ÿÖÜÉý¼¶Í¨¸æ-2022-10-11

Ðû²¼Ê±¼ä 2022-10-11

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_Dolibarr_ERP-CRM_8.0.4_rowid_SQL×¢Èë

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃDolibarrEPR-CRM8.0.4ÒÔ¼°Ö®Ç°°æ±¾±£´æµÄsql×¢ÈëÎó²î£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳÊý¾Ý¿âÖеÄÐÅÏ¢¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Redis_v4.x-v5.x_Ô¶³ÌÏÂÁîÖ´ÐÐ1

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Redis4.x¡¢5.x°æ±¾ÖУ¬£¬ £¬£¬£¬£¬£¬ÌṩÁËÖ÷´Óģʽ¡£¡£¡£¡£Ö÷´ÓģʽָʹÓÃÒ»¸öredis×÷ΪÖ÷»ú£¬£¬ £¬£¬£¬£¬£¬ÆäËûµÄ×÷Ϊ±¸·Ý»ú£¬£¬ £¬£¬£¬£¬£¬Ö÷»ú´Ó»úÊý¾Ý¶¼ÊÇÒ»ÑùµÄ£¬£¬ £¬£¬£¬£¬£¬´Ó»úÖ»ÈÏÕæ¶Á£¬£¬ £¬£¬£¬£¬£¬Ö÷»úÖ»ÈÏÕæÐ´¡£¡£¡£¡£ÔÚReids4.xÖ®ºó£¬£¬ £¬£¬£¬£¬£¬Í¨¹ýÍâ²¿ÍØÕ¹£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔʵÏÖÔÚredisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁ£¬ £¬£¬£¬£¬£¬½á¹¹¶ñÒâ.soÎļþ¡£¡£¡£¡£ÔÚÁ½¸öRedisʵÀýÉèÖÃÖ÷´ÓģʽµÄʱ¼ä£¬£¬ £¬£¬£¬£¬£¬RedisµÄÖ÷»úʵÀý¿ÉÒÔͨ¹ýFULLRESYNCͬ²½Îļþµ½´Ó»úÉÏ¡£¡£¡£¡£È»ºóÔÚ´Ó»úÉϼÓÔØ¶ñÒâsoÎļþ£¬£¬ £¬£¬£¬£¬£¬¼´¿ÉÖ´ÐÐÏÂÁî¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Redis_v4.x-v5.x_Ô¶³ÌÏÂÁîÖ´ÐÐ2

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Redis4.x¡¢5.x°æ±¾ÖУ¬£¬ £¬£¬£¬£¬£¬ÌṩÁËÖ÷´Óģʽ¡£¡£¡£¡£Ö÷´ÓģʽָʹÓÃÒ»¸öredis×÷ΪÖ÷»ú£¬£¬ £¬£¬£¬£¬£¬ÆäËûµÄ×÷Ϊ±¸·Ý»ú£¬£¬ £¬£¬£¬£¬£¬Ö÷»ú´Ó»úÊý¾Ý¶¼ÊÇÒ»ÑùµÄ£¬£¬ £¬£¬£¬£¬£¬´Ó»úÖ»ÈÏÕæ¶Á£¬£¬ £¬£¬£¬£¬£¬Ö÷»úÖ»ÈÏÕæÐ´¡£¡£¡£¡£ÔÚReids4.xÖ®ºó£¬£¬ £¬£¬£¬£¬£¬Í¨¹ýÍâ²¿ÍØÕ¹£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔʵÏÖÔÚredisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁ£¬ £¬£¬£¬£¬£¬½á¹¹¶ñÒâ.soÎļþ¡£¡£¡£¡£ÔÚÁ½¸öRedisʵÀýÉèÖÃÖ÷´ÓģʽµÄʱ¼ä£¬£¬ £¬£¬£¬£¬£¬RedisµÄÖ÷»úʵÀý¿ÉÒÔͨ¹ýFULLRESYNCͬ²½Îļþµ½´Ó»úÉÏ¡£¡£¡£¡£È»ºóÔÚ´Ó»úÉϼÓÔØ¶ñÒâsoÎļþ£¬£¬ £¬£¬£¬£¬£¬¼´¿ÉÖ´ÐÐÏÂÁî¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Drogon_framework_СÓÚ1.75_í§ÒâÎļþÉÏ´«[CVE-2022-25297]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

