ÿÖÜÉý¼¶Í¨¸æ-2022-10-25

Ðû²¼Ê±¼ä 2022-10-25

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_PropertyPathFactoryBean_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLµÄPropertyPathFactoryBean·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷ £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_DefaultBeanFactoryPointcutAdvisor_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLµÄDefaultBeanFactoryPointcutAdvisor·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷ £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_CommonsConfiguration_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLµÄCommonsConfiguration·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷ £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Grafana_8.3.0_Îļþ¶ÁÈ¡[CVE-2021-43798][CNNVD-202112-482]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃGrafana8.0.0-8.3.0°æ±¾Öб£´æµÄÎļþ¶ÁÈ¡Îó²î £¬£¬£¬ £¬£¬´Ó¶øÔÚδÊÚȨµÄÇéÐÎ϶ÁȡĿµÄϵͳÃô¸ÐÎļþ¡£¡£¡£¡£¡£GrafanaÊÇÒ»¸ö¿çƽ̨¡¢¿ªÔ´µÄÊý¾Ý¿ÉÊÓ»¯ÍøÂçÓ¦ÓóÌÐòƽ̨¡£¡£¡£¡£¡£Óû§ÉèÖÃÅþÁ¬µÄÊý¾ÝÔ´Ö®ºó £¬£¬£¬ £¬£¬Grafana¿ÉÒÔÔÚÍøÂçä¯ÀÀÆ÷ÀïÏÔʾÊý¾Ýͼ±íºÍÖÒÑÔ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_HTTP_ɨÃè

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓöÔÄ¿µÄÖ÷»úÊÔͼͨ¹ýNMAP»ñÈ¡¶ÔÓ¦Ö÷»úhttpЧÀÍÆ÷°æ±¾ºÍ¶ÔÓ¦³§É̵ÄÐÐΪ¡£¡£¡£¡£¡£Õâ¿ÉÄܻᵼÖÂϵͳй¶Ïà¹ØÐÅÏ¢¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_FortiOS_7.2.1_ȨÏÞÈÆ¹ý[CVE-2022-40684][CNNVD-202210-347]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFortiOS7.2.1¼°ÒÔϰ汾 £¬£¬£¬ £¬£¬FortiProxy7.2.0¼°ÒÔϰ汾 £¬£¬£¬ £¬£¬FortiSwitchManager7.2.0¼°ÒÔϰ汾Öб£´æµÄȨÏÞÈÆ¹ýÎó²î £¬£¬£¬ £¬£¬ÔÚδÊÚȨµÄÇéÐÎÏÂÐÞ¸ÄÓû§µÄssh¹«Ô¿ £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âʹÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐÐʹÓÃÁ´±©ÆÆ¹¥»÷¡£¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü £¬£¬£¬ £¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025

 

ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Struts2_S2-032_´úÂëÖ´ÐÐ[CVE-2016-3081]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃStruts2.3.20-StrutsStruts2.3.28(2.3.20.3ºÍ2.3.24.3³ýÍâ)Öб£´æµÄ´úÂëÖ´ÐÐÎó²î £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£Struts2ÊÇÒ»¸ö¾«Á·µÄ¡¢¿ÉÀ©Õ¹µÄ¿ò¼Ü £¬£¬£¬ £¬£¬¿ÉÓÃÓÚ½¨ÉèÆóÒµ¼¶JavawebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£Éè¼ÆÕâ¸ö¿ò¼ÜÊÇΪÁË´Ó¹¹½¨¡¢°²ÅÅ¡¢µ½Ó¦ÓóÌÐòά»¤·½ÃæÀ´¼ò»¯Õû¸ö¿ª·¢ÖÜÆÚ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_Weblogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2801]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃOracleWeblogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î £¬£¬£¬ £¬£¬Ê¹ÓÃt3ЭÒé·¢ËͶñÒâµÄÐòÁл¯Êý¾Ý £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£WeblogicÊÇÏÖÔÚÈ«ÇòÊг¡ÉÏÓ¦ÓÃ×îÆÕ±éµÄJ2EE¹¤¾ßÖ®Ò» £¬£¬£¬ £¬£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÓ¦ÓóÌÐòЧÀÍÆ÷ £¬£¬£¬ £¬£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦ÓóÌÐò £¬£¬£¬ £¬£¬Ö§³Öй¦Ð§ £¬£¬£¬ £¬£¬¿É½µµÍÔËÓª±¾Ç® £¬£¬£¬ £¬£¬Ìá¸ßÐÔÄÜ £¬£¬£¬ £¬£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÓÃÓÑNC6.5_XbrlPersistenceServlet_·´ÐòÁл¯_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

