ÿÖÜÉý¼¶Í¨¸æ-2022-10-25

Ðû²¼Ê±¼ä 2022-10-25

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_PropertyPathFactoryBean_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLµÄPropertyPathFactoryBean·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_DefaultBeanFactoryPointcutAdvisor_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLµÄDefaultBeanFactoryPointcutAdvisor·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_CommonsConfiguration_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLµÄCommonsConfiguration·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Grafana_8.3.0_Îļþ¶ÁÈ¡[CVE-2021-43798][CNNVD-202112-482]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃGrafana8.0.0-8.3.0°æ±¾Öб£´æµÄÎļþ¶ÁÈ¡Îó²î£¬£¬ £¬´Ó¶øÔÚδÊÚȨµÄÇéÐÎ϶ÁȡĿµÄϵͳÃô¸ÐÎļþ¡£¡£¡£¡£GrafanaÊÇÒ»¸ö¿çƽ̨¡¢¿ªÔ´µÄÊý¾Ý¿ÉÊÓ»¯ÍøÂçÓ¦ÓóÌÐòƽ̨¡£¡£¡£¡£Óû§ÉèÖÃÅþÁ¬µÄÊý¾ÝÔ´Ö®ºó£¬£¬ £¬Grafana¿ÉÒÔÔÚÍøÂçä¯ÀÀÆ÷ÀïÏÔʾÊý¾Ýͼ±íºÍÖÒÑÔ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_HTTP_ɨÃè

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓöÔÄ¿µÄÖ÷»úÊÔͼͨ¹ýNMAP»ñÈ¡¶ÔÓ¦Ö÷»úhttpЧÀÍÆ÷°æ±¾ºÍ¶ÔÓ¦³§É̵ÄÐÐΪ¡£¡£¡£¡£Õâ¿ÉÄܻᵼÖÂϵͳй¶Ïà¹ØÐÅÏ¢¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_FortiOS_7.2.1_ȨÏÞÈÆ¹ý[CVE-2022-40684][CNNVD-202210-347]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFortiOS7.2.1¼°ÒÔϰ汾£¬£¬ £¬FortiProxy7.2.0¼°ÒÔϰ汾£¬£¬ £¬FortiSwitchManager7.2.0¼°ÒÔϰ汾Öб£´æµÄȨÏÞÈÆ¹ýÎó²î£¬£¬ £¬ÔÚδÊÚȨµÄÇéÐÎÏÂÐÞ¸ÄÓû§µÄssh¹«Ô¿£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âʹÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐÐʹÓÃÁ´±©ÆÆ¹¥»÷¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬ £¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025

 

ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Struts2_S2-032_´úÂëÖ´ÐÐ[CVE-2016-3081]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃStruts2.3.20-StrutsStruts2.3.28(2.3.20.3ºÍ2.3.24.3³ýÍâ)Öб£´æµÄ´úÂëÖ´ÐÐÎó²î£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£Struts2ÊÇÒ»¸ö¾«Á·µÄ¡¢¿ÉÀ©Õ¹µÄ¿ò¼Ü£¬£¬ £¬¿ÉÓÃÓÚ½¨ÉèÆóÒµ¼¶JavawebÓ¦ÓóÌÐò¡£¡£¡£¡£Éè¼ÆÕâ¸ö¿ò¼ÜÊÇΪÁË´Ó¹¹½¨¡¢°²ÅÅ¡¢µ½Ó¦ÓóÌÐòά»¤·½ÃæÀ´¼ò»¯Õû¸ö¿ª·¢ÖÜÆÚ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_Weblogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2801]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃOracleWeblogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬Ê¹ÓÃt3ЭÒé·¢ËͶñÒâµÄÐòÁл¯Êý¾Ý£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£WeblogicÊÇÏÖÔÚÈ«ÇòÊг¡ÉÏÓ¦ÓÃ×îÆÕ±éµÄJ2EE¹¤¾ßÖ®Ò»£¬£¬ £¬±»³ÆÎªÒµ½ç×î¼ÑµÄÓ¦ÓóÌÐòЧÀÍÆ÷£¬£¬ £¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦ÓóÌÐò£¬£¬ £¬Ö§³Öй¦Ð§£¬£¬ £¬¿É½µµÍÔËÓª±¾Ç®£¬£¬ £¬Ìá¸ßÐÔÄÜ£¬£¬ £¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÓÃÓÑNC6.5_XbrlPersistenceServlet_·´ÐòÁл¯_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

