ÿÖÜÉý¼¶²¼¸æ-2022-04-19

°ä²¼¹¦·ò 2022-04-19
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_·ÉËþSSL-VPNÎļþ¶ÁÈ¡·ì϶[CVE-2018-13379][CNNVD-201905-1026]

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

·¢ÏÖÖ¸±êÔÚÔâ·ê·ÉËþSSL-VP.NÎļþ¶ÁÈ¡·ì϶[CVE-2018-13379]¹¥»÷

¸üй¦·ò£º

20220419


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Apache-Tapestry-HMAC_ÐÅϢй¶

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

ApacheTapestryÊÇÒ»ÖÖÓÃJava±àдµÄÃæÏò×é¼þµÄWebÀûÓ÷¨Ê½¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£¡£TapestryÄܹ»ÔÚÖ°ºÎÀûÓ÷¨Ê½·þÎñÆ÷Ϲ¤×÷£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒÄܹ»ÇáËɼ¯³ÉËùÓкó¶Ë£¬£¬£¬ £¬£¬£¬£¬£¬ÈçSpring£¬£¬£¬ £¬£¬£¬£¬£¬HibernateµÈ¡£¡£¡£¡£¡£¡£¡£¡£http://localhost:8080/assets/something/services/AppModule.class/ÔÚºÚÃûµ¥²é³­ºó£¬£¬£¬ £¬£¬£¬£¬£¬Ð±Ïß±»°þÀ룬£¬£¬ £¬£¬£¬£¬£¬AppModule.classÎļþ±»¼ÓÔØµ½ÏìÓ¦ÖÓ×£¡£¡£¡£¡£¡£¡£¡£Õâ¸öÀàͨ³£Ô̺¬ÓÃÓÚ¶ÔÐòÁл¯µÄJava¶ÔÏó½øÐÐÊðÃûµÄHMACÃØÔ¿£¬£¬£¬ £¬£¬£¬£¬£¬ÔÚ֪·¸ÃÃÜÔ¿µÄÇé¿öÏ£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄܹ»Ç©ÊðJavaÓ×¹¤¾ßÁ´£¨ÀýÈçysoserialµÄCommonsBeanUtils1£©£¬£¬£¬ £¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2021-27850£©¡£¡£¡£¡£¡£¡£¡£¡£CVE-2021-27850Ó°ÏìÁìÓò:ApacheTapestry5.4.5ApacheTapestry5.5.0ApacheTapestry5.6.2ApacheTapestry5.7.0

¸üй¦·ò£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Apache_Kylin_δÊÚȨÅäÖÃй¶·ì϶[CVE-2020-13937][CNNVD-202010-896]

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

ApacheKylinÊÇÒ»¸ö¿ªÔ´µÄÉ¢²¼Ê½·ÖÎöÒýÇæ£¬£¬£¬ £¬£¬£¬£¬£¬Ëü×î³õÓÉeBay¿ª·¢£¬£¬£¬ £¬£¬£¬£¬£¬´Ë¿ÌÊÇApacheSoftwareFoundationµÄÏîÄ¿¡£¡£¡£¡£¡£¡£¡£¡£ApacheKylin³ÉÁ¢ÔÚApacheHadoop£¬£¬£¬ £¬£¬£¬£¬£¬ApacheHive£¬£¬£¬ £¬£¬£¬£¬£¬ApacheHBase£¬£¬£¬ £¬£¬£¬£¬£¬ApacheParquet£¬£¬£¬ £¬£¬£¬£¬£¬ApacheCalcite£¬£¬£¬ £¬£¬£¬£¬£¬ApacheSparkºÍÆäËû¼¼ÊõÖ®ÉÏ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¼¼ÊõʹKylinÄܹ»ÇáËÉÀ©´óÒÔÖ§³Öº£Á¿Êý¾Ý¸ºÔØ¡£¡£¡£¡£¡£¡£¡£¡£ApacheKylinÓÐÒ»¸örestfulapi»áÔÚûÓÐÈÏ¿ÉÈÏÖ¤µÄÇé¿ö϶³öÅäÏàÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñȡϵͳÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Jira_δ¾­Éí·ÝÑéÖ¤Óû§Ãûö¾Ù·ì϶[CVE-2020-14181][CNNVD-202009-1072]