¿ÉÒÔÐÐΪ

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNC6.5ÖÐXbrlPersistenceServlet½Ó¿Ú±£´æµÄ·´ÐòÁл¯Îó²î £¬£¬£¬ £¬£¬Ê¹ÓÃURLDNSʹÓÃÁ´Ì½²â¸ÃÎó²îÊÇ·ñ±£´æ¡£¡£¡£¡£¡£ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ £¬£¬£¬ £¬£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-36189¡¢CVE-2020-36188¡¢CVE-2019-14439¡¢CVE-2019-14361]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´® £¬£¬£¬ £¬£¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜʹÓÃjacksonµÄ¿ÉÒÉ·´ÐòÁл¯Ààlogback¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2883]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃWebLogicServer10.3.6.0.0 £¬£¬£¬ £¬£¬12.1.3.0.0 £¬£¬£¬ £¬£¬12.2.1.3.0 £¬£¬£¬ £¬£¬12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ¡£¡£¡£¡£¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplicationserver £¬£¬£¬ £¬£¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖÐÐļþ £¬£¬£¬ £¬£¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀí´óÐÍÂþÑÜʽWebÓ¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦ÓõÄJavaÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£½«JavaµÄ¶¯Ì¬¹¦Ð§ºÍJavaEnterprise±ê×¼µÄÇå¾²ÐÔÒýÈë´óÐÍÍøÂçÓ¦ÓõĿª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀíÖ®ÖС£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-8840][CNNVD-202002-354]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´® £¬£¬£¬ £¬£¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¡£¡£¡£¡£´ËÎó²îÖй¥»÷Õß¿ÉʹÓÃxbean-reflectµÄʹÓÃÁ´´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zabbix_СÓÚ4.4_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃZabbixСÓÚ4.4°æ±¾Öб£´æµÄΪδÊÚȨ»á¼ûÎó²î £¬£¬£¬ £¬£¬´Ó¶øÔÚδ¾­ÊÚȨµÄÇéÐÎÏ»á¼ûZabbixЧÀÍÆ÷ÉϵÄÊý¾Ý £¬£¬£¬ £¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Struts2_S2-055_REST_JacksonLibrary_´úÂëÖ´ÐÐ[CVE-2017-7525]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

TomcatЧÀÍÆ÷ÊÇÒ»¸öÃâ·ÑµÄ¿ª·ÅÔ´´úÂëµÄWebÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£Struts2ÊÇApacheÈí¼þ»ù½ð»áÈÏÕæÎ¬»¤µÄÒ»¿îÓÃÓÚ½¨ÉèÆóÒµ¼¶JavaWebÓ¦ÓõĿªÔ´¿ò¼Ü¡£¡£¡£¡£¡£Struts2ÔÚv2.5-v2.5.14 £¬£¬£¬ £¬£¬¹¥»÷Õßͨ¹ýŲÓÃREST²å¼þÖеı£´æ·´ÐòÁл¯Îó²îµÄJacksonLibraryÀ´´¦Öóͷ£JSONÊý¾Ý £¬£¬£¬ £¬£¬´Ó¶ø´¥·¢·´ÐòÁл¯Îó²î¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÐÅϢй¶_PACSOne_Server_6.6.2_DICOM_Web_Viewer_Ŀ¼±éÀú

