ÿÖÜÉý¼¶Í¨¸æ-2022-10-25

Ðû²¼Ê±¼ä 2022-10-25

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_PropertyPathFactoryBean_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLµÄPropertyPathFactoryBean·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_DefaultBeanFactoryPointcutAdvisor_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLµÄDefaultBeanFactoryPointcutAdvisor·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_CommonsConfiguration_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLµÄCommonsConfiguration·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Grafana_8.3.0_Îļþ¶ÁÈ¡[CVE-2021-43798][CNNVD-202112-482]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃGrafana8.0.0-8.3.0°æ±¾Öб£´æµÄÎļþ¶ÁÈ¡Îó²î£¬£¬£¬ £¬£¬£¬ £¬´Ó¶øÔÚδÊÚȨµÄÇéÐÎ϶ÁȡĿµÄϵͳÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£GrafanaÊÇÒ»¸ö¿çƽ̨¡¢¿ªÔ´µÄÊý¾Ý¿ÉÊÓ»¯ÍøÂçÓ¦ÓóÌÐòƽ̨¡£¡£¡£¡£¡£¡£Óû§ÉèÖÃÅþÁ¬µÄÊý¾ÝÔ´Ö®ºó£¬£¬£¬ £¬£¬£¬ £¬Grafana¿ÉÒÔÔÚÍøÂçä¯ÀÀÆ÷ÀïÏÔʾÊý¾Ýͼ±íºÍÖÒÑÔ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_HTTP_ɨÃè

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓöÔÄ¿µÄÖ÷»úÊÔͼͨ¹ýNMAP»ñÈ¡¶ÔÓ¦Ö÷»úhttpЧÀÍÆ÷°æ±¾ºÍ¶ÔÓ¦³§É̵ÄÐÐΪ¡£¡£¡£¡£¡£¡£Õâ¿ÉÄܻᵼÖÂϵͳй¶Ïà¹ØÐÅÏ¢¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_FortiOS_7.2.1_ȨÏÞÈÆ¹ý[CVE-2022-40684][CNNVD-202210-347]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFortiOS7.2.1¼°ÒÔϰ汾£¬£¬£¬ £¬£¬£¬ £¬FortiProxy7.2.0¼°ÒÔϰ汾£¬£¬£¬ £¬£¬£¬ £¬FortiSwitchManager7.2.0¼°ÒÔϰ汾Öб£´æµÄȨÏÞÈÆ¹ýÎó²î£¬£¬£¬ £¬£¬£¬ £¬ÔÚδÊÚȨµÄÇéÐÎÏÂÐÞ¸ÄÓû§µÄssh¹«Ô¿£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âʹÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐÐʹÓÃÁ´±©ÆÆ¹¥»÷¡£¡£¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬£¬ £¬£¬£¬ £¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025

 

ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Struts2_S2-032_´úÂëÖ´ÐÐ[CVE-2016-3081]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃStruts2.3.20-StrutsStruts2.3.28(2.3.20.3ºÍ2.3.24.3³ýÍâ)Öб£´æµÄ´úÂëÖ´ÐÐÎó²î£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£¡£Struts2ÊÇÒ»¸ö¾«Á·µÄ¡¢¿ÉÀ©Õ¹µÄ¿ò¼Ü£¬£¬£¬ £¬£¬£¬ £¬¿ÉÓÃÓÚ½¨ÉèÆóÒµ¼¶JavawebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£Éè¼ÆÕâ¸ö¿ò¼ÜÊÇΪÁË´Ó¹¹½¨¡¢°²ÅÅ¡¢µ½Ó¦ÓóÌÐòά»¤·½ÃæÀ´¼ò»¯Õû¸ö¿ª·¢ÖÜÆÚ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_Weblogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2801]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃOracleWeblogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬£¬ £¬£¬£¬ £¬Ê¹ÓÃt3ЭÒé·¢ËͶñÒâµÄÐòÁл¯Êý¾Ý£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£¡£WeblogicÊÇÏÖÔÚÈ«ÇòÊг¡ÉÏÓ¦ÓÃ×îÆÕ±éµÄJ2EE¹¤¾ßÖ®Ò»£¬£¬£¬ £¬£¬£¬ £¬±»³ÆÎªÒµ½ç×î¼ÑµÄÓ¦ÓóÌÐòЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬ £¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦ÓóÌÐò£¬£¬£¬ £¬£¬£¬ £¬Ö§³Öй¦Ð§£¬£¬£¬ £¬£¬£¬ £¬¿É½µµÍÔËÓª±¾Ç®£¬£¬£¬ £¬£¬£¬ £¬Ìá¸ßÐÔÄÜ£¬£¬£¬ £¬£¬£¬ £¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÓÃÓÑNC6.5_XbrlPersistenceServlet_·´ÐòÁл¯_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