DrogonframeworkÊÇÒ»¸ö»ùÓÚC++14/17µÄHTTPÓ¦ÓóÌÐò¿ò¼Ü£¬£¬ £¬£¬£¬£¬£¬Ð¡ÓÚ1.75°æ±¾Ê±ÈÝÒ×Êܵ½í§ÒâÎļþдÈëµÄÓ°Ïì¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚÔÚÉÏ´«Àú³ÌÖжÔÎļþÃûµÄ²»Çå¾²´¦Öóͷ£¿ÉÄÜʹ¹¥»÷ÕßÄܹ»½«ÎļþдÈëÖ¸¶¨Ä¿µÄÎļþ¼ÐÖ®ÍâµÄí§ÒâλÖᣡ£¡£¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ColdFusion_Îļþ¶ÁÈ¡[CVE-2010-2861]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

AdobeColdFusionÊÇÒ»¸ö¶¯Ì¬WebЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬£¬ÆäËù½ÓÄɵÄCFML(ColdFusionMarkupLanguage)³ÌÐòÉè¼ÆÓïÑÔÀàËÆ"107" style="border-right: 1px solid windowtext; border-bottom: 1px solid windowtext; border-left: 1px solid windowtext; border-image: initial; border-top: none; background: white; padding: 0px 7px;">

¸üÐÂʱ¼ä£º20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Bitbucket_Server_ÏÂÁîÖ´ÐÐ[CVE-2022-36804]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

AtlassianBitbucketServerºÍDataCenter7.0.07.6.17֮ǰµÄ¶à¸öAPI¶Ëµã£¬£¬ £¬£¬£¬£¬£¬7.17.10֮ǰµÄ°æ±¾7.7.0£¬£¬ £¬£¬£¬£¬£¬7.21.4֮ǰµÄ°æ±¾7.18.0£¬£¬ £¬£¬£¬£¬£¬8.0֮ǰµÄ°æ±¾8.0.0¡£¡£¡£¡£3£¬£¬ £¬£¬£¬£¬£¬´Ó°æ±¾8.1.0µ½°æ±¾8.1.3£¬£¬ £¬£¬£¬£¬£¬´Ó°æ±¾8.2.0µ½°æ±¾8.2.2£¬£¬ £¬£¬£¬£¬£¬´Ó°æ±¾8.3.0µ½8.3.1ÔÊÐíÔ¶³Ì¹¥»÷Õß¶Ô¹«¹²»ò˽ÓÐBitbucket´æ´¢¿â¾ßÓжÁȡȨÏÞÖ´ÐÐͨ¹ý·¢ËͶñÒâHTTPÇëÇóµÄí§Òâ´úÂë

