¡¾Îó²îͨ¸æ¡¿ownCloud graphapiÐÅϢй¶Îó²î£¨CVE-2023-49103£©

Ðû²¼Ê±¼ä 2023-11-24

 

Ò»¡¢Îó²î¸ÅÊö

CVE   ID

CVE-2023-49103

·¢Ã÷ʱ¼ä

2023-11-24

Àà    ÐÍ

ÐÅϢй¶

µÈ    ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÖØÆ¯ºó

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ֪

 

ownCloud ÊÇÒ»ÖÖÆÕ±éʹÓõÄÓÃÓÚÎļþ¹²ÏíºÍÄÚÈÝЭ×÷µÄ¿ªÔ´Èí¼þ£¬£¬£¬ £¬£¬£¬ËüÖ§³ÖÔÚÏßÎĵµ±à¼­ÒÔ¼°ÈÕÀúºÍÁªÏµÈËͬ²½µÈÀ©Õ¹£¬£¬£¬ £¬£¬£¬Óû§¿ÉÒÔͨ¹ýÍøÂçä¯ÀÀÆ÷»òÖÖÖÖ¿Í»§¶ËÓ¦ÓóÌÐò»á¼ûÊý¾ÝºÍÎĵµ¡£¡£

11ÔÂ24ÈÕ£¬£¬£¬ £¬£¬£¬ÄϹ¬NGÓéÀÖVSRC¼à²âµ½ownCloud graphapiÖÐÐÞ¸´ÁËÒ»¸öÃô¸ÐÐÅϢй¶Îó²î£¨CVE-2023-49103£©£¬£¬£¬ £¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ10.0¡£¡£ÓÉÓÚgraphapi Ó¦ÓóÌÐòÖÐÒÀÀµµÚÈý·½ GetPhpInfo.php¿â£¬£¬£¬ £¬£¬£¬µ±»á¼û¸Ã URL ʱ£¬£¬£¬ £¬£¬£¬»áÏÔʾ PHP ÇéÐΣ¨phpinfo£©µÄÉèÖÃÏêÇ飬£¬£¬ £¬£¬£¬ÕâЩÐÅÏ¢°üÀ¨ÍøÂçЧÀÍÆ÷µÄËùÓÐÇéÐαäÁ¿£¬£¬£¬ £¬£¬£¬ÔÚÈÝÆ÷»¯°²ÅÅÖУ¬£¬£¬ £¬£¬£¬ÕâЩÇéÐαäÁ¿¿ÉÄܰüÀ¨Ãô¸ÐÊý¾Ý£¬£¬£¬ £¬£¬£¬ÈçownCloud ÖÎÀíÔ±ÃÜÂë¡¢ÓʼþЧÀÍÆ÷ƾ֤ºÍÔÊÐíÖ¤ÃÜÔ¿µÈ£¬£¬£¬ £¬£¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£

±ðµÄ£¬£¬£¬ £¬£¬£¬ownCloud oauth2Öл¹ÐÞ¸´ÁË×ÓÓòÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-49104£¬£¬£¬ £¬£¬£¬CVSSv3ÆÀ·ÖΪ9.0£©£¬£¬£¬ £¬£¬£¬µ±ÆôÓÃAllow Subdomainsʱ£¬£¬£¬ £¬£¬£¬ÍþвÕß¿ÉÒÔ´«ÈëÈÆ¹ýÑéÖ¤µÄÌØÖÆÖØ¶¨Ïòurl£¬£¬£¬ £¬£¬£¬´Ó¶øÔÊÐíÍþвÕß½«»Øµ÷ÖØ¶¨Ïòµ½Æä¿ØÖƵĶ¥¼¶Óò£»£» £»£»£»£»ÒÔ¼°ÐÞ¸´ÁËWebDAV API Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-49105£¬£¬£¬ £¬£¬£¬CVSSv3ÆÀ·ÖΪ9.8£©£¬£¬£¬ £¬£¬£¬¿ÉʹÓÃÔ¤ÊðÃûURLÈÆ¹ýWebDAV Api Éí·ÝÑéÖ¤£¬£¬£¬ £¬£¬£¬ÈôÊÇÒÑÖªÊܺ¦ÕßµÄÓû§Ãû²¢ÇÒÊܺ¦ÕßûÓÐÉèÖÃÊðÃûÃÜÔ¿£¨ÕâÊÇĬÈÏÉèÖã©£¬£¬£¬ £¬£¬£¬ÔòÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼û¡¢Ð޸Ļòɾ³ýÈκÎÎļþ¡£¡£

 

¶þ¡¢Ó°Ïì¹æÄ£

CVE-2023-49103

ownCloud/graphapi 0.2.x < 0.2.1

ownCloud/graphapi 0.3.x < 0.3.1

CVE-2023-49104

ownCloud/oauth2 < 0.6.1

CVE-2023-49105

10.6.0 <=ownCloud/core< 10.13.1

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ¹Ù·½ÒÑÐû²¼ÁËÇå¾²¸üУ¬£¬£¬ £¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½×îа汾¡£¡£

ownCloud/graphapiÏÂÔØÁ´½Ó£º

https://marketplace.owncloud.com/apps/graphapi

3.2 ÔÝʱ²½·¥

CVE-2023-49103£º

1.½ö½ûÓà graphapi Ó¦ÓóÌÐò²¢²»¿ÉÏû³ý¸ÃÎó²î£¬£¬£¬ £¬£¬£¬¿Éɾ³ýÎļþ owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php¡£¡£

2. ¿É½ûÓà docker-containers ÖÐµÄ phpinfo ¹¦Ð§¡£¡£

3. ½¨Òé¸ü¸ÄÒªº¦Æ¾Ö¤£¬£¬£¬ £¬£¬£¬°üÀ¨ownCloud ÖÎÀíÔ±ÃÜÂë¡¢ÓʼþЧÀÍÆ÷ƾ֤¡¢Êý¾Ý¿âƾ֤¡¢¹¤¾ß´æ´¢/S3 »á¼ûÃÜÔ¿µÈ¡£¡£

CVE-2023-49104£º

1.ÔöÇ¿oauth2Ó¦ÓóÌÐòÖеÄÑéÖ¤´úÂë¡£¡£

2. ½ûÓá°Allow Subdomains¡±Ñ¡ÏîÀ´»º½â¸ÃÎó²î¡£¡£

CVE-2023-49105£º

ÈôÊÇûÓÐΪÎļþËùÓÐÕßÉèÖÃÊðÃûÃÜÔ¿£¬£¬£¬ £¬£¬£¬Ôò¾Ü¾øÊ¹ÓÃÔ¤ÊðÃûURL¡£¡£

 

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¬£¬£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£

3.4 ²Î¿¼Á´½Ó

https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/

https://owncloud.com/security-advisories/subdomain-validation-bypass/

https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-11-24

Ê×´ÎÐû²¼

 


Îå¡¢¸½Â¼

5.1 ÄϹ¬NGÓéÀÖ¼ò½é

ÄϹ¬NGÓéÀÖ½¨ÉèÓÚ1996Ä꣬£¬£¬ £¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÄϹ¬NGÓéÀÖ´óÏ㬣¬£¬ £¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬ £¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬ £¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬ £¬£¬£¬ÄϹ¬NGÓéÀÖÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬ £¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬ £¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£

5.2 ¹ØÓÚÄϹ¬NGÓéÀÖ

ÄϹ¬NGÓéÀÖÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬ £¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬ £¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png