ÿÖÜÉý¼¶Í¨¸æ-2023-03-21

Ðû²¼Ê±¼ä 2023-03-21
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_SSRF_Microsoft_Exchange_ProxyLogon_ɨÃè[CVE-2021-26855][CNNVD-202103-192][CVE-2021-26855]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

MicrosoftExchangeÖаüÀ¨ÁËÊý¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎÏ£¬£¬£¬£¬£¬ £¬¿ÉÒÔͨ¹ýÁ¬ÏµÊ¹ÓÃÊý¸öÎó²îÀ´ÈƹýExchangeǰ¶ËºÍÉí·ÝÏÞÖÆ£¬£¬£¬£¬£¬ £¬ÉÏ´«¶ñÒâÎļþµ½ExchangeЧÀÍÆ÷ÉÏ£¬£¬£¬£¬£¬ £¬¸ÃÎó²îÁ´¼´±»³ÆÎªProxyLogon£¬£¬£¬£¬£¬ £¬¸ÃÊÂÎñ¼ì²â¶ÔÆäÖеÄSSRFÎó²îɨÃèÐÐΪ£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎó²îÌáÉýȨÏÞ²¢Ö±½Ó»á¼ûºó¶Ë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÏÂÁîÖ´ÐÐ_Bitbucket-Server&Data-Center_ÇéÐαäÁ¿×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ö÷»úÕýÔÚÊܵ½Bitbucket-Server&Data-CenterÇéÐαäÁ¿×¢È룬£¬£¬£¬£¬ £¬¿Éµ¼ÖÂí§ÒâÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇͨ¹ýÇéÐαäÁ¿Òý·¢µÄÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬ £¬¿Éµ¼Ö¾ßÓÐȨÏ޵Ĺ¥»÷Õß¿ØÖÆÓû§Ãû£¬£¬£¬£¬£¬ £¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£×÷ΪÔÝʱ»º½â²½·¥£¬£¬£¬£¬£¬ £¬Atlassian¹«Ë¾½¨ÒéÓû§¹Ø±Õ¡°¹ûÕæ×¢²á¡±Ñ¡Ïî¡£¡£¡£¡£¡£¡£Ç徲ͨ¸æÖ¸³ö£¬£¬£¬£¬£¬ £¬¡°½ûÓùûÕæ×¢²á½«Ê¹¹¥»÷ÏòÁ¿´ÓδÈÏÖ¤¹¥»÷¸ü¸ÄΪÈÏÖ¤¹¥»÷£¬£¬£¬£¬£¬ £¬´Ó¶ø½µµÍʹÓÃΣº¦¡£¡£¡£¡£¡£¡£¾­ÖÎÀíÔ±»òϵͳÖÎÀíÔ±ÈÏÖ¤µÄÓû§Äܹ»ÔÚ½ûÓùûÕæ×¢²áÑ¡ÏîʱʹÓøÃÎó²î¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_Ç徲Σº¦_¿ÉÒÉÐÐΪ_esi±êÇ©ÇëÇó

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

EdgeSideIncludes(ESI)ÊÇÒ»ÖÖ±ê¼ÇÓïÑÔ£¬£¬£¬£¬£¬ £¬Ö÷ÒªÔÚ³£¼ûµÄHTTPÊðÀí£¨·´ÏòÊðÀí¡¢¸ºÔØÆ½ºâ¡¢»º´æÐ§ÀÍÆ÷¡¢ÊðÀíЧÀÍÆ÷£©ÖÐʹÓᣡ£¡£¡£¡£¡£Í¨¹ýESI×¢ÈëÊÖÒÕ¿ÉÒÔµ¼ÖÂЧÀͶËÇëÇóαÔ죨SSRF£©£¬£¬£¬£¬£¬ £¬ÈƹýHTTPOnlycookieµÄ¿çÕ¾¾ç±¾¹¥»÷£¨XSS£©ÒÔ¼°Ð§ÀͶ˾ܾøÐ§À͹¥»÷¡£¡£¡£¡£¡£¡£Í¨¹ý²âÊÔ£¬£¬£¬£¬£¬ £¬Óм¸Ê®ÖÖÖ§³Ö´¦Öóͷ£ESIµÄ²úÆ·£ºVarnish£¬£¬£¬£¬£¬ £¬SquidProxy£¬£¬£¬£¬£¬ £¬IBMWebSphere£¬£¬£¬£¬£¬ £¬OracleFusion/WebLogic£¬£¬£¬£¬£¬ £¬Akamai£¬£¬£¬£¬£¬ £¬Fastly£¬£¬£¬£¬£¬ £¬F5£¬£¬£¬£¬£¬ £¬Node.jsESI£¬£¬£¬£¬£¬ £¬LiteSpeedºÍÒ»Ð©ÌØ¶¨ÓïÑÔ²å¼þ£¬£¬£¬£¬£¬ £¬µ«²¢²»ÊÇÕâЩ²úƷĬÈÏÆôÓÃÁËESI¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_RichFaces[CVE-2018-14667]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