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

ICMP_ºóÃÅ_Bvp47_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

Bvp47ÊÇ·½³Ìʽ×éÖ¯µÄ¶¥¼¶LinuxºóÃÅ£¬£¬ £¬£¬£¬£¬£¬·½³Ìʽ×éÖ¯ÊÇÌìϳ¬Ò»Á÷µÄÍøÂç¹¥»÷×éÖ¯£¬£¬ £¬£¬£¬£¬£¬ÆÕ±éÒÔΪÁ¥ÊôÓÚÃÀ¹ú¹ú¼ÒÇå¾²¾ÖNSA¡£¡£¡£¡£Bvp47ͨ¹ýÔÚµÚÒ»¸öSYN°üÖмдøÊý¾ÝµÄ·½·¨À´ÌÓ±ÜÍøÂçÇå¾²×°±¸µÄ¼ì²â¡£¡£¡£¡£Bvp47ʵÏÖ°üÀ¨ÁËÖØ´óµÄ´úÂë¡¢Çø¶Î¼Ó½âÃÜ£¬£¬ £¬£¬£¬£¬£¬Linux¶à°æ±¾Æ½Ì¨ÊÊÅ䣬£¬ £¬£¬£¬£¬£¬¸»ºñµÄrootkit·´×·×Ù¼¼ÇÉ¡£¡£¡£¡£×îÖ÷ÒªµÄÊǼ¯³ÉÁׯ߼¶Òþ²ØÐŵÀÖÐËùʹÓõÄBPFÒýÇæ¸ß¼¶Ê¹Óü¼ÇÉ£¬£¬ £¬£¬£¬£¬£¬ÒÔ¼°·±ËöµÄͨѶ¼Ó½âÃÜÁ÷³Ì¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-35491/CVE-2020-36179/CVE-2020-36181/CVE-2020-36183/CVE-2020-36186]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJackson<2.9.9.2ÒÔ¼°>=2.0.0,<=2.9.10.7°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬£¬ £¬£¬£¬£¬£¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_WebLogic·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2018-3191]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼʹÓÃWebLogic12.2.1.3¼°Ö®Ç°µÄ°æ±¾±£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£WeblogicÊÇÏÖÔÚÈ«ÇòÊг¡ÉÏÓ¦ÓÃ×îÆÕ±éµÄJ2EE¹¤¾ßÖ®Ò»£¬£¬ £¬£¬£¬£¬£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÓ¦ÓóÌÐòЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦ÓóÌÐò£¬£¬ £¬£¬£¬£¬£¬Ö§³Öй¦Ð§£¬£¬ £¬£¬£¬£¬£¬¿É½µµÍÔËÓª±¾Ç®£¬£¬ £¬£¬£¬£¬£¬Ìá¸ßÐÔÄÜ£¬£¬ £¬£¬£¬£¬£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£¡£¡£¡£T3ЭÒéÊÇÓÃÓÚWeblogicЧÀÍÆ÷ºÍÆäËûJavaApplicationÖ®¼ä´«ÊäÐÅÏ¢µÄЭÒ飬£¬ £¬£¬£¬£¬£¬ÊÇʵÏÖRMIÔ¶³ÌÀú³ÌŲÓõÄרÓÐЭÒ飬£¬ £¬£¬£¬£¬£¬ÆäÔÊÐí¿Í»§¶Ë¾ÙÐÐJNDIŲÓᣡ£¡£¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Redis_v4.x-v5.x_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Redis4.x¡¢5.x°æ±¾ÖУ¬£¬ £¬£¬£¬£¬£¬ÌṩÁËÖ÷´Óģʽ¡£¡£¡£¡£Ö÷´ÓģʽָʹÓÃÒ»¸öredis×÷ΪÖ÷»ú£¬£¬ £¬£¬£¬£¬£¬ÆäËûµÄ×÷Ϊ±¸·Ý»ú£¬£¬ £¬£¬£¬£¬£¬Ö÷»ú´Ó»úÊý¾Ý¶¼ÊÇÒ»ÑùµÄ£¬£¬ £¬£¬£¬£¬£¬´Ó»úÖ»ÈÏÕæ¶Á£¬£¬ £¬£¬£¬£¬£¬Ö÷»úÖ»ÈÏÕæÐ´¡£¡£¡£¡£ÔÚReids4.xÖ®ºó£¬£¬ £¬£¬£¬£¬£¬Í¨¹ýÍâ²¿ÍØÕ¹£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔʵÏÖÔÚredisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁ£¬ £¬£¬£¬£¬£¬½á¹¹¶ñÒâ.soÎļþ¡£¡£¡£¡£ÔÚÁ½¸öRedisʵÀýÉèÖÃÖ÷´ÓģʽµÄʱ¼ä£¬£¬ £¬£¬£¬£¬£¬RedisµÄÖ÷»úʵÀý¿ÉÒÔͨ¹ýFULLRESYNCͬ²½Îļþµ½´Ó»úÉÏ¡£¡£¡£¡£È»ºóÔÚ´Ó»úÉϼÓÔØ¶ñÒâsoÎļþ£¬£¬ £¬£¬£¬£¬£¬¼´¿ÉÖ´ÐÐÏÂÁî¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_ÍøÂçɨÃè_Netsparker_WEBÎó²îɨÃè

