ÿÖÜÉý¼¶²¼¸æ-2022-10-25
°ä²¼¹¦·ò 2022-10-25ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_PropertyPathFactoryBean_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃSnakeYAMLµÄPropertyPathFactoryBean·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_DefaultBeanFactoryPointcutAdvisor_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃSnakeYAMLµÄDefaultBeanFactoryPointcutAdvisor·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_CommonsConfiguration_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃSnakeYAMLµÄCommonsConfiguration·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Grafana_8.3.0_Îļþ¶ÁÈ¡[CVE-2021-43798][CNNVD-202112-482] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃGrafana8.0.0-8.3.0°æ±¾ÖдæÔÚµÄÎļþ¶ÁÈ¡·ì϶£¬£¬£¬£¬£¬£¬´Ó¶øÔÚδÊÚȨµÄÇé¿ö϶Áȡָ±êϵͳÃô¸ÐÎļþ¡£¡£¡£¡£¡£GrafanaÊÇÒ»¸ö¿çƽ̨¡¢¿ªÔ´µÄÊý¾Ý¿ÉÊÓ»¯ÍøÂçÀûÓ÷¨Ê½Æ½Ì¨¡£¡£¡£¡£¡£Óû§ÅäÖÃÏνӵÄÊý¾ÝÔ´Ö®ºó£¬£¬£¬£¬£¬£¬GrafanaÄܹ»ÔÚÍøÂçä¯ÀÀÆ÷ÀïÏÔʾÊý¾Ýͼ±íºÍÖÒ¸æ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_HTTP_ɨÃè |
°²È«ÀàÐÍ£º | °²È«É¨Ãè |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓöÔÖ÷ÕÅÖ÷»úÊÔͼͨ¹ýNMAP»ñÈ¡¶ÔÓ¦Ö÷»úhttp·þÎñÆ÷°æ±¾ºÍ¶ÔÓ¦³§É̵ÄÐÐΪ¡£¡£¡£¡£¡£Õâ¿ÉÄܻᵼÖÂϵͳй¶ÓйØÐÅÏ¢¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_FortiOS_7.2.1_ȨÏÞÈÆ¹ý[CVE-2022-40684][CNNVD-202210-347] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃFortiOS7.2.1¼°ÒÔϰ汾£¬£¬£¬£¬£¬£¬FortiProxy7.2.0¼°ÒÔϰ汾£¬£¬£¬£¬£¬£¬FortiSwitchManager7.2.0¼°ÒÔϰ汾ÖдæÔÚµÄȨÏÞÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬ÔÚδÊÚȨµÄÇé¿öÏÂÅú¸ÄÓû§µÄssh¹«Ô¿£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_·ì϶ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âÀûÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÖ÷ÕÅÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´Ðзì϶½øÐÐÀûÓÃÁ´±©ÆÆ¹¥»÷¡£¡£¡£¡£¡£ApacheShiro£¨·ì϶°æ±¾<=1.2.4£©ÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬£¬£¬£¬£¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí |
¸üй¦·ò£º | 20221025 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Struts2_S2-032_´úÂëÖ´ÐÐ[CVE-2016-3081] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃStruts2.3.20-StrutsStruts2.3.28(2.3.20.3ºÍ2.3.24.3Ö®±í)ÖдæÔڵĴúÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£Struts2ÊÇÒ»¸ö¼ò½àµÄ¡¢¿ÉÀ©´óµÄ¿ò¼Ü£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ´´½¨ÆóÒµ¼¶JavawebÀûÓ÷¨Ê½¡£¡£¡£¡£¡£Éè¼ÆÕâ¸ö¿ò¼ÜÊÇΪÁË´Ó¹¹½¨¡¢²¿Êð¡¢µ½ÀûÓ÷¨Ê½ÊØ»¤·½ÃæÀ´¼ò»¯Õû¸ö¿ª·¢ÖÜÆÚ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_Weblogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2801] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃOracleWeblogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬Ê¹ÓÃt3ºÍ̸·¢ËͶñÒâµÄÐòÁл¯Êý¾Ý£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£WeblogicÊÇĿǰȫÇòÊг¡ÉÏÀûÓÃ×î¿í·ºµÄJ2EE¹¤¾ßÖ®Ò»£¬£