ÿÖÜÉý¼¶²¼¸æ-2022-10-11
°ä²¼¹¦·ò 2022-10-11ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_×¢Èë¹¥»÷_Dolibarr_ERP-CRM_8.0.4_rowid_SQL×¢Èë |
°²È«ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃDolibarrEPR-CRM8.0.4ÒÔ¼°Ö®Ç°°æ±¾´æÔÚµÄsql×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳÊý¾Ý¿âÖеÄÐÅÏ¢¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Redis_v4.x-v5.x_Ô¶³ÌºÅÁîÖ´ÐÐ1 |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Redis4.x¡¢5.x°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬ÌṩÁËÖ÷´Óģʽ¡£¡£¡£¡£¡£Ö÷´Óģʽ֧ʹÓÃÒ»¸öredis×÷ΪÖ÷»ú£¬£¬£¬£¬£¬£¬£¬ÆäËûµÄ×÷Ϊ±¸·Ý»ú£¬£¬£¬£¬£¬£¬£¬Ö÷»ú´Ó»úÊý¾Ý¶¼ÊÇÒ»ÑùµÄ£¬£¬£¬£¬£¬£¬£¬´Ó»úÖ»ÕÆ¹Ü¶Á£¬£¬£¬£¬£¬£¬£¬Ö÷»úÖ»ÕÆ¹Üд¡£¡£¡£¡£¡£ÔÚReids4.xÖ®ºó£¬£¬£¬£¬£¬£¬£¬Í¨¹ý±í²¿ÍØÕ¹£¬£¬£¬£¬£¬£¬£¬Äܹ»Êµ´Ë¿ÌredisÖÐʵÏÖÒ»¸öеÄRedisºÅÁ£¬£¬£¬£¬£¬£¬»ú¹Ø¶ñÒâ.soÎļþ¡£¡£¡£¡£¡£ÔÚÁ½¸öRedisÊ·ýÉèÖÃÖ÷´ÓģʽµÄʱ³½£¬£¬£¬£¬£¬£¬£¬RedisµÄÖ÷»úÊ·ýÄܹ»Í¨¹ýFULLRESYNCͬ²½Îļþµ½´Ó»úÉÏ¡£¡£¡£¡£¡£¶øºóÔÚ´Ó»úÉϼÓÔØ¶ñÒâsoÎļþ£¬£¬£¬£¬£¬£¬£¬¼´¿ÉÖ´ÐкÅÁî¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Redis_v4.x-v5.x_Ô¶³ÌºÅÁîÖ´ÐÐ2 |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Redis4.x¡¢5.x°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬ÌṩÁËÖ÷´Óģʽ¡£¡£¡£¡£¡£Ö÷´Óģʽ֧ʹÓÃÒ»¸öredis×÷ΪÖ÷»ú£¬£¬£¬£¬£¬£¬£¬ÆäËûµÄ×÷Ϊ±¸·Ý»ú£¬£¬£¬£¬£¬£¬£¬Ö÷»ú´Ó»úÊý¾Ý¶¼ÊÇÒ»ÑùµÄ£¬£¬£¬£¬£¬£¬£¬´Ó»úÖ»ÕÆ¹Ü¶Á£¬£¬£¬£¬£¬£¬£¬Ö÷»úÖ»ÕÆ¹Üд¡£¡£¡£¡£¡£ÔÚReids4.xÖ®ºó£¬£¬£¬£¬£¬£¬£¬Í¨¹ý±í²¿ÍØÕ¹£¬£¬£¬£¬£¬£¬£¬Äܹ»Êµ´Ë¿ÌredisÖÐʵÏÖÒ»¸öеÄRedisºÅÁ£¬£¬£¬£¬£¬£¬»ú¹Ø¶ñÒâ.soÎļþ¡£¡£¡£¡£¡£ÔÚÁ½¸öRedisÊ·ýÉèÖÃÖ÷´ÓģʽµÄʱ³½£¬£¬£¬£¬£¬£¬£¬RedisµÄÖ÷»úÊ·ýÄܹ»Í¨¹ýFULLRESYNCͬ²½Îļþµ½´Ó»úÉÏ¡£¡£¡£¡£¡£¶øºóÔÚ´Ó»úÉϼÓÔØ¶ñÒâsoÎļþ£¬£¬£¬£¬£¬£¬£¬¼´¿ÉÖ´ÐкÅÁî¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Drogon_framework_Ó×ÓÚ1.75_ËÁÒâÎļþÉÏ´«[CVE-2022-25297] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | DrogonframeworkÊÇÒ»¸ö»ùÓÚC++14/17µÄHTTPÀûÓ÷¨Ê½¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬Ó×ÓÚ1.75°æ±¾Ê±ÈÝÒ×Êܵ½ËÁÒâÎļþдÈëµÄÓ°Ïì¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚÔÚÉÏ´«¹ý³ÌÖжÔÎļþÃûµÄ²»°²È«´¦ÖÿÉÄÜʹ¹¥»÷Õß¿ÉÄܽ«ÎļþдÈëÖ¸¶¨Ö¸±êÎļþ¼ÐÖ®±íµÄËÁÒâµØÎ»¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_ColdFusion_Îļþ¶ÁÈ¡[CVE-2010-2861] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | AdobeColdFusionÊÇÒ»¸ö¶¯Ì¬Web·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬ÆäËùѡȡµÄCFML(ColdFusionMarkupLanguage)·¨Ê½Éè¼ÆËµ»°ÀàËÆ"107" style="border-right: 