ÿÖÜÉý¼¶Í¨¸æ-2022-10-11

Ðû²¼Ê±¼ä 2022-10-11

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_Dolibarr_ERP-CRM_8.0.4_rowid_SQL×¢Èë

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃDolibarrEPR-CRM8.0.4ÒÔ¼°Ö®Ç°°æ±¾±£´æµÄsql×¢ÈëÎó²î£¬£¬£¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳÊý¾Ý¿âÖеÄÐÅÏ¢¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Redis_v4.x-v5.x_Ô¶³ÌÏÂÁîÖ´ÐÐ1

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Redis4.x¡¢5.x°æ±¾ÖУ¬£¬£¬£¬£¬ £¬£¬ÌṩÁËÖ÷´Óģʽ¡£¡£¡£¡£¡£ ¡£Ö÷´ÓģʽָʹÓÃÒ»¸öredis×÷ΪÖ÷»ú£¬£¬£¬£¬£¬ £¬£¬ÆäËûµÄ×÷Ϊ±¸·Ý»ú£¬£¬£¬£¬£¬ £¬£¬Ö÷»ú´Ó»úÊý¾Ý¶¼ÊÇÒ»ÑùµÄ£¬£¬£¬£¬£¬ £¬£¬´Ó»úÖ»ÈÏÕæ¶Á£¬£¬£¬£¬£¬ £¬£¬Ö÷»úÖ»ÈÏÕæÐ´¡£¡£¡£¡£¡£ ¡£ÔÚReids4.xÖ®ºó£¬£¬£¬£¬£¬ £¬£¬Í¨¹ýÍâ²¿ÍØÕ¹£¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔʵÏÖÔÚredisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁ£¬£¬£¬£¬ £¬£¬½á¹¹¶ñÒâ.soÎļþ¡£¡£¡£¡£¡£ ¡£ÔÚÁ½¸öRedisʵÀýÉèÖÃÖ÷´ÓģʽµÄʱ¼ä£¬£¬£¬£¬£¬ £¬£¬RedisµÄÖ÷»úʵÀý¿ÉÒÔͨ¹ýFULLRESYNCͬ²½Îļþµ½´Ó»úÉÏ¡£¡£¡£¡£¡£ ¡£È»ºóÔÚ´Ó»úÉϼÓÔØ¶ñÒâsoÎļþ£¬£¬£¬£¬£¬ £¬£¬¼´¿ÉÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Redis_v4.x-v5.x_Ô¶³ÌÏÂÁîÖ´ÐÐ2

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Redis4.x¡¢5.x°æ±¾ÖУ¬£¬£¬£¬£¬ £¬£¬ÌṩÁËÖ÷´Óģʽ¡£¡£¡£¡£¡£ ¡£Ö÷´ÓģʽָʹÓÃÒ»¸öredis×÷ΪÖ÷»ú£¬£¬£¬£¬£¬ £¬£¬ÆäËûµÄ×÷Ϊ±¸·Ý»ú£¬£¬£¬£¬£¬ £¬£¬Ö÷»ú´Ó»úÊý¾Ý¶¼ÊÇÒ»ÑùµÄ£¬£¬£¬£¬£¬ £¬£¬´Ó»úÖ»ÈÏÕæ¶Á£¬£¬£¬£¬£¬ £¬£¬Ö÷»úÖ»ÈÏÕæÐ´¡£¡£¡£¡£¡£ ¡£ÔÚReids4.xÖ®ºó£¬£¬£¬£¬£¬ £¬£¬Í¨¹ýÍâ²¿ÍØÕ¹£¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔʵÏÖÔÚredisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁ£¬£¬£¬£¬ £¬£¬½á¹¹¶ñÒâ.soÎļþ¡£¡£¡£¡£¡£ ¡£ÔÚÁ½¸öRedisʵÀýÉèÖÃÖ÷´ÓģʽµÄʱ¼ä£¬£¬£¬£¬£¬ £¬£¬RedisµÄÖ÷»úʵÀý¿ÉÒÔͨ¹ýFULLRESYNCͬ²½Îļþµ½´Ó»úÉÏ¡£¡£¡£¡£¡£ ¡£È»ºóÔÚ´Ó»úÉϼÓÔØ¶ñÒâsoÎļþ£¬£¬£¬£¬£¬ £¬£¬¼´¿ÉÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Drogon_framework_СÓÚ1.75_í§ÒâÎļþÉÏ´«[CVE-2022-25297]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

