目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2021-39180— OpenOLAT 路径遍历漏洞

一分钟漏洞结论

影响对象
OpenOLAT OpenOLAT
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

OpenOLAT是一个基于网络的电子学习平台,用于教学、学习、评估和交流,一个 LMS,一个学习管理系统。 OpenOLAT 存在路径遍历漏洞,该漏洞源于软件对于上传zip文件没有进行有效的过滤和验证。攻击者使用特别准备的ZIP文件,可以覆盖应用服务器用户(例如tomcat用户)可写入的任何文件。根据配置的不同,这种攻击可能仅限于OpenOlat用户数据目录的文件,但是,如果没有正确设置,这种攻击还可能用于覆盖应用服务器配置文件、java代码甚至操作系统文件。这种攻击可以用来破坏或修改任何OpenOlat

CVSS 8.1 · High EPSS 2.44% · P83
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2021-39180 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Path Traversal in Archive Handling Leading to Code Execution
来源: CVE Program / CVE List V5
Vulnerability Description
OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application server user (e.g. the tomcat user). Depending on the configuration this can be limited to files of the OpenOlat user data directory, however, if not properly set up, the attack could also be used to overwrite application server config files, java code or even operating system files. The attack could be used to corrupt or modify any OpenOlat file such as course structures, config files or temporary test data. Those attack would require in-depth knowledge of the installation and thus more theoretical. If the app server configuration allows the execution of jsp files and the path to the context is known, it is also possible to execute java code. If the app server runs with the same user that is used to deploy the OpenOlat code or has write permissions on the OpenOlat code files and the path to the context is know, code injection is possible. The attack requires an OpenOlat user account to upload a ZIP file and trigger the unzip method. It can not be exploited by unregistered users. The problem is fixed in versions 15.3.18, 15.5.3 and 16.0.0. There are no known workarounds aside from upgrading.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
来源: CVE Program / CVE List V5
Vulnerability Title
OpenOLAT 路径遍历漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
OpenOLAT是一个基于网络的电子学习平台,用于教学、学习、评估和交流,一个 LMS,一个学习管理系统。 OpenOLAT 存在路径遍历漏洞,该漏洞源于软件对于上传zip文件没有进行有效的过滤和验证。攻击者使用特别准备的ZIP文件,可以覆盖应用服务器用户(例如tomcat用户)可写入的任何文件。根据配置的不同,这种攻击可能仅限于OpenOlat用户数据目录的文件,但是,如果没有正确设置,这种攻击还可能用于覆盖应用服务器配置文件、java代码甚至操作系统文件。这种攻击可以用来破坏或修改任何OpenOlat
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
OpenOLAT OpenOLAT < 15.3.18 -

二、漏洞 CVE-2021-39180 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-39180 的情报信息

登录查看更多情报信息。

CVE-2021-39180 补丁与修复 (3)

CVE-2021-39180 厂商安全公告 (1)

CVE-2021-39180 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2021-39180

暂无评论


发表评论