¿ÉÒÔÐÐΪ

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNC6.5ÖÐXbrlPersistenceServlet½Ó¿Ú±£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬Ê¹ÓÃURLDNSʹÓÃÁ´Ì½²â¸ÃÎó²îÊÇ·ñ±£´æ¡£¡£¡£¡£ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬£¬ £¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-36189¡¢CVE-2020-36188¡¢CVE-2019-14439¡¢CVE-2019-14361]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬£¬ £¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜʹÓÃjacksonµÄ¿ÉÒÉ·´ÐòÁл¯Ààlogback¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2883]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃWebLogicServer10.3.6.0.0£¬£¬ £¬12.1.3.0.0£¬£¬ £¬12.2.1.3.0£¬£¬ £¬12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ¡£¡£¡£¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplicationserver£¬£¬ £¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖÐÐļþ£¬£¬ £¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀí´óÐÍÂþÑÜʽWebÓ¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦ÓõÄJavaÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£½«JavaµÄ¶¯Ì¬¹¦Ð§ºÍJavaEnterprise±ê×¼µÄÇå¾²ÐÔÒýÈë´óÐÍÍøÂçÓ¦ÓõĿª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀíÖ®ÖС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-8840][CNNVD-202002-354]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬£¬ £¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¡£¡£¡£´ËÎó²îÖй¥»÷Õß¿ÉʹÓÃxbean-reflectµÄʹÓÃÁ´´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zabbix_СÓÚ4.4_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃZabbixСÓÚ4.4°æ±¾Öб£´æµÄΪδÊÚȨ»á¼ûÎó²î£¬£¬ £¬´Ó¶øÔÚδ¾­ÊÚȨµÄÇéÐÎÏ»á¼ûZabbixЧÀÍÆ÷ÉϵÄÊý¾Ý£¬£¬ £¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Struts2_S2-055_REST_JacksonLibrary_´úÂëÖ´ÐÐ[CVE-2017-7525]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

TomcatЧÀÍÆ÷ÊÇÒ»¸öÃâ·ÑµÄ¿ª·ÅÔ´´úÂëµÄWebÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£Struts2ÊÇApacheÈí¼þ»ù½ð»áÈÏÕæÎ¬»¤µÄÒ»¿îÓÃÓÚ½¨ÉèÆóÒµ¼¶JavaWebÓ¦ÓõĿªÔ´¿ò¼Ü¡£¡£¡£¡£Struts2ÔÚv2.5-v2.5.14£¬£¬ £¬¹¥»÷Õßͨ¹ýŲÓÃREST²å¼þÖеı£´æ·´ÐòÁл¯Îó²îµÄJacksonLibraryÀ´´¦Öóͷ£JSONÊý¾Ý£¬£¬ £¬´Ó¶ø´¥·¢·´ÐòÁл¯Îó²î¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÐÅϢй¶_PACSOne_Server_6.6.2_DICOM_Web_Viewer_Ŀ¼±éÀú

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýPACSOneServerÖб£´æµÄĿ¼±éÀúÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúnocache.php¾ç±¾µÄ¡®path¡¯²ÎÊýÖеġ®..¡¯×Ö·ûʹÓøÃÎó²î¶ÁÈ¡í§ÒâÎļþ¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡Ãô¸ÐÐÅÏ¢

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ͨ´ïOA_print.php_Îļþɾ³ý

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃͨ´ïOAµÄV11.6¼°ÒÔǰµÄ°æ±¾±£´æµÄÎļþɾ³ýÎó²î¾ÙÐй¥»÷¡£¡£¡£¡£Í¨´ïOAÊÇOfficeAnywhereµÄ¼ò³Æ£¬£¬ £¬¸Ãϵͳ½ÓÄÉÁìÏȵÄB/S(ä¯ÀÀÆ÷/ЧÀÍÆ÷)²Ù×÷·½·¨£¬£¬ £¬Ê¹µÃÍøÂç°ì¹«²»ÊܵØÇøÏÞ¡£¡£¡£¡£OfficeAnywhere½ÓÄÉ»ùÓÚWEBµÄÆóÒµÅÌË㣬£¬ £¬Ö÷HTTPЧÀÍÆ÷½ÓÄÉÁËÌìÏÂÉÏ×îÏȽøµÄApacheЧÀÍÆ÷£¬£¬ £¬ÐÔÄÜÎȹ̿ɿ¿¡£¡£¡£¡£Êý¾Ý´æÈ¡¼¯ÖпØÖÆ£¬£¬ £¬×èÖ¹ÁËÊý¾Ý×ß©µÄ¿ÉÄÜ¡£¡£¡£¡£ÌṩÊý¾Ý±¸·Ý¹¤¾ß£¬£¬ £¬±£»£»£»£»¤ÏµÍ³Êý¾ÝÇå¾²¡£¡£¡£¡£¶à¼¶µÄȨÏÞ¿ØÖÆ£¬£¬ £¬ÍêÉÆµÄÃÜÂëÑéÖ¤ÓëµÇ¼ÑéÖ¤»úÖÆÔ½·¢Ç¿ÁËϵͳÇå¾²ÐÔ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14645][CVE-2020-14625][CVE-2020-14644][CVE-2020-14687]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃOracleWebLogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÆäËü¿ÉÒÉÐÐΪ_PHPαЭÒé