DrogonframeworkÊÇÒ»¸ö»ùÓÚC++14/17µÄHTTPÓ¦ÓóÌÐò¿ò¼Ü£¬£¬£¬£¬£¬ £¬£¬Ð¡ÓÚ1.75°æ±¾Ê±ÈÝÒ×Êܵ½í§ÒâÎļþдÈëµÄÓ°Ïì¡£¡£¡£¡£¡£ ¡£¸ÃÎó²îÔ´ÓÚÔÚÉÏ´«Àú³ÌÖжÔÎļþÃûµÄ²»Çå¾²´¦Öóͷ£¿ÉÄÜʹ¹¥»÷ÕßÄܹ»½«ÎļþдÈëÖ¸¶¨Ä¿µÄÎļþ¼ÐÖ®ÍâµÄí§ÒâλÖᣡ£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ColdFusion_Îļþ¶ÁÈ¡[CVE-2010-2861]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

AdobeColdFusionÊÇÒ»¸ö¶¯Ì¬WebЧÀÍÆ÷£¬£¬£¬£¬£¬ £¬£¬ÆäËù½ÓÄɵÄCFML(ColdFusionMarkupLanguage)³ÌÐòÉè¼ÆÓïÑÔÀàËÆ"107" style="border-right: 1px solid windowtext; border-bottom: 1px solid windowtext; border-left: 1px solid windowtext; border-image: initial; border-top: none; background: white; padding: 0px 7px;">

¸üÐÂʱ¼ä£º20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Bitbucket_Server_ÏÂÁîÖ´ÐÐ[CVE-2022-36804]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

AtlassianBitbucketServerºÍDataCenter7.0.07.6.17֮ǰµÄ¶à¸öAPI¶Ëµã£¬£¬£¬£¬£¬ £¬£¬7.17.10֮ǰµÄ°æ±¾7.7.0£¬£¬£¬£¬£¬ £¬£¬7.21.4֮ǰµÄ°æ±¾7.18.0£¬£¬£¬£¬£¬ £¬£¬8.0֮ǰµÄ°æ±¾8.0.0¡£¡£¡£¡£¡£ ¡£3£¬£¬£¬£¬£¬ £¬£¬´Ó°æ±¾8.1.0µ½°æ±¾8.1.3£¬£¬£¬£¬£¬ £¬£¬´Ó°æ±¾8.2.0µ½°æ±¾8.2.2£¬£¬£¬£¬£¬ £¬£¬´Ó°æ±¾8.3.0µ½8.3.1ÔÊÐíÔ¶³Ì¹¥»÷Õß¶Ô¹«¹²»ò˽ÓÐBitbucket´æ´¢¿â¾ßÓжÁȡȨÏÞÖ´ÐÐͨ¹ý·¢ËͶñÒâHTTPÇëÇóµÄí§Òâ´úÂë