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

AtlassianJiraÊÇÆóÒµ¿í·ºÊ¹ÓõÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß£¬£¬£¬ £¬£¬£¬£¬£¬±»¿í·ºÀûÓÃÓÚȱµã¸ú×Ù¡¢¿Í»§·þÎñ¡¢ÐèÒªÍøÂç¡¢Á÷³ÌÉóÅú¡¢¹¤×÷¸ú×Ù¡¢ÏîÄ¿¸ú×ٺͻðËÙÖÎÀíµÈ¹¤×÷ÁìÓò¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÓÃÓÚö¾ÙÓû§Õ˺𣡣¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_Apache_Druid_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2021-26919][CNNVD-202101-2542]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ApacheDruidʹÓÃJDBC´ÓÆäËüÊý¾Ý¿â¶ÁÈ¡Êý¾Ý£¬£¬£¬ £¬£¬£¬£¬£¬´ËÖ°ÄÜÊÇΪÁËÈÃÊÜÐÅÀµµÄÓû§Í¨¹ýÊʵ±µÄȨÏÞÀ´ÉèÖòéÕÒ»òÌá½»ÌáÈ¡¹¤×÷¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚApacheDruidĬÈÏÇé¿öϲ»×ãÊÚȨÈÏÖ¤£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâÒªÇóÖ´ÐÐËÁÒâ´úÂ룬£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_IOT·ì϶_Trend_Micro_InterScan_WebSecurity_Virtual_Appliance_ºÅÁî×¢Èë·ì϶[CVE-2020-8466][CNNVD-202012-1205]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

TrendMicroInterScanWebSecurityVirtualAppliance6.5SP2´æÔÚÒ»¸öºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚ¶ÔHTTPÒªÇóÖÐÓû§ÌṩµÄÊý¾ÝµÄÑéÖ¤²»µ±Ôì³ÉµÄ¡£¡£¡£¡£¡£¡£¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±ê·þÎñÆ÷·¢ËͶñÒâÒªÇóÀ´ÀûÓÃÕâЩ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬³É¹¦ÀûÓÃÕâЩ·ì϶¿ÉÄÜÔÊÐíÔÚiscanÕÊ»§µÄ°²È«¸ßµÍÎÄÖÐÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Nexus_EL±í°×ʽעÈë·ì϶[CVE-2018-16341]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

NuxeoPlatformÊÇÒ»¿î¿çƽ̨¿ªÔ´µÄÆóÒµ¼¶ÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚnuxeo-jsf-ui×é¼þ´¦ÖÃfaceletÄ£°å²»µ±£¬£¬£¬ £¬£¬£¬£¬£¬µ±½Ó¼ûµÄfaceletÄ£°å²»´æÔÚʱ£¬£¬£¬ £¬£¬£¬£¬£¬ÓйصÄÎļþÃû»áÊä³öµ½ÃýÎóÒ³ÃæÉÏ£¬£¬£¬ £¬£¬£¬£¬£¬¶øÃýÎóÒ³Ãæ»áµ±³ÉÄ£°å±»½âÎö£¬£¬£¬ £¬£¬£¬£¬£¬ÎļþÃûÔ̺¬±í°×ʽ»á±»Êä³öͬʱ±»½âÎöÖ´ÐУ¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Zoho_ManageEngine_Applications_Manager_upload.php_ËÁÒâÎļþÉÏ´«·ì϶[CVE-2020-14008][CNNVD-202009-296]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ZohoManageEngineApplicationsManager14710¼°Ö®Ç°°æ±¾ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÖÎÀíÔ±Óû§ÔÚÌØ¶¨µØÎ»ÉÏ´«ËÁÒâjarÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419