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýPACSOneServerÖб£´æµÄĿ¼±éÀúÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúnocache.php¾ç±¾µÄ¡®path¡¯²ÎÊýÖеġ®..¡¯×Ö·ûʹÓøÃÎó²î¶ÁÈ¡í§ÒâÎļþ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡Ãô¸ÐÐÅÏ¢

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ͨ´ïOA_print.php_Îļþɾ³ý

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃͨ´ïOAµÄV11.6¼°ÒÔǰµÄ°æ±¾±£´æµÄÎļþɾ³ýÎó²î¾ÙÐй¥»÷¡£¡£¡£¡£¡£Í¨´ïOAÊÇOfficeAnywhereµÄ¼ò³Æ £¬£¬£¬ £¬£¬¸Ãϵͳ½ÓÄÉÁìÏȵÄB/S(ä¯ÀÀÆ÷/ЧÀÍÆ÷)²Ù×÷·½·¨ £¬£¬£¬ £¬£¬Ê¹µÃÍøÂç°ì¹«²»ÊܵØÇøÏÞ¡£¡£¡£¡£¡£OfficeAnywhere½ÓÄÉ»ùÓÚWEBµÄÆóÒµÅÌËã £¬£¬£¬ £¬£¬Ö÷HTTPЧÀÍÆ÷½ÓÄÉÁËÌìÏÂÉÏ×îÏȽøµÄApacheЧÀÍÆ÷ £¬£¬£¬ £¬£¬ÐÔÄÜÎȹ̿ɿ¿¡£¡£¡£¡£¡£Êý¾Ý´æÈ¡¼¯ÖпØÖÆ £¬£¬£¬ £¬£¬×èÖ¹ÁËÊý¾Ý×ß©µÄ¿ÉÄÜ¡£¡£¡£¡£¡£ÌṩÊý¾Ý±¸·Ý¹¤¾ß £¬£¬£¬ £¬£¬±£»£»£»£»£»¤ÏµÍ³Êý¾ÝÇå¾²¡£¡£¡£¡£¡£¶à¼¶µÄȨÏÞ¿ØÖÆ £¬£¬£¬ £¬£¬ÍêÉÆµÄÃÜÂëÑéÖ¤ÓëµÇ¼ÑéÖ¤»úÖÆÔ½·¢Ç¿ÁËϵͳÇå¾²ÐÔ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14645][CVE-2020-14625][CVE-2020-14644][CVE-2020-14687]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃOracleWebLogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÆäËü¿ÉÒÉÐÐΪ_PHPαЭÒé

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃPHPµÄһЩ·âװЭÒé £¬£¬£¬ £¬£¬Èçphp://input,php://filterµÈÌá½»Ò»¾ä»°Ä¾Âí £¬£¬£¬ £¬£¬»òÔ¶³ÌÖ´ÐÐÏÂÁîÀ´¹¥»÷Êܺ¦ÕßЧÀÍÆ÷ £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-1000353]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î¾ÙÐй¥»÷ £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£JenkinsÊÇÒ»¸ö¿ÉÀ©Õ¹µÄ¿ªÔ´Ò»Á¬¼¯³ÉЧÀÍÆ÷ £¬£¬£¬ £¬£¬ÔÚÐí¶àÆóÒµµÄÄÚÍøÖж¼°²ÅÅÁËÕâ¸öϵͳ¡£¡£¡£¡£¡£Jenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòJenkinsCLIת´ïÐòÁл¯µÄJava¡®SignedObject¡¯¹¤¾ßʹÓøÃÎó²îÈÆ¹ý»ùÓÚºÚÃûµ¥µÄ±£»£»£»£»£»¤»úÖÆ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2015-8103]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJenkins1.637¼°Ö®Ç°°æ±¾¡¢JenkinsLTS1.625.1¼°Ö®Ç°°æ±¾±£´æµÄ·´ÐòÁл¯Îó²î¾ÙÐдúÂëÖ´Ðй¥»÷ £¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄÖ÷»úȨÏÞ¡£¡£¡£¡£¡£JenkinsÊÇÒ»¸ö¿ÉÀ©Õ¹µÄ¿ªÔ´Ò»Á¬¼¯³ÉЧÀÍÆ÷¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JBossMQ_JMS·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-7504][CNNVD-201705-937]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