¬£¬£¬£¬£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÀûÓ÷¨Ê½·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÆäÓÃÓÚ¹¹½¨J2EEÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬Ö§³ÖÐÂÖ°ÄÜ£¬£¬£¬£¬£¬£¬¿É½µµÍÔËÓª³É±¾£¬£¬£¬£¬£¬£¬Ìá¸ß»úÄÜ£¬£¬£¬£¬£¬£¬¼ÓÇ¿¿ÉÀ©´óÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ÓÃÓÑNC6.5_XbrlPersistenceServlet_·´ÐòÁл¯_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | Äܹ»ÐÐΪ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃÓÃÓÑNC6.5ÖÐXbrlPersistenceServlet½Ó¿Ú´æÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬Ê¹ÓÃURLDNSÀûÓÃÁ´Ì½²â¸Ã·ì϶ÊÇ·ñ´æÔÚ¡£¡£¡£¡£¡£ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¹æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯ÀûÓü¯³É¡±µÄÖÎÀíÒµÎñÀíÏë¶øÉè¼Æ£¬£¬£¬£¬£¬£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯ÀûÓÃϵͳµÄÊ×Ñ¡¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-36189¡¢CVE-2020-36188¡¢CVE-2019-14439¡¢CVE-2019-14361] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | JacksonÊÇÒ»¸ö¿ÉÄܽ«java¶ÔÏóÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬£¬Ò²¿ÉÄܽ«JSON×Ö·û´®·´ÐòÁл¯Îªjava¶ÔÏóµÄ¿ò¼Ü¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜÀûÓÃjacksonµÄ¿ÉÒÉ·´ÐòÁл¯Ààlogback¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2883] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃWebLogicServer10.3.6.0.0£¬£¬£¬£¬£¬£¬12.1.3.0.0£¬£¬£¬£¬£¬£¬12.2.1.3.0£¬£¬£¬£¬£¬£¬12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳµÄȨÏÞ¡£¡£¡£¡£¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplicationserver£¬£¬£¬£¬£¬£¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖÐÑë¼þ£¬£¬£¬£¬£¬£¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀí´óÐÍÉ¢²¼Ê½WebÀûÓá¢ÍøÂçÀûÓúÍÊý¾Ý¿âÀûÓõÄJavaÀûÓ÷þÎñÆ÷¡£¡£¡£¡£¡£½«JavaµÄ¶¯Ì¬Ö°ÄܺÍJavaEnterprise³ß¶ÈµÄ°²È«ÐÔÒýÈë´óÐÍÍøÂçÀûÓõĿª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀíÖ®ÖÓ×£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-8840][CNNVD-202002-354] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | JacksonÊÇÒ»¸ö¿ÉÄܽ«java¶ÔÏóÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬£¬Ò²¿ÉÄܽ«JSON×Ö·û´®·´ÐòÁл¯Îªjava¶ÔÏóµÄ¿ò¼Ü¡£¡£¡£¡£¡£´Ë·ì϶Öй¥»÷Õß¿ÉÀûÓÃxbean-reflectµÄÀûÓÃÁ´´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ´Ó¶ø´ïµ½Ô¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Zabbix_Ó×ÓÚ4.4_δÊÚȨ½Ó¼û |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃZabbixÓ×ÓÚ4.4°æ±¾ÖдæÔÚµÄΪδÊÚȨ½Ó¼û·ì϶£¬£¬£¬£¬£¬£¬´Ó¶øÔÚδ¾ÊÚȨµÄÇé¿öϽӼûZabbix·þÎñÆ÷ÉϵÄÊý¾Ý£¬£¬£¬£¬£¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Struts2_S2-055_REST_JacksonLibrary_´úÂëÖ´ÐÐ[CVE-2017-7525] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | Tomcat·þÎñÆ÷ÊÇÒ»¸öÃâ·ÑµÄÊ¢¿ªÔ´´úÂëµÄWebÀûÓ÷þÎñÆ÷¡£¡£¡£¡£¡£Struts2ÊÇApacheÈí¼þ»ù½ð»áÕÆ¹ÜÊØ»¤µÄÒ»¿îÓÃÓÚ´´½¨ÆóÒµ¼¶JavaWebÀûÓõĿªÔ´¿ò¼Ü¡£¡£¡£¡£¡£Struts2ÔÚv2.5-v2.5.14£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýŲÓÃREST²å¼þÖеĴæÔÚ·´ÐòÁл¯·ì϶µÄJacksonLibraryÀ´´¦ÖÃJSONÊý¾Ý£¬£¬£¬£¬£¬£¬´Ó¶ø´¥·¢·´ÐòÁл¯·ì϶¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÐÅϢй¶_PACSOne_Server_6.6.2_DICOM_Web_Viewer_Ŀ¼±éÀú |