RichFacesÊÇÒ»¸ö»ùÓÚLGPLЭÒ鿪·ÅÔ´´úÂëµÄJSF£¨JavaServerFaces£©×é¼þ¿â£¬£¬£¬£¬£¬ £¬ËüÄܹ»Ê¹Ó¦Óÿª·¢Àû±ãµØ¼¯³ÉAJAX¡£¡£¡£¡£¡£¡£ÏÖÔÚµÄRichFaces¿âÊÇÓÉAjax4jsfºÍRichFacesÁ½²¿·Ö×é³É¡£¡£¡£¡£¡£¡£JavaRichFaces¿ò¼ÜÖаüÀ¨Ò»¸öRCEÎó²î,¹¥»÷Õ߿ɽṹ°üÀ¨org.ajax4jsf.resource.UserResource$UriDataÐòÁл¯¹¤¾ßµÄÌØ¶¨UserResourceÇëÇ󣬣¬£¬£¬£¬ £¬RichFaces»áÏÈ·´ÐòÁл¯¸ÃUriData¹¤¾ß£¬£¬£¬£¬£¬ £¬È»ºóʹÓÃEL±í´ïʽÆÊÎö²¢»ñÈ¡resourceµÄmodified¡¢expiresµÈÖµµ¼ÖÂÁËí§ÒâEL±í´ïʽִÐУ¬£¬£¬£¬£¬ £¬Í¨¹ý½á¹¹ÌØÊâµÄEL±í´ïʽ¿ÉʵÏÖÔ¶³Ìí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Õã½­ÓîÊӿƼ¼ÍøÂçÊÓÆµÂ¼Ïñ»ú_LogReport.php

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÕýÔÚʹÓÃÕã½­ÓîÊӿƼ¼ÍøÂçÊÓÆµÂ¼Ïñ»úµÄÎó²î¾ÙÐдúÂëÖ´Ðй¥»÷£»£» £»

¸üÐÂʱ¼ä£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÐÅϢй¶_Ametys_auto-completion_plugin[CVE-2022-26159]

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÕýÔÚʹÓÃAmetys_CMSµÄauto-completion²å¼þ±£´æµÄÐÅϢй¶Îó²î£¬£¬£¬£¬£¬ £¬ÇÔȡĿµÄÖ÷»úIPµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£AmetysCmsÊÇÓÃÓÚÔÚͳһ̨ЧÀÍÆ÷ÉÏÔËÐдóÐÍÆóÒµÍøÕ¾£¬£¬£¬£¬£¬ £¬²©¿Í£¬£¬£¬£¬£¬ £¬IntranetºÍExtranet¡£¡£¡£¡£¡£¡££¨Ametys£©ÉçÇøµÄCmsÒ»¸öÓÃJava±àдµÄÃâ·Ñ¿ªÔ´ÄÚÈÝÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230321

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Confluence[CVE-2021-26084][CNNVD-202108-2421]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

AtlassianConfluenceÊÇAtlassian¹«Ë¾³öÆ·µÄרҵµÄÆóҵ֪ʶÖÎÀíÓëЭͬÈí¼þ£¬£¬£¬£¬£¬ £¬¿ÉÓÃÓÚ¹¹½¨ÆóÒµÎÄ¿âµÈ¡£¡£¡£¡£¡£¡£ConfluenceServerºÍConfluenceDataCenter(<6.13.23¡¢<7.11.6¡¢<7.12.5¡¢<7.4.11°æ±¾)Éϱ£´æÒ»¸öOGNL×¢ÈëÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤»òÔÚijЩÇéÐÎÏÂδÊÚȨµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬ £¬ÔÚConfluenceServer»òConfluenceDataCenterʵÀýÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Apache_AXIS[CVE-2019-0227]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWebЧÀͼܹ¹¡£¡£¡£¡£¡£¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAPЧÀÍÆ÷£¬£¬£¬£¬£¬ £¬ÒÔ¼°ÖÖÖÖ¹«ÓÃЧÀͼ°API£¬£¬£¬£¬£¬ £¬ÒÔÌìÉúºÍ°²ÅÅWebЧÀÍÓ¦Óᣡ£¡£¡£¡£¡£Îó²îʵÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÉèÖùýʧ¡£¡£¡£¡£¡£¡£µ±enableRemoteAdminÊôÐÔÉèÖÃΪtrueʱ£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒԽṹWebServiceŲÓÃfreemarker×é¼þÖеÄtemplate.utility.ExecuteÀ࣬£¬£¬£¬£¬ £¬Ô¶³ÌʹÓÃAdminService½Ó¿Ú¾ÙÐÐWebServiceÐû²¼£¬£¬£¬£¬£¬ £¬Ôٴλá¼ûÌìÉúµÄWebService½Ó¿Ú£¬£¬£¬£¬£¬ £¬´«ÈëÒªÖ´ÐеÄÏÂÁ£¬£¬£¬£¬ £¬¾Í¿ÉÒÔ¾ÙÐÐÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îµÄʹÓᣡ£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230321

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_δÊÚȨ»á¼û_Hadoop_Yarn_RPC

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃHadoopYarnµÄÎó²î¾ÙÐÐδÊÚȨ»á¼û£»£» £»¹ØÓÚ8032̻¶ÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬£¬£¬£¬£¬ £¬±àдӦÓóÌÐòŲÓÃyarnClient.getApplications()¼´¿ÉÉó²éËùÓÐÓ¦ÓÃÐÅÏ¢£»£» £»Hadoop×÷Ϊһ¸öÂþÑÜʽÅÌËãÓ¦Óÿò¼Ü£¬£¬£¬£¬£¬ £¬ÖÖÀ๦Ч·±¶à£¬£¬£¬£¬£¬ £¬¶øHadoopYarn×÷ΪÆä½¹µã×é¼þÖ®Ò»¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230321