¿ÉÒÔÐÐΪ

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNC6.5ÖÐXbrlPersistenceServlet½Ó¿Ú±£´æµÄ·´ÐòÁл¯Îó²î£¬£¬£¬ £¬£¬£¬ £¬Ê¹ÓÃURLDNSʹÓÃÁ´Ì½²â¸ÃÎó²îÊÇ·ñ±£´æ¡£¡£¡£¡£¡£¡£ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬£¬£¬ £¬£¬£¬ £¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-36189¡¢CVE-2020-36188¡¢CVE-2019-14439¡¢CVE-2019-14361]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬ £¬£¬£¬ £¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜʹÓÃjacksonµÄ¿ÉÒÉ·´ÐòÁл¯Ààlogback¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2883]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃWebLogicServer10.3.6.0.0£¬£¬£¬ £¬£¬£¬ £¬12.1.3.0.0£¬£¬£¬ £¬£¬£¬ £¬12.2.1.3.0£¬£¬£¬ £¬£¬£¬ £¬12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ¡£¡£¡£¡£¡£¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplicationserver£¬£¬£¬ £¬£¬£¬ £¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖÐÐļþ£¬£¬£¬ £¬£¬£¬ £¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀí´óÐÍÂþÑÜʽWebÓ¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦ÓõÄJavaÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£¡£½«JavaµÄ¶¯Ì¬¹¦Ð§ºÍJavaEnterprise±ê×¼µÄÇå¾²ÐÔÒýÈë´óÐÍÍøÂçÓ¦ÓõĿª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀíÖ®ÖС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-8840][CNNVD-202002-354]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬ £¬£¬£¬ £¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¡£¡£¡£¡£¡£´ËÎó²îÖй¥»÷Õß¿ÉʹÓÃxbean-reflectµÄʹÓÃÁ´´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zabbix_СÓÚ4.4_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃZabbixСÓÚ4.4°æ±¾Öб£´æµÄΪδÊÚȨ»á¼ûÎó²î£¬£¬£¬ £¬£¬£¬ £¬´Ó¶øÔÚδ¾­ÊÚȨµÄÇéÐÎÏ»á¼ûZabbixЧÀÍÆ÷ÉϵÄÊý¾Ý£¬£¬£¬ £¬£¬£¬ £¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Struts2_S2-055_REST_JacksonLibrary_´úÂëÖ´ÐÐ[CVE-2017-7525]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

TomcatЧÀÍÆ÷ÊÇÒ»¸öÃâ·ÑµÄ¿ª·ÅÔ´´úÂëµÄWebÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Struts2ÊÇApacheÈí¼þ»ù½ð»áÈÏÕæÎ¬»¤µÄÒ»¿îÓÃÓÚ½¨ÉèÆóÒµ¼¶JavaWebÓ¦ÓõĿªÔ´¿ò¼Ü¡£¡£¡£¡£¡£¡£Struts2ÔÚv2.5-v2.5.14£¬£¬£¬ £¬£¬£¬ £¬¹¥»÷Õßͨ¹ýŲÓÃREST²å¼þÖеı£´æ·´ÐòÁл¯Îó²îµÄJacksonLibraryÀ´´¦Öóͷ£JSONÊý¾Ý£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø´¥·¢·´ÐòÁл¯Îó²î¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÐÅϢй¶_PACSOne_Server_6.6.2_DICOM_Web_Viewer_Ŀ¼±éÀú

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýPACSOneServerÖб£´æµÄĿ¼±éÀúÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúnocache.php¾ç±¾µÄ¡®path¡¯²ÎÊýÖеġ®..¡¯×Ö·ûʹÓøÃÎó²î¶ÁÈ¡í§ÒâÎļþ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡Ãô¸ÐÐÅÏ¢

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ͨ´ïOA_print.php_Îļþɾ³ý

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃͨ´ïOAµÄV11.6¼°ÒÔǰµÄ°æ±¾±£´æµÄÎļþɾ³ýÎó²î¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£Í¨´ïOAÊÇOfficeAnywhereµÄ¼ò³Æ£¬£¬£¬ £¬£¬£¬ £¬¸Ãϵͳ½ÓÄÉÁìÏȵÄB/S(ä¯ÀÀÆ÷/ЧÀÍÆ÷)²Ù×÷·½·¨£¬£¬£¬ £¬£¬£¬ £¬Ê¹µÃÍøÂç°ì¹«²»ÊܵØÇøÏÞ¡£¡£¡£¡£¡£¡£OfficeAnywhere½ÓÄÉ»ùÓÚWEBµÄÆóÒµÅÌË㣬£¬£¬ £¬£¬£¬ £¬Ö÷HTTPЧÀÍÆ÷½ÓÄÉÁËÌìÏÂÉÏ×îÏȽøµÄApacheЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬ £¬ÐÔÄÜÎȹ̿ɿ¿¡£¡£¡£¡£¡£¡£Êý¾Ý´æÈ¡¼¯ÖпØÖÆ£¬£¬£¬ £¬£¬£¬ £¬×èÖ¹ÁËÊý¾Ý×ß©µÄ¿ÉÄÜ¡£¡£¡£¡£¡£¡£ÌṩÊý¾Ý±¸·Ý¹¤¾ß£¬£¬£¬ £¬£¬£¬ £¬±£»£»£»¤ÏµÍ³Êý¾ÝÇå¾²¡£¡£¡£¡£¡£¡£¶à¼¶µÄȨÏÞ¿ØÖÆ£¬£¬£¬ £¬£¬£¬ £¬ÍêÉÆµÄÃÜÂëÑéÖ¤ÓëµÇ¼ÑéÖ¤»úÖÆÔ½·¢Ç¿ÁËϵͳÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14645][CVE-2020-14625][CVE-2020-14644][CVE-2020-14687]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃOracleWebLogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÆäËü¿ÉÒÉÐÐΪ_PHPαЭÒé

