¡¾·ì϶¹«¸æ¡¿Apache Struts XWork ×é¼þ XXE ·ì϶(CVE-2025-68493)
°ä²¼¹¦·ò 2026-01-12Ò»¡¢¡¢¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Apache Struts XWork ×é¼þ XXE ·ì϶ | ||
CVE ID | CVE-2025-68493 | ||
·ì϶ÀàÐÍ | XXE | ·¢ÏÖ¹¦·ò | 2026-1-12 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache StrutsÊÇÒ»¸ö»ùÓÚJavaµÄ¿ªÔ´WebÀûÓÿª·¢¿ò¼Ü£¬£¬£¬Ñ¡È¡MVC£¨Ä£ÐÍ-ÊÓͼ-½ÚÖÆÆ÷£©¼Ü¹¹Ä£Ê½£¬£¬£¬ÖØÒªÓÃÓÚ¹¹½¨ÆóÒµ¼¶WebÀûÓᣡ£Strutsͨ¹ýÇ峺·Ö²ã£¬£¬£¬½«ÒµÎñÂß¼¡¢¡¢¡¢Ò³ÃæÕ¹Ê¾ºÍÒªÇó½ÚÖÆ½âñ£¬£¬ÌáÉýÀûÓõĿÉÊØ»¤ÐÔÓë¿ÉÀ©´óÐÔ¡£¡£ÆäÖ÷Ìâ×é¼þÔ̺¬Struts Core¡¢¡¢¡¢XWorkºÍOGNL£¬£¬£¬Ö§³Ö±íµ¥´¦Öᢡ¢¡¢²ÎÊý°ó¶¨¡¢¡¢¡¢À¹½ØÆ÷»úÖÆ¼°½Ã½ÝµÄÅäÖ÷½Ê½¡£¡£Apache StrutsÔøÔÚJava WebÁìÓò±»¿í·ºÀûÓ㬣¬£¬µ«Òòº¹ÇàÉÏÂŴγöÏÖ¸ßΣ°²È«·ì϶£¬£¬£¬µ±Ç°Ê¹ÓÃÖÐÐè³ö¸ñÆ÷ÖØ°æ±¾¸üÐÂÓ밲ȫ¼Ó¹Ì¡£¡£
2026Äê1ÔÂ12ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Apache Struts¿ò¼ÜÖÐXWork×é¼þ´æÔÚµÄÒ»´¦XMLÍⲿʵÌå×¢È루XXE£©·ì϶¡£¡£¸Ã·ì϶ԴÓÚXWorkÔÚ½âÎöXMLÅäÖÃÎļþʱ£¬£¬£¬Î´¶ÔXMLÍⲿʵÌå½øÐгä·ÖУÑéÓëÏÞ¶È£¬£¬£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâXMLÄÚÈÝ´¥·¢ÍⲿʵÌå½âÎö¡£¡£³É¹¦ÀûÓú󣬣¬£¬¿ÉÄÜÔì³ÉÃô¸ÐÊý¾Ýй¶¡¢¡¢¡¢»Ø¾ø·þÎñ£¨DoS£©ÒÔ¼°·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©µÈ°²È«Ó°Ïì¡£¡£·ì϶ÆÀ·Ö9.8·Ö£¬£¬£¬·ì϶¼¶±ðÑÏÖØ¡£¡£
¶þ¡¢¡¢¡¢Ó°ÏìÁìÓò
Èý¡¢¡¢¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://struts.apache.org/download.cgi/


¾©¹«Íø°²±¸11010802024551ºÅ