1px solid windowtext; border-bottom: 1px solid windowtext; border-left: 1px solid windowtext; border-image: initial; border-top: none; background: white; padding: 0px 7px;"> ¸üй¦·ò£º20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Bitbucket_Server_ºÅÁîÖ´ÐÐ[CVE-2022-36804] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | AtlassianBitbucketServerºÍDataCenter7.0.07.6.17֮ǰµÄ¶à¸öAPI¶Ëµã£¬£¬£¬£¬£¬£¬£¬7.17.10֮ǰµÄ°æ±¾7.7.0£¬£¬£¬£¬£¬£¬£¬7.21.4֮ǰµÄ°æ±¾7.18.0£¬£¬£¬£¬£¬£¬£¬8.0֮ǰµÄ°æ±¾8.0.0¡£¡£¡£¡£¡£3£¬£¬£¬£¬£¬£¬£¬´Ó°æ±¾8.1.0µ½°æ±¾8.1.3£¬£¬£¬£¬£¬£¬£¬´Ó°æ±¾8.2.0µ½°æ±¾8.2.2£¬£¬£¬£¬£¬£¬£¬´Ó°æ±¾8.3.0µ½8.3.1ÔÊÐíÔ¶³Ì¹¥»÷Õß¶Ô¹«¹²»ò˽ÓÐBitbucket´æ´¢¿âÓµÓжÁȡȨÏÞÖ´ÐÐͨ¹ý·¢ËͶñÒâHTTPÒªÇóµÄËÁÒâ´úÂë |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | ICMP_ºóÃÅ_Bvp47_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | Bvp47ÊÇ·½³Ìʽ×éÖ¯µÄ¶¥¼¶LinuxºóÃÅ£¬£¬£¬£¬£¬£¬£¬·½³Ìʽ×éÖ¯ÊÇÊÀ½ç³¬Ò»Á÷µÄÍøÂç¹¥»÷×éÖ¯£¬£¬£¬£¬£¬£¬£¬ÆÕ±éÒÔΪ´ÓÊôÓÚÃÀ¹ú¹ú¶È°²È«¾ÖNSA¡£¡£¡£¡£¡£Bvp47ͨ¹ýÔÚµÚÒ»¸öSYN°üÖмдøÊý¾ÝµÄ·½Ê½À´¶ã±ÜÍøÂ簲ȫÉ豸µÄ¼ì²â¡£¡£¡£¡£¡£Bvp47ʵÏÖÔ̺¬Á˸´ÔӵĴúÂë¡¢Çø¶Î¼Ó½âÃÜ£¬£¬£¬£¬£¬£¬£¬Linux¶à°æ±¾Æ½Ì¨ÊÊÅ䣬£¬£¬£¬£¬£¬£¬·á˶µÄrootkit·´×·×Ù¼¼ÇÉ¡£¡£¡£¡£¡£×î³ÁÒªµÄÊǼ¯³ÉÁ¶¯ß¼¶Òñ±ÎÐÅ·ÖÐËùʹÓõÄBPFÒýÇæ¸ß¼¶ÀûÓü¼ÇÉ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°·±ËöµÄͨѶ¼Ó½âÃÜÁ÷³Ì¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-35491/CVE-2020-36179/CVE-2020-36181/CVE-2020-36183/CVE-2020-36186] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃJackson<2.9.9.2ÒÔ¼°>=2.0.0,<=2.9.10.7°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£JacksonÊÇÒ»¸ö¿ÉÄܽ«java¶ÔÏóÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÄܽ«JSON×Ö·û´®·´ÐòÁл¯Îªjava¶ÔÏóµÄ¿ò¼Ü |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_WebLogic·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2018-3191] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÊÔIJÀûÓÃWebLogic12.2.1.3¼°Ö®Ç°µÄ°æ±¾´æÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£WeblogicÊÇĿǰȫÇòÊг¡ÉÏÀûÓÃ×î¿í·ºµÄJ2EE¹¤¾ßÖ®Ò»£¬£¬£¬£¬£¬£¬£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÀûÓ÷¨Ê½·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬ÆäÓÃÓÚ¹¹½¨J2EEÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬Ö§³ÖÐÂÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬¿É½µµÍÔËÓª³É±¾£¬£¬£¬£¬£¬£¬£¬Ìá¸ß»úÄÜ£¬£¬£¬£¬£¬£¬£¬¼ÓÇ¿¿ÉÀ©´óÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£¡£¡£¡£¡£T3ºÍ̸ÊÇÓÃÓÚWeblogic·þÎñÆ÷ºÍÆäËûJavaApplicationÖ®¼ä´«ÊäÐÅÏ¢µÄºÍ̸£¬£¬£¬£¬£¬£¬£¬ÊÇʵÏÖRMIÔ¶³Ì¹ý³ÌŲÓõÄרÓкÍ̸£¬£¬£¬£¬£¬£¬£¬ÆäÔÊÐí¿Í»§¶Ë½øÐÐJNDIŲÓᣡ£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Redis_v4.x-v5.x_Ô¶³ÌºÅÁîÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Redis4.x¡¢5.x°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬ÌṩÁËÖ÷´Óģʽ¡£¡£¡£¡£¡£Ö÷´Óģʽ֧ʹÓÃÒ»¸öredis×÷ΪÖ÷»ú£¬£¬£¬£¬£¬£¬£¬ÆäËûµÄ×÷Ϊ±¸·Ý»ú£¬£¬£¬£¬£¬£¬£¬Ö÷»ú´Ó»úÊý¾Ý¶¼ÊÇÒ»ÑùµÄ£¬£¬£¬£¬£¬£¬£¬´Ó»úÖ»ÕÆ¹Ü¶Á£¬£¬£¬£¬£¬£¬£¬Ö÷»úÖ»ÕÆ¹Üд¡£¡£¡£¡£¡£ÔÚReids4.xÖ®ºó£¬£¬£¬£¬£¬£¬£¬Í¨¹ý±í²¿ÍØÕ¹£¬£¬£¬£¬£¬£¬£¬Äܹ»Êµ´Ë¿ÌredisÖÐʵÏÖÒ»¸öеÄRedisºÅÁ£¬£¬£¬£¬£¬£¬»ú¹Ø¶ñÒâ.soÎļþ¡£¡£¡£¡£¡£ÔÚÁ½¸öRedisÊ·ýÉèÖÃÖ÷´ÓģʽµÄʱ³½£¬£¬£¬£¬£¬£¬£¬RedisµÄÖ÷»úÊ·ýÄܹ»Í¨¹ýFULLRESYNCͬ²½Îļþµ½´Ó»úÉÏ¡£¡£¡£¡£¡£¶øºóÔÚ´Ó»úÉϼÓÔØ¶ñÒâsoÎļþ£¬£¬£¬£¬£¬£¬£¬¼´¿ÉÖ´ÐкÅÁî¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÍøÂçɨÃè_Netsparker_WEB·ì϶ɨÃè |
°²È«ÀàÐÍ£º | °²È«É¨Ãè |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃNetsparker¶ÔÖ÷ÕÅÖ÷»ú½øÐÐwebÀûÓð²È«·ì϶ɨÃèµÄÐÐΪ¡£¡£¡£¡£¡£NetsparkerÊÇÒ»¿î×ÛºÏÐ͵ÄwebÀûÓð²È«·ì϶ɨÃ蹤¾ß,Ëü¿ÉÄܸüºÃµÄ¼ì²âSQLInjectionºÍCross-siteScriptingÀàÐ͵ݲȫ·ì϶¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ÉÄܻᵼÖÂϵͳй¶ijЩÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Sanic_static_Îļþ¶ÁÈ¡ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IP¶ÔÖ÷ÕÅIPµÄSanic½øÐй¥»÷µÄÐÐΪ.SanicÒ»¸ö»ùÓÚPython3.5+µÄÒì²½(asyncio+uvloop)web¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬ÓëFlaskÓеãÀàËÆ¡£¡£¡£¡£¡£´¦ÖÃËٶȿ죬£¬£¬£¬£¬£¬£¬ÀûÓÃ¿í·º¡£¡£¡£¡£¡£ÔÊÐí¶ÁÈ¡ËÁÒâÎļþ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÐÅϢй¶_DedeCMSÖÎÀíĿ¼ö¾Ù_Ãô¸ÐÐÅϢй¶ |
°²È«ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPµØÖ·Ö÷»úÔÚÏòÖ÷ÕÅIPµØÖ·Ö÷»úÌáÒéDedeCMSÖÎÀíĿ¼ö¾Ù·ì϶¹¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£DedeCMSÊÇÊ¢ÐеÄPHP¿ªÔ´ÍøÕ¾ÖÎÀíϵͳ¡£¡£¡£¡£¡£Í¨³£DedeCMSÍøÕ¾ÔÚ×°ÖúóÖÎÀíÔ±»áÅú¸Äºó¶ÜÖÎÀíĿ¼Ϊһ¸öÌØÊâµÄ×Ö·û´®£¬£¬£¬£¬£¬£¬£¬Ô¤·À¹¥»÷Õß´Ó±í²¿ÕÒµ½ºó¶ÜÖÎÀíĿ¼¡£¡£¡£¡£¡£DedeCMSV5.7SP2×îа汾¼°ÒÔǰ°æ±¾´æÔÚÖÎÀíĿ¼ö¾Ù·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýWindows²Ù×÷ϵͳ¸öÐÔ¼¼ÇÉÐԵı©Á¦Ã¶¾ÙÖÎÀíºó¶ÜĿ¼¡£¡£¡£¡£¡£³¢ÊÔ±©Á¦Ã¶¾ÙÖÎÀíĿ¼¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_php·´ÐòÁл¯Ó×Âí_ÎļþÉÏ´« |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÏòÖ÷ÕÅipÉÏ´«php·´ÐòÁл¯µÄwebshellÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþͨ³£Ô̺¬·´ÐòÁл¯destruct()º¯Êý£¬£¬£¬£¬£¬£¬£¬ºÍÖ´ÐкÅÁîµÄassert.