°²È«ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýPACSOneServerÖдæÔÚµÄĿ¼±éÀú·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúnocache.php¾ç±¾µÄ¡®path¡¯²ÎÊýÖеġ®..¡¯×Ö·ûÀûÓø÷ì϶¶ÁÈ¡ËÁÒâÎļþ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_ÁéͨOA_print.php_Îļþɾ³ý |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃÁéͨOAµÄV11.6¼°ÒÔǰµÄ°æ±¾´æÔÚµÄÎļþɾ³ý·ì϶½øÐй¥»÷¡£¡£¡£¡£¡£ÁéͨOAÊÇOfficeAnywhereµÄ¼ò³Æ£¬£¬£¬£¬£¬£¬¸Ãϵͳѡȡµ±ÏȵÄB/S(ä¯ÀÀÆ÷/·þÎñÆ÷)²Ù×÷·½Ê½£¬£¬£¬£¬£¬£¬Ê¹µÃÍøÂç°ì¹«²»ÊܵØÓòÏÞ¡£¡£¡£¡£¡£OfficeAnywhereѡȡ»ùÓÚWEBµÄÆóÒµÍÆË㣬£¬£¬£¬£¬£¬Ö÷HTTP·þÎñÆ÷ѡȡÁËÊÀ½çÉÏ×îÏȽøµÄApache·þÎñÆ÷£¬£¬£¬£¬£¬£¬»úÄܲ»±ä¿¿µÃס¡£¡£¡£¡£¡£Êý¾Ý´æÈ¡¼¯ÖнÚÔ죬£¬£¬£¬£¬£¬Ô¤·ÀÁËÊý¾Ýй©µÄ¿ÉÄÜ¡£¡£¡£¡£¡£ÌṩÊý¾Ý±¸·Ý¹¤¾ß£¬£¬£¬£¬£¬£¬±£»£»£»£»£»£»¤ÏµÍ³Êý¾Ý°²È«¡£¡£¡£¡£¡£¶à¼¶µÄȨÏÞ½ÚÔ죬£¬£¬£¬£¬£¬ÃÀÂúµÄÃÜÂëÑéÖ¤ÓëµÇ¼ÑéÖ¤»úÔìÔ½·¢Ç¿ÁËϵͳ°²È«ÐÔ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14645][CVE-2020-14625][CVE-2020-14644][CVE-2020-14687] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃOracleWebLogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÆäËü¿ÉÒÉÐÐΪ_PHPαºÍ̸ |
°²È«ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚʹÓÃPHPµÄһЩ·â×°ºÍ̸£¬£¬£¬£¬£¬£¬Èçphp://input,php://filterµÈÌá½»Ò»¾ä»°Ä¾Âí£¬£¬£¬£¬£¬£¬»òÔ¶³ÌÖ´ÐкÅÁîÀ´¹¥»÷Êܺ¦Õß·þÎñÆ÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-1000353] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃJenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶½øÐй¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£JenkinsÊÇÒ»¸ö¿ÉÀ©´óµÄ¿ªÔ´³ÖÐø¼¯³É·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÔںöàÆóÒµµÄÄÚÍøÖж¼²¿ÊðÁËÕâ¸öϵͳ¡£¡£¡£¡£¡£Jenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòJenkinsCLI´«µÝÐòÁл¯µÄJava¡®SignedObject¡¯¶ÔÏóÀûÓø÷ìÏ¶ÈÆ¹ý»ùÓÚºÚÃûµ¥µÄ±£»£»£»£»£»£»¤»úÔì¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2015-8103] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃJenkins1.637¼°Ö®Ç°°æ±¾¡¢JenkinsLTS1.625.1¼°Ö®Ç°°æ±¾´æÔڵķ´ÐòÁл¯·ì϶½øÐдúÂëÖ´Ðй¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êÖ÷»úȨÏÞ¡£¡£¡£¡£¡£JenkinsÊÇÒ»¸ö¿ÉÀ©´óµÄ¿ªÔ´³ÖÐø¼¯³É·þÎñÆ÷¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JBossMQ_JMS·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-7504][CNNVD-201705-937] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | RedHatJBossApplicationServerÊÇÒ»¿î»ùÓÚJavaEEµÄ¿ªÔ´ÀûÓ÷þÎñÆ÷¡£¡£¡£¡£¡£JBossAS4.x¼°Ö®Ç°°æ±¾ÖУ¬£¬£¬£¬£¬£¬JbossMQʵÏÖ¹ý³ÌµÄJMSoverHTTPInvocationLayerµÄHTTPServerILServlet.javaÎļþ´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÔìµÄÐòÁл¯Êý¾ÝÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JACKSON-databind_2670_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-11113][CNNVD-202003-1735] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´Ðзì϶ÏòÖ÷ÕÅip½øÐз´ÐòÁл¯¹¥»÷£»£»£»£»£»£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îºÏÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßº±¼û¾Ý°ó¶¨Ö°ÄܵÄ×é¼þ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_InfluxDB_δÊÚȨ½Ó¼û |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | influxdbÊÇÒ»¿î³ÛÃûµÄʱÐòÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÆäʹÓÃjwt×÷Ϊ¼øÈ¨·½Ê½¡£¡£¡£¡£¡£ÔÚÓû§¿ªÆôÁËÈÏÖ¤£¬£¬£¬£¬£¬£¬µ«Î´ÉèÖòÎÊýshared-secretµÄÇé¿öÏ£¬£¬£¬£¬£¬£¬jwtµÄÈÏÖ¤ÃÜԿΪ¿Õ×Ö·û´®£¬£¬£¬£¬£¬£¬´Ëʱ¹¥»÷ÕßÄܹ»Î±ÔìËÁÒâÓû§Éí·ÝÔÚinfluxdbÖÐÖ´ÐÐSQLÓï¾ä¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_IncomCMS_2.0_ÎļþÉÏ´«[CVE-2020-29597][CNNVD-202012-431] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | IncomCMS2.0ÒÔ¼°Ö®Ç°µÄ°æ±¾´æÔÚÎļþÉÏ´«·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÉÏ´«webshell»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Docker_Remote_API_δÊÚȨ½Ó¼û |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃDockerRemoteAPIÅäÖò»Æäʱµ¼ÖµÄδÊÚȨ½Ó¼û·ì϶dockerclient»òÕßhttpÖ±½ÓÒªÇó½Ó¼ûÕâ¸öAPI£¬£¬£¬£¬£¬£¬´Ó¶øÖ±½Ó½Ó¼ûËÞÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬»ò¶ÔÃô¸ÐÎļþ½øÐÐÅú¸Ä£¬£¬£¬£¬£¬£¬×îÖÕÆëÈ«½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£DockerRemoteAPIÊÇÒ»¸öÈ¡´úÔ¶³ÌºÅÁîÐнçÃæ£¨rcli£©µÄRESTAPI¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ShiroAttack¹¤¾ßʹÓÃ_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÖ÷ÕÅÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´Ðзì϶½øÐй¥»÷¡£¡£¡£¡£¡£ApacheShiro£¨·ì϶°æ±¾<=1.2.4£©ÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬£¬£¬£¬£¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨºÅÁî×¢Èë |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬£¬£¬£¬£¬exportovpn½Ó¿Ú´æÔÚºÅÁî×¢È룬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâºÅÁî¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_·ì϶ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ_ÄÚ´æÂí×¢Èë_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÖ÷ÕÅÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´Ðзì϶½øÐÐÀûÓ㬣¬£¬£¬£¬£¬²¢ÔÚÒªÇóÌ崦עÈëÄÚ´æÂí¡£¡£¡£¡£¡£ApacheShiro£¨·ì϶°æ±¾<=1.2.4£©ÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬£¬£¬£¬£¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_·ì϶ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âÀûÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÖ÷ÕÅÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´Ðзì϶½øÐÐÀûÓÃÁ´±©ÆÆ¹¥»÷¡£¡£¡£¡£¡£ApacheShiro£¨·ì϶°æ±¾<=1.2.4£©ÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬£¬£¬£¬£¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí |
¸üй¦·ò£º | 20221025 |


¾©¹«Íø°²±¸11010802024551ºÅ