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

ICMP_ºóÃÅ_Bvp47_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

Bvp47ÊÇ·½³Ìʽ×éÖ¯µÄ¶¥¼¶LinuxºóÃÅ£¬£¬£¬£¬£¬ £¬£¬·½³Ìʽ×éÖ¯ÊÇÌìϳ¬Ò»Á÷µÄÍøÂç¹¥»÷×éÖ¯£¬£¬£¬£¬£¬ £¬£¬ÆÕ±éÒÔΪÁ¥ÊôÓÚÃÀ¹ú¹ú¼ÒÇå¾²¾ÖNSA¡£¡£¡£¡£¡£ ¡£Bvp47ͨ¹ýÔÚµÚÒ»¸öSYN°üÖмдøÊý¾ÝµÄ·½·¨À´ÌÓ±ÜÍøÂçÇå¾²×°±¸µÄ¼ì²â¡£¡£¡£¡£¡£ ¡£Bvp47ʵÏÖ°üÀ¨ÁËÖØ´óµÄ´úÂë¡¢Çø¶Î¼Ó½âÃÜ£¬£¬£¬£¬£¬ £¬£¬Linux¶à°æ±¾Æ½Ì¨ÊÊÅ䣬£¬£¬£¬£¬ £¬£¬¸»ºñµÄrootkit·´×·×Ù¼¼ÇÉ¡£¡£¡£¡£¡£ ¡£×îÖ÷ÒªµÄÊǼ¯³ÉÁׯ߼¶Òþ²ØÐŵÀÖÐËùʹÓõÄBPFÒýÇæ¸ß¼¶Ê¹Óü¼ÇÉ£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°·±ËöµÄͨѶ¼Ó½âÃÜÁ÷³Ì¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-35491/CVE-2020-36179/CVE-2020-36181/CVE-2020-36183/CVE-2020-36186]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJackson<2.9.9.2ÒÔ¼°>=2.0.0,<=2.9.10.7°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£ ¡£JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬ £¬£¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_WebLogic·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2018-3191]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼʹÓÃWebLogic12.2.1.3¼°Ö®Ç°µÄ°æ±¾±£´æµÄ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£ ¡£WeblogicÊÇÏÖÔÚÈ«ÇòÊг¡ÉÏÓ¦ÓÃ×îÆÕ±éµÄJ2EE¹¤¾ßÖ®Ò»£¬£¬£¬£¬£¬ £¬£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÓ¦ÓóÌÐòЧÀÍÆ÷£¬£¬£¬£¬£¬ £¬£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦ÓóÌÐò£¬£¬£¬£¬£¬ £¬£¬Ö§³Öй¦Ð§£¬£¬£¬£¬£¬ £¬£¬¿É½µµÍÔËÓª±¾Ç®£¬£¬£¬£¬£¬ £¬£¬Ìá¸ßÐÔÄÜ£¬£¬£¬£¬£¬ £¬£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£¡£¡£¡£¡£ ¡£T3ЭÒéÊÇÓÃÓÚWeblogicЧÀÍÆ÷ºÍÆäËûJavaApplicationÖ®¼ä´«ÊäÐÅÏ¢µÄЭÒ飬£¬£¬£¬£¬ £¬£¬ÊÇʵÏÖRMIÔ¶³ÌÀú³ÌŲÓõÄרÓÐЭÒ飬£¬£¬£¬£¬ £¬£¬ÆäÔÊÐí¿Í»§¶Ë¾ÙÐÐJNDIŲÓᣡ£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Redis_v4.x-v5.x_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Redis4.x¡¢5.x°æ±¾ÖУ¬£¬£¬£¬£¬ £¬£¬ÌṩÁËÖ÷´Óģʽ¡£¡£¡£¡£¡£ ¡£Ö÷´ÓģʽָʹÓÃÒ»¸öredis×÷ΪÖ÷»ú£¬£¬£¬£¬£¬ £¬£¬ÆäËûµÄ×÷Ϊ±¸·Ý»ú£¬£¬£¬£¬£¬ £¬£¬Ö÷»ú´Ó»úÊý¾Ý¶¼ÊÇÒ»ÑùµÄ£¬£¬£¬£¬£¬ £¬£¬´Ó»úÖ»ÈÏÕæ¶Á£¬£¬£¬£¬£¬ £¬£¬Ö÷»úÖ»ÈÏÕæÐ´¡£¡£¡£¡£¡£ ¡£ÔÚReids4.xÖ®ºó£¬£¬£¬£¬£¬ £¬£¬Í¨¹ýÍâ²¿ÍØÕ¹£¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔʵÏÖÔÚredisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁ£¬£¬£¬£¬ £¬£¬½á¹¹¶ñÒâ.soÎļþ¡£¡£¡£¡£¡£ ¡£ÔÚÁ½¸öRedisʵÀýÉèÖÃÖ÷´ÓģʽµÄʱ¼ä£¬£¬£¬£¬£¬ £¬£¬RedisµÄÖ÷»úʵÀý¿ÉÒÔͨ¹ýFULLRESYNCͬ²½Îļþµ½´Ó»úÉÏ¡£¡£¡£¡£¡£ ¡£È»ºóÔÚ´Ó»úÉϼÓÔØ¶ñÒâsoÎļþ£¬£¬£¬£¬£¬ £¬£¬¼´¿ÉÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_ÍøÂçɨÃè_Netsparker_WEBÎó²îɨÃè