()º¯Êý¡£¡£¡£¡£¡£ÉÏ´«³É¹¦ºóµ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×¢·þÎñÆ÷±»ÊÕÊܵȺó¹û¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Atlassian_Crowd_Ô¶³ÌºÅÁîÖ´ÐÐ[CNNVD-201905-1031] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´Ö÷»úIPÔÚÀûÓÃÖ÷ÕÅIPÖ÷»úÉÏAtlassian-CrowdÉÏ¡°/crowd/plugins/servlet/cdl¡±´¦µÄ´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬£¬»ú¹Ø¶ñÒâºÅÁ£¬£¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¼°·þÎñÆ÷ȨÏÞ¡£¡£¡£¡£¡£AtlassianCrowdÊÇÒ»Ì×»ùÓÚWebµÄµ¥µãµÇ¼ϵͳ¡£¡£¡£¡£¡£¸ÃϵͳΪ¶àÓû§¡¢ÍøÂçÀûÓ÷¨Ê½ºÍĿ¼·þÎñÆ÷ÌṩÑéÖ¤¡¢ÊÚȨµÈÖ°ÄÜ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9546/9547/9548] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃÖ÷ÕÅÖ÷»úÉÏJACKSONµÄºÚÃûµ¥¾ÖÏÞ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýshiro-coreÀà´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ²Ù×÷¡£¡£¡£¡£¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îºÏÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßº±¼û¾Ý°ó¶¨Ö°ÄܵÄÖ÷Ìâ×é¼þÖ®Ò»¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Ruby_On_Rails_ºÅÁîÖ´ÐÐ[CVE-2020-8163][CNNVD-202005-856] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃRuby_On_RailsµÄsystemÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬»ú¹Ø¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬Ö´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£RailsÓÐÒ»¸öÃûΪrenderµÄAPI£¬£¬£¬£¬£¬£¬£¬ËüÄܹ»Èÿª·¢ÈËԱѡÔñÒª³öÏÖÄÚÈݵÄÄ£°å¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬£¬£¬»¹Äܹ»´«µÝÒ»¸ölocalsÊý×飬£¬£¬£¬£¬£¬£¬½«¸ü¶àµÄ±äÁ¿ÏòÏ´«µÝ¸øÄ£°å×ÔÉí£¬£¬£¬£¬£¬£¬£¬·½±ãÄúÀ©´óÄ£°åµÄ½Ã½ÝÐÔ£¬£¬£¬£¬£¬£¬£¬ÉõÖÁʹÆäÖ°Äܸü׳´ó¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Jackson·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14060][CNNVD-202006-997] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃFasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬Í¨¹ý»ú¹Ø¶ñÒâµÄoadd.org.apache.xalan.lib.sql.JNDIConnectionPoolÀàjsonÐòÁл¯×Ö·û´®£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Jackson_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14062][CNNVD-202006-996] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃFasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¶ñÒâµÄcom.