ÐèÊÖ¶¯ÆôÓÃÏÂÁвå¼þ£º
-
WebDAV plugin
-
Widget Connector
-
Office Connector.
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊÐÉúÒ⣬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£