Zimbra Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-18Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£º
ZimbraCollaboration Server 8.8.11 ֮ǰµÄ°æ±¾¶¼Êܵ½Ó°Ïì¡£ÏêϸÀ´Ëµ£º
1. Zimbra < 8.7.11 °æ±¾ÖУ¬¹¥»÷Õß¿ÉÒÔÔÚÎÞÐèµÇ¼µÄÇéÐÎÏ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ
2. Zimbra < 8.8.11 °æ±¾ÖУ¬ÔÚ·þÎñ¶ËʹÓà Memcached ×ö»º´æµÄÇéÐÎÏ£¬¾ÓɵǼÈÏÖ¤ºóµÄ¹¥»÷Õß¿ÉÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ
Îó²î¸ÅÊö
Zimbra ÊÇÒ»¼ÒÌṩרҵµÄµç×ÓÓʼþÈí¼þ¿ª·¢¹©Ó¦ÉÌ£¬Ö÷ÒªÌṩ Zimbra Collaboration Server Ð×÷·þÎñÆ÷Ì×¼þ¡¢Zimbra Desktop ÓʼþÖÎÀíÈí¼þµÈÓʼþ·½ÃæµÄÈí¼þ¡£
3 Ô 13 ÈÕ£¬ ÍâÑóÇå¾²Ñо¿Ô± tint0 Ðû²¼ÁËһƪ²©¿Í£¬Ö¸³ö Zimbra Collaboration Server ϵͳȫ°æ±¾±£´æÒ»ÏµÁÐÎó²î£¬Í¨¹ý¶ñÒâʹÓÿÉÒÔµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£
Îó²îϸ½Ú
µ± Zimbra ±£´æÏñí§ÒâÎļþ¶ÁÈ¡¡¢XXE£¨XML ÍⲿʵÌå×¢È룩 ÕâÖÖÎó²îʱ£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î¶ÁÈ¡ localconfig.xml ÉèÖÃÎļþ£¬»ñÈ¡µ½ zimbra admin ldap password£¬²¢Í¨¹ý 7071 admin ¶Ë¿Ú¾ÙÐÐ SOAP AuthRequest ÈÏÖ¤£¬»ñµÃ admin authtoken£¬È»ºó¾Í¿ÉÒÔʹÓà admin authtoken ¾ÙÐÐí§ÒâÎļþÉÏ´«£¬´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄΣº¦¡£
¶ø tint0 ²©¿ÍÎÄÕÂÀïÖ¸³ö£¬×ÝÈ»ÔÚ 7071 admin ¶Ë¿Ú×öÁË·À»ðǽÉèÖá¢²î³ØÍ⿪·ÅµÄÇéÐÎÏ£¬Ò²¿ÉÒÔʹÓñ£´æÓÚ 443 ͨË×Óû§¶Ë¿Ú·þÎñÀïÉí·ÝÈÏÖ¤µÄÒ»¸öÌØÕ÷£¬ÅäºÏ ProxyServlet.doProxy() ÒªÁìÀïµÄ SSRF£¬Í¬ÑùÒ²ÄÜÍê³É admin SOAP AuthRequest ÈÏÖ¤£¬»ñµÃ admin authtoken¡£
ÏÂͼΪÅäºÏʹÓà XXE ºÍ ProxyServlet SSRF Îó²îÄõ½ admin authtoken ºó£¬Í¨¹ýÎļþÉÏ´«ÔÚ·þÎñ¶ËÖ´ÐÐí§Òâ´úÂëµÄÍâµØ²âÊÔ½ØÍ¼£º
³ý´ËÖ®Í⣬ÔÚ Zimbra·þÎñ¶ËʹÓà Memcached ×ö»º´æ·þÎñʱ£¬»¹¿ÉÒÔʹÓà SSRF ¹¥»÷ Memcached »º´æ·þÎñ£¬Í¨¹ý·´ÐòÁл¯ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£²»¹ýÓÉÓÚ Zimbra µÄ×°ÖÃÀú³ÌÖÐµÄ bug£¬µ¼Öµ¥·þÎñÆ÷µÄÇéÐÎÏ£¬Memcached Ö»¹Ü»áÆô¶¯£¬µ«²¢²»»áʹÓã¬Òò´Ë SSRF ¹¥»÷ Memcached ·´ÐòÁл¯µÄʹÓó¡¾°½ÏÁ¿ÓÐÏÞ¡£
ÐÞ¸´½¨Òé
¸üйٷ½Ðû²¼µÄÇå¾²²¹¶¡»òÉý¼¶ Zimbra µ½×îа棺https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories¡£
²Î¿¼Á´½Ó
https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories


¾©¹«Íø°²±¸11010802024551ºÅ