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPoolÀàjsonÐòÁл¯×Ö·û´®»ñȡָ±êϵͳµÄȨÏÞ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Jackson·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14195][CNNVD-202006-1070] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃFasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬Í¨¹ý»ú¹Ø¶ñÒâµÄorg.jsecurity.realm.jndi.JndiRealmFactoryÀàjsonÐòÁл¯×Ö·û´®Ôì³É´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬´Ó¶ø½ÚÔìÖ¸±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Jackson·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-14540][CNNVD-201909-716] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃJackson2.9.10°æ±¾Ö®Ç°´æÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬Í¨¹ý»ú¹Ø¶ñÒâµÄcom.zaxxer.hikari.HikariConfigÀàjsonÐòÁл¯Êý¾Ý½øÐÐjndi×¢Èë¹¥»÷£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳµÄȨÏÞ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_SangforEDR_cssp_Ô¶³ÌºÅÁîÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÕÛ·þ¹«Ë¾ÌṩµÄÒ»Ì×Öն˰²È«½â¾ö¹æ»®¡£¡£¡£¡£¡£´Ë²úÆ·´æÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¨ºÅÁî×¢È룩£¬£¬£¬£¬£¬£¬£¬Î´¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÔìÒªÇó°ü£¬£¬£¬£¬£¬£¬£¬Äܹ»Ôì³ÉÔ¶³ÌÖ´ÐкÅÁîµÄºó¹û¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JACKSON_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-12384][CNNVD-201906-867] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_JACKSON_Ô¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îºÏÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßº±¼û¾Ý°ó¶¨Ö°ÄܵÄÖ÷Ìâ×é¼þÖ®Ò»¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚJacksonºÚÃûµ¥¹ýÂ˲»ÆëÈ«¶øµ¼Ö£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɻú¹ØÔ̺¬ÓжñÒâ´úÂëµÄjsonÊý¾Ý°ü¶ÔÀûÓýøÐй¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¶³ÌºÅÁîÖ´ÐÓ×£¡£¡£¡£¡£¹¥»÷³É¹¦£¬£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221011 |


¾©¹«Íø°²±¸11010802024551ºÅ