RedHatJBossApplicationServerÊÇÒ»¿î»ùÓÚJavaEEµÄ¿ªÔ´Ó¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£JBossAS4.x¼°Ö®Ç°°æ±¾ÖÐ £¬£¬£¬ £¬£¬JbossMQʵÏÖÀú³ÌµÄJMSoverHTTPInvocationLayerµÄHTTPServerILServlet.javaÎļþ±£´æ·´ÐòÁл¯Îó²î £¬£¬£¬ £¬£¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÐòÁл¯Êý¾ÝʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON-databind_2670_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-11113][CNNVD-202003-1735]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÏòÄ¿µÄip¾ÙÐз´ÐòÁл¯¹¥»÷£»£»£»£»£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_InfluxDB_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

influxdbÊÇÒ»¿îÖøÃûµÄʱÐòÊý¾Ý¿â £¬£¬£¬ £¬£¬ÆäʹÓÃjwt×÷Ϊ¼øÈ¨·½·¨¡£¡£¡£¡£¡£ÔÚÓû§¿ªÆôÁËÈÏÖ¤ £¬£¬£¬ £¬£¬µ«Î´ÉèÖòÎÊýshared-secretµÄÇéÐÎÏ £¬£¬£¬ £¬£¬jwtµÄÈÏÖ¤ÃÜԿΪ¿Õ×Ö·û´® £¬£¬£¬ £¬£¬´Ëʱ¹¥»÷Õß¿ÉÒÔαÔìí§ÒâÓû§Éí·ÝÔÚinfluxdbÖÐÖ´ÐÐSQLÓï¾ä¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_IncomCMS_2.0_ÎļþÉÏ´«[CVE-2020-29597][CNNVD-202012-431]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

IncomCMS2.0ÒÔ¼°Ö®Ç°µÄ°æ±¾±£´æÎļþÉÏ´«Îó²î £¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔÉÏ´«webshell»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Docker_Remote_API_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃDockerRemoteAPIÉèÖò»µ±Ê±µ¼ÖµÄδÊÚȨ»á¼ûÎó²îdockerclient»òÕßhttpÖ±½ÓÇëÇó»á¼ûÕâ¸öAPI £¬£¬£¬ £¬£¬´Ó¶øÖ±½Ó»á¼ûËÞÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢ £¬£¬£¬ £¬£¬»ò¶ÔÃô¸ÐÎļþ¾ÙÐÐÐÞ¸Ä £¬£¬£¬ £¬£¬×îÖÕÍêÈ«¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£DockerRemoteAPIÊÇÒ»¸öÈ¡´úÔ¶³ÌÏÂÁîÐнçÃæ£¨rcli£©µÄRESTAPI¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ShiroAttack¹¤¾ßʹÓÃ_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷¡£¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü £¬£¬£¬ £¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖÐ £¬£¬£¬ £¬£¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢Èë £¬£¬£¬ £¬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ_ÄÚ´æÂí×¢Èë_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐÐʹÓà £¬£¬£¬ £¬£¬²¢ÔÚÇëÇóÌ崦עÈëÄÚ´æÂí¡£¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü £¬£¬£¬ £¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âʹÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐÐʹÓÃÁ´±©ÆÆ¹¥»÷¡£¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü £¬£¬£¬ £¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025