Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2023-45612-PoC — 演示JetBrains Ktor < 2.3.5中通过XML ContentNegotiation存在的XXE漏洞的概念验证,包含预防指南和基于OWASP的分析。 | Kitploit
工具/GitHubGitHub/infernosalex/cve-2023-45612-poc
漏洞分析漏洞利用Web应用程序漏洞利用Web安全CTF学习与教育
GitHubinfernosalex/cve-2023-45612-poc

CVE-2023-45612-PoC

演示JetBrains Ktor < 2.3.5中通过XML ContentNegotiation存在的XXE漏洞的概念验证,包含预防指南和基于OWASP的分析。

查看仓库
1811个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2023-45612

  • https://nvd.nist.gov/vuln/detail/CVE-2023-45612

CVE描述

在JetBrains Ktor 2.3.5之前,ContentNegotiation的默认配置与XML格式存在XXE漏洞。

该漏洞由@marychatte于2023年9月29日修复(https://github.com/ktorio/ktor/pull/3770),漏洞是由于外部库`xmlutil version 0.86.1`中的配置错误导致的供应链攻击。 vulnerability_xmlutil_diff

根据OWASP指南(https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html),修复措施不够全面,我在这里找到了一个有趣的答案(https://security.stackexchange.com/questions/260956/java-xxe-vulnerability):`The main objective is to disable DTDs, it basically consists of the primary defense against this attack.`

OWASP_Cheatsheet_XXE

什么是OWASP?

  • OWASP(Open Worldwide Application Security Project)是一个全球性的非营利社区,专注于提升软件安全。它提供免费、厂商中立的资源,如文档、工具和培训,帮助开发者、安全研究人员和组织构建安全的应用程序。其最著名的项目之一是OWASP Top 10,列出了最关键的网络应用安全风险。

概念验证

Proof_of_Concept-script

预防指南

  • 升级:Ktor ≥ 2.3.5 并更新 xmlutil 至已修复版本
  • 强化XML解析:
    • 禁用DOCTYPE声明
    • 禁用外部通用/参数实体
    • 禁用外部DTD加载
    • 启用 FEATURE_SECURE_PROCESSING
    • 禁用XInclude
  • 除非必须,优先使用JSON而非XML
  • 最小权限原则:运行服务时不赋予文件系统/网络访问权限用于解析
  • 输入验证:在应用层拒绝包含DOCTYPE声明的载荷

参考来源:

  • https://security.stackexchange.com/questions/260956/java-xxe-vulnerability
  • https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
  • https://docs.datadoghq.com/security/code_security/static_analysis/static_analysis_rules/java-security/xml-parsing-xee/
  • https://github.com/jwenjian/ghiblog/issues/37
  • https://www.jetbrains.com/privacy-security/issues-fixed/?product=Ktor
  • https://patorjk.com/software/taag/#p=display&f=Big&t=CVE-2023-45612%0A&x=none&v=4&h=4&w=80&we=false
  • https://github.com/ktorio/ktor/blob/05f8f73b8e20962fe55c003eb0757113e3495272/ktor-shared/ktor-serialization/ktor-serialization-kotlinx/ktor-serialization-kotlinx-xml/jvm/test/XmlServerKotlinxSerializationTest.kt
下载工具