ÿÖÜÉý¼¶²¼¸æ-2023-03-21

°ä²¼¹¦·ò 2023-03-21
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_SSRF_Microsoft_Exchange_ProxyLogon_ɨÃè[CVE-2021-26855][CNNVD-202103-192][CVE-2021-26855]

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

MicrosoftExchangeÖÐÔ̺¬ÁËÊý¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öÏ£¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ý½áºÏʹÓÃÊý¸ö·ì϶À´ÈƹýExchangeǰ¶ËºÍÉí·ÝÏÞ¶È£¬£¬£¬£¬£¬£¬ÉÏ´«¶ñÒâÎļþµ½Exchange·þÎñÆ÷ÉÏ£¬£¬£¬£¬£¬£¬¸Ã·ì϶Á´¼´±»³ÆÎªProxyLogon£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñ¼ì²â¶ÔÆäÖеÄSSRF·ì϶ɨÃèÐÐΪ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý¸Ã·ì϶ÌáÉýȨÏÞ²¢Ö±½Ó½Ó¼ûºó¶Ë¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ºÅÁîÖ´ÐÐ_Bitbucket-Server&Data-Center_»·¾³±äÁ¿×¢Èë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ö÷»úÔÚÊܵ½Bitbucket-Server&Data-Center»·¾³±äÁ¿×¢È룬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËÁÒâºÅÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇͨ¹ý»·¾³±äÁ¿Òý·¢µÄºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓµÓÐȨÏ޵Ĺ¥»÷Õß½ÚÔìÓû§Ãû£¬£¬£¬£¬£¬£¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£×÷Ϊһʱ»º½â´ëÊ©£¬£¬£¬£¬£¬£¬Atlassian¹«Ë¾½¨ÒéÓû§¹Ø¹Ø¡°¹«¿ª×¢²á¡±Ñ¡Ïî¡£¡£¡£¡£¡£¡£¡£¡£°²È«²¼¸æÖ¸³ö£¬£¬£¬£¬£¬£¬¡°½ûÓù«¿ª×¢²á½«Ê¹¹¥»÷ÏòÁ¿´ÓδÈÏÖ¤¹¥»÷¸ü¸ÄΪÈÏÖ¤¹¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø½µµÍÀûÓ÷çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£¾­ÖÎÀíÔ±»òϵͳÖÎÀíÔ±ÈÏÖ¤µÄÓû§¿ÉÄÜÔÚ½ûÓù«¿ª×¢²áÑ¡ÏîʱÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·çÏÕ_¿ÉÒÉÐÐΪ_esi±êǩҪÇó

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

EdgeSideIncludes(ESI)ÊÇÒ»ÖÖÏóÕ÷˵»°£¬£¬£¬£¬£¬£¬ÖØÒªÔÚ³£¼ûµÄHTTP´úÀí£¨·´Ïò´úÀí¡¢¸ºÔØÆ½ºâ¡¢»º´æ·þÎñÆ÷¡¢´úÀí·þÎñÆ÷£©ÖÐʹÓᣡ£¡£¡£¡£¡£¡£¡£Í¨¹ýESI×¢Èë¼¼ÊõÄܹ»µ¼Ö·þÎñ¶ËÒªÇóαÔ죨SSRF£©£¬£¬£¬£¬£¬£¬ÈƹýHTTPOnlycookieµÄ¿çÕ¾¾ç±¾¹¥»÷£¨XSS£©ÒÔ¼°·þÎñ¶Ë»Ø¾ø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Í¨¹ý²âÊÔ£¬£¬£¬£¬£¬£¬Óм¸Ê®ÖÖÖ§³Ö´¦ÖÃESIµÄ²úÆ·£ºVarnish£¬£¬£¬£¬£¬£¬SquidProxy£¬£¬£¬£¬£¬£¬IBMWebSphere£¬£¬£¬£¬£¬£¬OracleFusion/WebLogic£¬£¬£¬£¬£¬£¬Akamai£¬£¬£¬£¬£¬£¬Fastly£¬£¬£¬£¬£¬£¬F5£¬£¬£¬£¬£¬£¬Node.jsESI£¬£¬£¬£¬£¬£¬LiteSpeedºÍÒ»Ð©ÌØ¶¨Ëµ»°²å¼þ£¬£¬£¬£¬£¬£¬µ«²¢²»ÊÇÕâЩ²úƷĬÈÏÆôÓÃÁËESI¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_RichFaces[CVE-2018-14667]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

