¡¾Îó²îͨ¸æ¡¿Apache Struts XWork ×é¼þ XXE Îó²î(CVE-2025-68493)

Ðû²¼Ê±¼ä 2026-01-12

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Apache Struts XWork ×é¼þ XXE Îó²î

CVE   ID

CVE-2025-68493

Îó²îÀàÐÍ

XXE

·¢Ã÷ʱ¼ä

2026-1-12

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Apache StrutsÊÇÒ»¸ö»ùÓÚJavaµÄ¿ªÔ´WebÓ¦Óÿª·¢¿ò¼Ü£¬£¬£¬½ÓÄÉMVC£¨Ä£×Ó-ÊÓͼ-¿ØÖÆÆ÷£©¼Ü¹¹Ä£Ê½£¬£¬£¬Ö÷ÒªÓÃÓÚ¹¹½¨ÆóÒµ¼¶WebÓ¦Óᣡ£¡£¡£¡£Strutsͨ¹ýÇåÎú·Ö²ã£¬£¬£¬½«ÓªÒµÂß¼­¡¢Ò³ÃæÕ¹Ê¾ºÍÇëÇó¿ØÖƽâñ£¬£¬ÌáÉýÓ¦ÓõĿÉά»¤ÐÔÓë¿ÉÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£Æä½¹µã×é¼þ°üÀ¨Struts Core¡¢XWorkºÍOGNL£¬£¬£¬Ö§³Ö±íµ¥´¦Öóͷ£¡¢²ÎÊý°ó¶¨¡¢×èµ²Æ÷»úÖÆ¼°ÎÞаµÄÉèÖ÷½·¨¡£¡£¡£¡£¡£Apache StrutsÔøÔÚJava WebÁìÓò±»ÆÕ±éÓ¦Ó㬣¬£¬µ«ÒòÀúÊ·É϶à´Î·ºÆð¸ßΣÇå¾²Îó²î£¬£¬£¬Ä¿½ñʹÓÃÖÐÐèÌØÊâÖØÊÓ°æ±¾¸üÐÂÓëÇå¾²¼Ó¹Ì¡£¡£¡£¡£¡£


2026Äê1ÔÂ12ÈÕ£¬£¬£¬ÈËÉú¾ÍÊDz©¼¯ÍÅVSRC¼à²âµ½Apache Struts¿ò¼ÜÖÐXWork×é¼þ±£´æµÄÒ»´¦XMLÍⲿʵÌå×¢È루XXE£©Îó²î¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚXWorkÔÚÆÊÎöXMLÉèÖÃÎļþʱ£¬£¬£¬Î´¶ÔXMLÍⲿʵÌå¾ÙÐгä·ÖУÑéÓëÏÞÖÆ£¬£¬£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâXMLÄÚÈÝ´¥·¢ÍⲿʵÌåÆÊÎö¡£¡£¡£¡£¡£ÀÖ³ÉʹÓú󣬣¬£¬¿ÉÄÜÔì³ÉÃô¸ÐÊý¾Ýй¶¡¢¾Ü¾øÐ§ÀÍ£¨DoS£©ÒÔ¼°Ð§ÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©µÈÇå¾²Ó°Ïì¡£¡£¡£¡£¡£Îó²îÆÀ·Ö9.8·Ö£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


2.0.0 <= Apache Struts <= 2.3.37£¨2.3.x ·ÖÖ§ÒÑ×èֹά»¤£©
2.5.0 <= Apache Struts <= 2.5.33£¨2.5.x ·ÖÖ§ÒÑ×èֹά»¤£©
6.0.0 <= Apache Struts <= 6.1.0


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£
Apache Struts >= 6.1.1


ÏÂÔØÁ´½Ó£ºhttps://struts.apache.org/download.cgi/


3.2 ÔÝʱ²½·¥


×Ô½ç˵SAXParserFactory£ºÍ¨¹ýÉèÖÃxwork.saxParserFactory=Ö¸Ïò×Ô½ç˵¹¤³§À࣬£¬£¬Ä¬ÈϽûÓÃÍⲿʵÌåÆÊÎö¡£¡£¡£¡£¡£
JVM²ãÃæ½ûÓÃÍⲿʵÌ壺Æô¶¯²ÎÊý¼ÓÈ루ÖÿտÉ×è¶ÏËùÓÐЭÒ飩£º
-Djavax.xml.accessExternalDTD=
-Djavax.xml.accessExternalSchema=
-Djavax.xml.accessExternalStylesheet=¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://cwiki.apache.org/confluence/display/WW/S2-069/