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃNetsparker¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐwebÓ¦ÓÃÇå¾²Îó²îɨÃèµÄÐÐΪ¡£¡£¡£¡£NetsparkerÊÇÒ»¿î×ÛºÏÐ͵ÄwebÓ¦ÓÃÇå¾²Îó²îɨÃ蹤¾ß,ËüÄܹ»¸üºÃµÄ¼ì²âSQLInjectionºÍCross-siteScriptingÀàÐ͵ÄÇå¾²Îó²î¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÄܻᵼÖÂϵͳй¶ijЩÃô¸ÐÐÅÏ¢¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Sanic_static_Îļþ¶ÁÈ¡

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP¶ÔÄ¿µÄIPµÄSanic¾ÙÐй¥»÷µÄÐÐΪ.SanicÒ»¸ö»ùÓÚPython3.5+µÄÒì²½(asyncio+uvloop)web¿ò¼Ü£¬£¬ £¬£¬£¬£¬£¬ÓëFlaskÓеãÏàËÆ¡£¡£¡£¡£´¦Öóͷ£ËÙÂʿ죬£¬ £¬£¬£¬£¬£¬Ó¦ÓÃÆÕ±é¡£¡£¡£¡£ÔÊÐí¶ÁÈ¡í§ÒâÎļþ

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÐÅϢй¶_DedeCMSÖÎÀíĿ¼ö¾Ù_Ãô¸ÐÐÅϢй¶