 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Fodcha_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçFodchaÊÔͼÏνÓC&C·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFodcha¡£¡£¡£¡£¡£¡£¡£¡£FodchaÖØÒªÍ¨¹ýNDay·ì϶ºÍTelnet/SSHÈõ¿ÚÁî´«²¼£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬CVE-2021-22205¡¢CVE-2021-35394¡¢AndroidADBDebugServerRCE¡¢LILINDVRRCEµÈ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÖðÈÕÉÏÏß¾³ÄÚÈ⼦ÊýÒÔIPÊýÍÆËãÒѳ¬¹ý1Íò£¬£¬£¬ £¬£¬£¬£¬£¬ÇÒÖðÈÕ»áÕë¶Ô³¬¹ý100¸ö¹¥»÷Ö¸±êÌáÒéDDoS¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷¼«¶È» £»£»£»£»£»îÔ¾¡£¡£¡£¡£¡£¡£¡£¡£FodchaʹÓÃChaCha20¼ÓÃܺÍC&CµÄͨѶÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419

  

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ExifTool_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2021-22204]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ExifToolÊÇÒ»¸ö¶ÀÁ¢ÓÚÆ½Ì¨µÄPerl¿â£¬£¬£¬ £¬£¬£¬£¬£¬Ò²ÓÐÒ»¸öºÅÁîÐÐÀûÓ÷¨Ê½£¬£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚ¶ÁÈ¡£¬£¬£¬ £¬£¬£¬£¬£¬Ð´ÈëºÍ±à×ë¸÷ÀàÎļþÖеÄÔªÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚExifTool°æ±¾7.44°æ±¾ÖдæÔÚ¶ÔDjVuÎļþÌåʽµÄÊý¾Ý´¦Öò»µ±¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚº¬Óзì϶°æ±¾µÄExifTool¿âµÄÀûÓ÷þÎñÆ÷»òÕßÀûÓ÷¨Ê½Ï£¬£¬£¬ £¬£¬£¬£¬£¬»ú¹Ø¶ñÒâDjVuÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬·þÎñÆ÷»òÕßÀûÓ÷¨Ê½Ô¶³Ì±¾µØ½âÎö´ËÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬£¬£¬ £¬£¬£¬£¬£¬×îÖÕ»ñÈ¡·þÎñÆ÷×î¸ßȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_IBM_QRada_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2018-1418][CNNVD-201804-1475]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

IBMQRadarÊÇÒ»¿îÆóÒµ°²È«ÐÅÏ¢ºÍÊÂÎñÖÎÀí²úÆ·£¬£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚÔ®ÊÖ°²È«·ÖÎöʦ¼ø±ðÆäÍøÂçÖеĸ´ÔÓÍþв²¢¸ÄÉÆÊÂÎñ½¨²¹´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£IBMSecurityQRadarSIEM7.2ºÍ7.3´æÔÚÒ»¸öÔ¶³ÌºÅÁîÖ´Ðзì϶£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐíÓû§ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬ £¬£¬£¬£¬£¬²¢Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_FatalRat_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºóÃÅFatalRatÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFatalRat¡£¡£¡£¡£¡£¡£¡£¡£FatalRatÊÇÒ»ÖÖ¸´ÔÓµÄC++RAT£¬£¬£¬ £¬£¬£¬£¬£¬¿ÉΪ¹¥»÷ÕßʵÏÖ¿í·ºµÄÔ¶¿ØÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£×ϺüľÂíPurpleFox×Ô2018ÄêÒÔÀ´¾ÍÒ»ÏòÆðÍ·»îÔ¾¡£¡£¡£¡£¡£¡£¡£¡£×î½üPurpleFoxͨ¹ý¸Ä½øÆä±øÆ÷¿â£¬£¬£¬ £¬£¬£¬£¬£¬ÓÔìðÍ·ÁËÐÂÒ»²¨µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Æä±øÆ÷¿â¾ÍÔ̺¬Á˺óÃÅFatalRat¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-061Ô¶³ÌºÅÁîÖ´Ðй¥»÷[CVE-2020-17530][CNNVD-202012-449][CVE-2020-17530/CVE-2021-31805][CNNVD-202012-449/CNNVD-202204-3223]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬£¬Òý·¢OGNL±í°×ʽ½âÎö£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20220419