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃNetsparker¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐwebÓ¦ÓÃÇå¾²Îó²îɨÃèµÄÐÐΪ¡£¡£¡£¡£¡£ ¡£NetsparkerÊÇÒ»¿î×ÛºÏÐ͵ÄwebÓ¦ÓÃÇå¾²Îó²îɨÃ蹤¾ß,ËüÄܹ»¸üºÃµÄ¼ì²âSQLInjectionºÍCross-siteScriptingÀàÐ͵ÄÇå¾²Îó²î¡£¡£¡£¡£¡£ ¡£¿£¿£¿ÉÄܻᵼÖÂϵͳй¶ijЩÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Sanic_static_Îļþ¶ÁÈ¡

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP¶ÔÄ¿µÄIPµÄSanic¾ÙÐй¥»÷µÄÐÐΪ.SanicÒ»¸ö»ùÓÚPython3.5+µÄÒì²½(asyncio+uvloop)web¿ò¼Ü£¬£¬£¬£¬£¬ £¬£¬ÓëFlaskÓеãÏàËÆ¡£¡£¡£¡£¡£ ¡£´¦Öóͷ£ËÙÂʿ죬£¬£¬£¬£¬ £¬£¬Ó¦ÓÃÆÕ±é¡£¡£¡£¡£¡£ ¡£ÔÊÐí¶ÁÈ¡í§ÒâÎļþ

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÐÅϢй¶_DedeCMSÖÎÀíĿ¼ö¾Ù_Ãô¸ÐÐÅϢй¶

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»úÌᳫDedeCMSÖÎÀíĿ¼ö¾ÙÎó²î¹¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£ ¡£DedeCMSÊÇÊ¢ÐеÄPHP¿ªÔ´ÍøÕ¾ÖÎÀíϵͳ¡£¡£¡£¡£¡£ ¡£Í¨³£DedeCMSÍøÕ¾ÔÚ×°ÖúóÖÎÀíÔ±»áÐ޸ĺǫ́ÖÎÀíĿ¼Ϊһ¸öÌØÊâµÄ×Ö·û´®£¬£¬£¬£¬£¬ £¬£¬±ÜÃâ¹¥»÷Õß´ÓÍⲿÕÒµ½ºǫ́ÖÎÀíĿ¼¡£¡£¡£¡£¡£ ¡£DedeCMSV5.7SP2×îа汾¼°ÒÔǰ°æ±¾±£´æÖÎÀíĿ¼ö¾ÙÎó²î£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýWindows²Ù×÷ÏµÍ³ÌØÕ÷¼¼ÇÉÐԵı©Á¦Ã¶¾ÙÖÎÀíºǫ́Ŀ¼¡£¡£¡£¡£¡£ ¡£ÊµÑ鱩Á¦Ã¶¾ÙÖÎÀíĿ¼¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_php·´ÐòÁл¯Ð¡Âí_ÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄipÉÏ´«php·´ÐòÁл¯µÄwebshellÎļþ£¬£¬£¬£¬£¬ £¬£¬¸ÃÎļþͨ³£°üÀ¨·´ÐòÁл¯destruct()º¯Êý£¬£¬£¬£¬£¬ £¬£¬ºÍÖ´ÐÐÏÂÁîµÄassert.()º¯Êý¡£¡£¡£¡£¡£ ¡£ÉÏ´«Àֳɺóµ¼ÖÂí§Òâ´úÂëÖ´ÐС¢Ð§ÀÍÆ÷±»½ÓÊܵÈЧ¹û¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Atlassian_Crowd_Ô¶³ÌÏÂÁîÖ´ÐÐ[CNNVD-201905-1031]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´Ö÷»úIPÕýÔÚʹÓÃÄ¿µÄIPÖ÷»úÉÏAtlassian-CrowdÉÏ¡°/crowd/plugins/servlet/cdl¡±´¦µÄ´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ £¬£¬½á¹¹¶ñÒâÏÂÁ£¬£¬£¬£¬ £¬£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬¼°Ð§ÀÍÆ÷ȨÏÞ¡£¡£¡£¡£¡£ ¡£AtlassianCrowdÊÇÒ»Ì×»ùÓÚWebµÄµ¥µãµÇ¼ϵͳ¡£¡£¡£¡£¡£ ¡£¸ÃϵͳΪ¶àÓû§¡¢ÍøÂçÓ¦ÓóÌÐòºÍĿ¼ЧÀÍÆ÷ÌṩÑéÖ¤¡¢ÊÚȨµÈ¹¦Ð§¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9546/9547/9548]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉÏJACKSONµÄºÚÃûµ¥¾ÖÏÞ£¬£¬£¬£¬£¬ £¬£¬Í¨¹ýshiro-coreÀà´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ²Ù×÷¡£¡£¡£¡£¡£ ¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£¡£ ¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ½¹µã×é¼þÖ®Ò»¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Ruby_On_Rails_ÏÂÁîÖ´ÐÐ[CVE-2020-8163][CNNVD-202005-856]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃRuby_On_RailsµÄsystemÒ³Ãæ£¬£¬£¬£¬£¬ £¬£¬½á¹¹¶ñÒâ´úÂ룬£¬£¬£¬£¬ £¬£¬Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£ ¡£RailsÓÐÒ»¸öÃûΪrenderµÄAPI£¬£¬£¬£¬£¬ £¬£¬Ëü¿ÉÒÔÉÁ¿ª·¢Ö°Ô±Ñ¡ÕªÒª·ºÆðÄÚÈݵÄÄ£°å¡£¡£¡£¡£¡£ ¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬ £¬£¬»¹¿ÉÒÔת´ïÒ»¸ölocalsÊý×飬£¬£¬£¬£¬ £¬£¬½«¸ü¶àµÄ±äÁ¿ÏòÏÂת´ï¸øÄ£°å×Ô¼º£¬£¬£¬£¬£¬ £¬£¬Àû±ãÄúÀ©Õ¹Ä£°åµÄÎÞаÐÔ£¬£¬£¬£¬£¬ £¬£¬ÉõÖÁʹÆä¹¦Ð§¸üǿʢ¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jackson·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14060][CNNVD-202006-997]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬ £¬£¬Í¨¹ý½á¹¹¶ñÒâµÄoadd.org.apache.xalan.lib.sql.JNDIConnectionPoolÀàjsonÐòÁл¯×Ö·û´®£¬£¬£¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jackson_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14062][CNNVD-202006-996]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬ £¬£¬Í¨¹ý¶ñÒâµÄcom.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPoolÀàjsonÐòÁл¯×Ö·û´®»ñȡĿµÄϵͳµÄȨÏÞ