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»úÌᳫDedeCMSÖÎÀíĿ¼ö¾ÙÎó²î¹¥»÷µÄÐÐΪ¡£¡£¡£¡£DedeCMSÊÇÊ¢ÐеÄPHP¿ªÔ´ÍøÕ¾ÖÎÀíϵͳ¡£¡£¡£¡£Í¨³£DedeCMSÍøÕ¾ÔÚ×°ÖúóÖÎÀíÔ±»áÐ޸ĺǫ́ÖÎÀíĿ¼Ϊһ¸öÌØÊâµÄ×Ö·û´®£¬£¬ £¬£¬£¬£¬£¬±ÜÃâ¹¥»÷Õß´ÓÍⲿÕÒµ½ºǫ́ÖÎÀíĿ¼¡£¡£¡£¡£DedeCMSV5.7SP2×îа汾¼°ÒÔǰ°æ±¾±£´æÖÎÀíĿ¼ö¾ÙÎó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýWindows²Ù×÷ÏµÍ³ÌØÕ÷¼¼ÇÉÐԵı©Á¦Ã¶¾ÙÖÎÀíºǫ́Ŀ¼¡£¡£¡£¡£ÊµÑ鱩Á¦Ã¶¾ÙÖÎÀíĿ¼¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_php·´ÐòÁл¯Ð¡Âí_ÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄipÉÏ´«php·´ÐòÁл¯µÄwebshellÎļþ£¬£¬ £¬£¬£¬£¬£¬¸ÃÎļþͨ³£°üÀ¨·´ÐòÁл¯destruct()º¯Êý£¬£¬ £¬£¬£¬£¬£¬ºÍÖ´ÐÐÏÂÁîµÄassert.()º¯Êý¡£¡£¡£¡£ÉÏ´«Àֳɺóµ¼ÖÂí§Òâ´úÂëÖ´ÐС¢Ð§ÀÍÆ÷±»½ÓÊܵÈЧ¹û¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Atlassian_Crowd_Ô¶³ÌÏÂÁîÖ´ÐÐ[CNNVD-201905-1031]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´Ö÷»úIPÕýÔÚʹÓÃÄ¿µÄIPÖ÷»úÉÏAtlassian-CrowdÉÏ¡°/crowd/plugins/servlet/cdl¡±´¦µÄ´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬£¬£¬£¬½á¹¹¶ñÒâÏÂÁ£¬ £¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬¼°Ð§ÀÍÆ÷ȨÏÞ¡£¡£¡£¡£AtlassianCrowdÊÇÒ»Ì×»ùÓÚWebµÄµ¥µãµÇ¼ϵͳ¡£¡£¡£¡£¸ÃϵͳΪ¶àÓû§¡¢ÍøÂçÓ¦ÓóÌÐòºÍĿ¼ЧÀÍÆ÷ÌṩÑéÖ¤¡¢ÊÚȨµÈ¹¦Ð§¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9546/9547/9548]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉÏJACKSONµÄºÚÃûµ¥¾ÖÏÞ£¬£¬ £¬£¬£¬£¬£¬Í¨¹ýshiro-coreÀà´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ²Ù×÷¡£¡£¡£¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ½¹µã×é¼þÖ®Ò»¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Ruby_On_Rails_ÏÂÁîÖ´ÐÐ[CVE-2020-8163][CNNVD-202005-856]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃRuby_On_RailsµÄsystemÒ³Ãæ£¬£¬ £¬£¬£¬£¬£¬½á¹¹¶ñÒâ´úÂ룬£¬ £¬£¬£¬£¬£¬Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£RailsÓÐÒ»¸öÃûΪrenderµÄAPI£¬£¬ £¬£¬£¬£¬£¬Ëü¿ÉÒÔÉÁ¿ª·¢Ö°Ô±Ñ¡ÕªÒª·ºÆðÄÚÈݵÄÄ£°å¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬ £¬£¬£¬£¬£¬»¹¿ÉÒÔת´ïÒ»¸ölocalsÊý×飬£¬ £¬£¬£¬£¬£¬½«¸ü¶àµÄ±äÁ¿ÏòÏÂת´ï¸øÄ£°å×Ô¼º£¬£¬ £¬£¬£¬£¬£¬Àû±ãÄúÀ©Õ¹Ä£°åµÄÎÞаÐÔ£¬£¬ £¬£¬£¬£¬£¬ÉõÖÁʹÆä¹¦Ð§¸üǿʢ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jackson·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14060][CNNVD-202006-997]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý½á¹¹¶ñÒâµÄoadd.org.apache.xalan.lib.sql.JNDIConnectionPoolÀàjsonÐòÁл¯×Ö·û´®£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jackson_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14062][CNNVD-202006-996]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý¶ñÒâµÄcom.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPoolÀàjsonÐòÁл¯×Ö·û´®»ñȡĿµÄϵͳµÄȨÏÞ

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jackson·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14195][CNNVD-202006-1070]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý½á¹¹¶ñÒâµÄorg.jsecurity.realm.jndi.JndiRealmFactoryÀàjsonÐòÁл¯×Ö·û´®Ôì³É´úÂëÖ´ÐУ¬£¬ £¬£¬£¬£¬£¬´Ó¶ø¿ØÖÆÄ¿µÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jackson·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-14540][CNNVD-201909-716]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJackson2.9.10°æ±¾Ö®Ç°±£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý½á¹¹¶ñÒâµÄcom.zaxxer.hikari.HikariConfigÀàjsonÐòÁл¯Êý¾Ý¾ÙÐÐjndi×¢Èë¹¥»÷£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SangforEDR_cssp_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÐÅ·þ¹«Ë¾ÌṩµÄÒ»Ì×ÖÕ¶ËÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£´Ë²úÆ·±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨ÏÂÁî×¢È룩£¬£¬ £¬£¬£¬£¬£¬Î´¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆÇëÇó°ü£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔì³ÉÔ¶³ÌÖ´ÐÐÏÂÁîµÄЧ¹û¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-12384][CNNVD-201906-867]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ½¹µã×é¼þÖ®Ò»¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚJacksonºÚÃûµ¥¹ýÂ˲»ÍêÕû¶øµ¼Ö£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õ߿ɽṹ°üÀ¨ÓжñÒâ´úÂëµÄjsonÊý¾Ý°ü¶ÔÓ¦ÓþÙÐй¥»÷£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¹¥»÷Àֳɣ¬£¬ £¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221011