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃPHPµÄһЩ·âװЭÒ飬£¬ £¬Èçphp://input,php://filterµÈÌá½»Ò»¾ä»°Ä¾Âí£¬£¬ £¬»òÔ¶³ÌÖ´ÐÐÏÂÁîÀ´¹¥»÷Êܺ¦ÕßЧÀÍÆ÷£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-1000353]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î¾ÙÐй¥»÷£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£JenkinsÊÇÒ»¸ö¿ÉÀ©Õ¹µÄ¿ªÔ´Ò»Á¬¼¯³ÉЧÀÍÆ÷£¬£¬ £¬ÔÚÐí¶àÆóÒµµÄÄÚÍøÖж¼°²ÅÅÁËÕâ¸öϵͳ¡£¡£¡£¡£Jenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòJenkinsCLIת´ïÐòÁл¯µÄJava¡®SignedObject¡¯¹¤¾ßʹÓøÃÎó²îÈÆ¹ý»ùÓÚºÚÃûµ¥µÄ±£»£»£»£»¤»úÖÆ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2015-8103]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJenkins1.637¼°Ö®Ç°°æ±¾¡¢JenkinsLTS1.625.1¼°Ö®Ç°°æ±¾±£´æµÄ·´ÐòÁл¯Îó²î¾ÙÐдúÂëÖ´Ðй¥»÷£¬£¬ £¬´Ó¶ø»ñȡĿµÄÖ÷»úȨÏÞ¡£¡£¡£¡£JenkinsÊÇÒ»¸ö¿ÉÀ©Õ¹µÄ¿ªÔ´Ò»Á¬¼¯³ÉЧÀÍÆ÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JBossMQ_JMS·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-7504][CNNVD-201705-937]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

RedHatJBossApplicationServerÊÇÒ»¿î»ùÓÚJavaEEµÄ¿ªÔ´Ó¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£JBossAS4.x¼°Ö®Ç°°æ±¾ÖУ¬£¬ £¬JbossMQʵÏÖÀú³ÌµÄJMSoverHTTPInvocationLayerµÄHTTPServerILServlet.javaÎļþ±£´æ·´ÐòÁл¯Îó²î£¬£¬ £¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÐòÁл¯Êý¾ÝʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON-databind_2670_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-11113][CNNVD-202003-1735]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÏòÄ¿µÄip¾ÙÐз´ÐòÁл¯¹¥»÷£»£»£»£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_InfluxDB_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

influxdbÊÇÒ»¿îÖøÃûµÄʱÐòÊý¾Ý¿â£¬£¬ £¬ÆäʹÓÃjwt×÷Ϊ¼øÈ¨·½·¨¡£¡£¡£¡£ÔÚÓû§¿ªÆôÁËÈÏÖ¤£¬£¬ £¬µ«Î´ÉèÖòÎÊýshared-secretµÄÇéÐÎÏ£¬£¬ £¬jwtµÄÈÏÖ¤ÃÜԿΪ¿Õ×Ö·û´®£¬£¬ £¬´Ëʱ¹¥»÷Õß¿ÉÒÔαÔìí§ÒâÓû§Éí·ÝÔÚinfluxdbÖÐÖ´ÐÐSQLÓï¾ä¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_IncomCMS_2.0_ÎļþÉÏ´«[CVE-2020-29597][CNNVD-202012-431]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

IncomCMS2.0ÒÔ¼°Ö®Ç°µÄ°æ±¾±£´æÎļþÉÏ´«Îó²î£¬£¬ £¬¹¥»÷Õß¿ÉÒÔÉÏ´«webshell»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Docker_Remote_API_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃDockerRemoteAPIÉèÖò»µ±Ê±µ¼ÖµÄδÊÚȨ»á¼ûÎó²îdockerclient»òÕßhttpÖ±½ÓÇëÇó»á¼ûÕâ¸öAPI£¬£¬ £¬´Ó¶øÖ±½Ó»á¼ûËÞÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢£¬£¬ £¬»ò¶ÔÃô¸ÐÎļþ¾ÙÐÐÐ޸쬣¬ £¬×îÖÕÍêÈ«¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£DockerRemoteAPIÊÇÒ»¸öÈ¡´úÔ¶³ÌÏÂÁîÐнçÃæ£¨rcli£©µÄRESTAPI¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ShiroAttack¹¤¾ßʹÓÃ_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬ £¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬ £¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬£¬ £¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ_ÄÚ´æÂí×¢Èë_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐÐʹÓ㬣¬ £¬²¢ÔÚÇëÇóÌ崦עÈëÄÚ´æÂí¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬ £¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âʹÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐÐʹÓÃÁ´±©ÆÆ¹¥»÷¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬ £¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025