CVE-2026-82045 UTMStack JPQL 注入漏洞
影响认证攻击者可读取任意实体数据,包括用户凭据表
UTMStack 11.2.16 之前版本存在 JPQL 注入漏洞。UtmNetworkScanService.searchPropertyValues() 使用 String.format() 拼接 JPQL 查询并通过 em.createQuery() 执行,未使用参数绑定。攻击者可通过 GET /api/utm-network-scans/searchPropertyValues 接口的 value 参数注入恶意 JPQL。
影响范围
UTMStack 11.2.16 之前的版本。
漏洞详情
漏洞类型为 JPQL 注入(类似 SQL 注入)。成因是服务端在构造 JPQL 查询时使用字符串格式化拼接用户输入,且未进行参数绑定,导致用户可控的 value 参数被直接拼入查询语句。攻击者利用该接口注入恶意 JPQL 片段,从而绕过查询限制读取任意实体数据,例如 jhi_user 等凭据表。
利用条件与风险
利用前提是攻击者需通过身份认证。成功利用后可读取数据库中的敏感信息,包括用户凭据,可能导致权限提升或横向移动,CVSS 评分为 6.5(中危)。
修复建议
官方修复方案为升级至 UTMStack 11.2.16 或更高版本。临时缓解措施包括限制该接口的访问权限、对输入参数进行严格校验,或在不影响业务的前提下禁用相关功能。
UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query with String.format() and executes it via em.createQuery() without parameter binding. Attackers can inject malicious JPQL through the value parameter in the GET /api/utm-network-scans/searchPropertyValues endpoint to extract sensitive data including credential tables such as jhi_user.