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jackson·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14195][CNNVD-202006-1070]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬ £¬£¬Í¨¹ý½á¹¹¶ñÒâµÄorg.jsecurity.realm.jndi.JndiRealmFactoryÀàjsonÐòÁл¯×Ö·û´®Ôì³É´úÂëÖ´ÐУ¬£¬£¬£¬£¬ £¬£¬´Ó¶ø¿ØÖÆÄ¿µÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jackson·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-14540][CNNVD-201909-716]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJackson2.9.10°æ±¾Ö®Ç°±£´æµÄ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬ £¬£¬Í¨¹ý½á¹¹¶ñÒâµÄcom.zaxxer.hikari.HikariConfigÀàjsonÐòÁл¯Êý¾Ý¾ÙÐÐjndi×¢Èë¹¥»÷£¬£¬£¬£¬£¬ £¬£¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ

¸üÐÂʱ¼ä£º

20221011

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SangforEDR_cssp_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÐÅ·þ¹«Ë¾ÌṩµÄÒ»Ì×ÖÕ¶ËÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£¡£ ¡£´Ë²úÆ·±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨ÏÂÁî×¢È룩£¬£¬£¬£¬£¬ £¬£¬Î´¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆÇëÇó°ü£¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔÔì³ÉÔ¶³ÌÖ´ÐÐÏÂÁîµÄЧ¹û¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-12384][CNNVD-201906-867]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£ ¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£¡£ ¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ½¹µã×é¼þÖ®Ò»¡£¡£¡£¡£¡£ ¡£¸ÃÎó²îÊÇÓÉÓÚJacksonºÚÃûµ¥¹ýÂ˲»ÍêÕû¶øµ¼Ö£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õ߿ɽṹ°üÀ¨ÓжñÒâ´úÂëµÄjsonÊý¾Ý°ü¶ÔÓ¦ÓþÙÐй¥»÷£¬£¬£¬£¬£¬ £¬£¬µ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¡£ ¡£¹¥»÷Àֳɣ¬£¬£¬£¬£¬ £¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£

¸üÐÂʱ¼ä£º

20221011