RichFacesÊÇÒ»¸ö»ùÓÚLGPLºÍ̸ʢ¿ªÔ´´úÂëµÄJSF£¨JavaServerFaces£©×é¼þ¿â£¬£¬£¬£¬£¬£¬Ëü¿ÉÄÜʹÀûÓÿª·¢·½±ãµØ¼¯³ÉAJAX¡£¡£¡£¡£¡£¡£¡£¡£´Ë¿ÌµÄRichFaces¿âÊÇÓÉAjax4jsfºÍRichFacesÁ½²¿ÃÅ×é³É¡£¡£¡£¡£¡£¡£¡£¡£JavaRichFaces¿ò¼ÜÖÐÔ̺¬Ò»¸öRCE·ì϶,¹¥»÷Õ߿ɻú¹ØÔ̺¬org.ajax4jsf.resource.UserResource$UriDataÐòÁл¯¶ÔÏóµÄÌØ¶¨UserResourceÒªÇ󣬣¬£¬£¬£¬£¬RichFaces»áÏÈ·´ÐòÁл¯¸ÃUriData¶ÔÏ󣬣¬£¬£¬£¬£¬¶øºóʹÓÃEL±í°×ʽ½âÎö²¢»ñÈ¡resourceµÄmodified¡¢expiresµÈÖµµ¼ÖÂÁËËÁÒâEL±í°×ʽִÐУ¬£¬£¬£¬£¬£¬Í¨¹ý»ú¹ØÌØÊâµÄEL±í°×ʽ¿ÉʵÏÖÔ¶³ÌËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Õã½­ÓîÊӿƼ¼ÍøÂçÊÓÆµÂ¼Ïñ»ú_LogReport.php

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÔÚÀûÓÃÕã½­ÓîÊӿƼ¼ÍøÂçÊÓÆµÂ¼Ïñ»úµÄ·ì϶½øÐдúÂëÖ´Ðй¥»÷£»£»£»£»£»

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ÐÅϢй¶_Ametys_auto-completion_plugin[CVE-2022-26159]

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÔÚÀûÓÃAmetys_CMSµÄauto-completion²å¼þ´æÔÚµÄÐÅϢй¶·ì϶£¬£¬£¬£¬£¬£¬ÇÔÈ¡Ö÷ÕÅÖ÷»úIPµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£AmetysCmsÊÇÓÃÓÚÔÚͳһ̨·þÎñÆ÷ÉÏÔËÐдóÐÍÆóÒµÍøÕ¾£¬£¬£¬£¬£¬£¬²©¿Í£¬£¬£¬£¬£¬£¬IntranetºÍExtranet¡£¡£¡£¡£¡£¡£¡£¡££¨Ametys£©ÉçÇøµÄCmsÒ»¸öÓÃJava±àдµÄÃâ·Ñ¿ªÔ´ÄÚÈÝÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230321

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Confluence[CVE-2021-26084][CNNVD-202108-2421]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

AtlassianConfluenceÊÇAtlassian¹«Ë¾³öÆ·µÄרҵµÄÆóҵ֪ʶÖÎÀíÓëЭͬÈí¼þ£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ¹¹½¨ÆóÒµÎÄ¿âµÈ¡£¡£¡£¡£¡£¡£¡£¡£ConfluenceServerºÍConfluenceDataCenter(<6.13.23¡¢<7.11.6¡¢<7.12.5¡¢<7.4.11°æ±¾)ÉÏ´æÔÚÒ»¸öOGNL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤»òÔÚijЩÇé¿öÏÂδÊÚȨµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬£¬ÔÚConfluenceServer»òConfluenceDataCenterÊ·ýÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Apache_AXIS[CVE-2019-0227]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·Ô̺¬ÁËJavaºÍC++˵»°ÊµÏÖµÄSOAP·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÒÔ¼°¸÷À๫Ó÷þÎñ¼°API£¬£¬£¬£¬£¬£¬ÒÔÌìÉúºÍ²¿ÊðWeb·þÎñÀûÓᣡ£¡£¡£¡£¡£¡£¡£·ì϶ÐÔÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÅäÖÃÃýÎ󡣡£¡£¡£¡£¡£¡£¡£µ±enableRemoteAdminÊôÐÔÉèÖÃΪtrueʱ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»»ú¹ØWebServiceŲÓÃfreemarker×é¼þÖеÄtemplate.utility.ExecuteÀ࣬£¬£¬£¬£¬£¬Ô¶³ÌÀûÓÃAdminService½Ó¿Ú½øÐÐWebService°ä²¼£¬£¬£¬£¬£¬£¬ÔٴνӼûÌìÉúµÄWebService½Ó¿Ú£¬£¬£¬£¬£¬£¬´«ÈëÒªÖ´ÐеĺÅÁ£¬£¬£¬£¬£¬¾ÍÄܹ»½øÐÐÔ¶³ÌºÅÁîÖ´Ðзì϶µÄÀûÓᣡ£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

TCP_·ì϶ÀûÓÃ_δÊÚȨ½Ó¼û_Hadoop_Yarn_RPC

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃHadoopYarnµÄ·ì϶½øÐÐδÊÚȨ½Ó¼û£»£»£»£»£»¶ÔÓÚ8032¶³öÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬£¬£¬£¬£¬£¬±àдÀûÓ÷¨Ê½Å²ÓÃyarnClient.getApplications()¼´¿É²é¿´ËùÓÐÀûÓÃÐÅÏ¢£»£»£»£»£»Hadoop×÷Ϊһ¸öÉ¢²¼Ê½ÍÆËãÀûÓÿò¼Ü£¬£¬£¬£¬£¬£¬ÖÖÀàÖ°ÄÜ·±¶à£¬£¬£¬£¬£¬£¬¶øHadoopYarn×÷ΪÆäÖ÷Ìâ×é¼þÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230321