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃPHPµÄһЩ·âװЭÒ飬£¬£¬ £¬£¬£¬ £¬Èçphp://input,php://filterµÈÌá½»Ò»¾ä»°Ä¾Âí£¬£¬£¬ £¬£¬£¬ £¬»òÔ¶³ÌÖ´ÐÐÏÂÁîÀ´¹¥»÷Êܺ¦ÕßЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-1000353]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î¾ÙÐй¥»÷£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£¡£JenkinsÊÇÒ»¸ö¿ÉÀ©Õ¹µÄ¿ªÔ´Ò»Á¬¼¯³ÉЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬ £¬ÔÚÐí¶àÆóÒµµÄÄÚÍøÖж¼°²ÅÅÁËÕâ¸öϵͳ¡£¡£¡£¡£¡£¡£Jenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòJenkinsCLIת´ïÐòÁл¯µÄJava¡®SignedObject¡¯¹¤¾ßʹÓøÃÎó²îÈÆ¹ý»ùÓÚºÚÃûµ¥µÄ±£»£»£»¤»úÖÆ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2015-8103]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJenkins1.637¼°Ö®Ç°°æ±¾¡¢JenkinsLTS1.625.1¼°Ö®Ç°°æ±¾±£´æµÄ·´ÐòÁл¯Îó²î¾ÙÐдúÂëÖ´Ðй¥»÷£¬£¬£¬ £¬£¬£¬ £¬´Ó¶ø»ñȡĿµÄÖ÷»úȨÏÞ¡£¡£¡£¡£¡£¡£JenkinsÊÇÒ»¸ö¿ÉÀ©Õ¹µÄ¿ªÔ´Ò»Á¬¼¯³ÉЧÀÍÆ÷¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JBossMQ_JMS·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-7504][CNNVD-201705-937]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

RedHatJBossApplicationServerÊÇÒ»¿î»ùÓÚJavaEEµÄ¿ªÔ´Ó¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£¡£JBossAS4.x¼°Ö®Ç°°æ±¾ÖУ¬£¬£¬ £¬£¬£¬ £¬JbossMQʵÏÖÀú³ÌµÄJMSoverHTTPInvocationLayerµÄHTTPServerILServlet.javaÎļþ±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬ £¬£¬£¬ £¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÐòÁл¯Êý¾ÝʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON-databind_2670_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-11113][CNNVD-202003-1735]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÏòÄ¿µÄip¾ÙÐз´ÐòÁл¯¹¥»÷£»£»£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_InfluxDB_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

influxdbÊÇÒ»¿îÖøÃûµÄʱÐòÊý¾Ý¿â£¬£¬£¬ £¬£¬£¬ £¬ÆäʹÓÃjwt×÷Ϊ¼øÈ¨·½·¨¡£¡£¡£¡£¡£¡£ÔÚÓû§¿ªÆôÁËÈÏÖ¤£¬£¬£¬ £¬£¬£¬ £¬µ«Î´ÉèÖòÎÊýshared-secretµÄÇéÐÎÏ£¬£¬£¬ £¬£¬£¬ £¬jwtµÄÈÏÖ¤ÃÜԿΪ¿Õ×Ö·û´®£¬£¬£¬ £¬£¬£¬ £¬´Ëʱ¹¥»÷Õß¿ÉÒÔαÔìí§ÒâÓû§Éí·ÝÔÚinfluxdbÖÐÖ´ÐÐSQLÓï¾ä¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_IncomCMS_2.0_ÎļþÉÏ´«[CVE-2020-29597][CNNVD-202012-431]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

IncomCMS2.0ÒÔ¼°Ö®Ç°µÄ°æ±¾±£´æÎļþÉÏ´«Îó²î£¬£¬£¬ £¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔÉÏ´«webshell»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Docker_Remote_API_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃDockerRemoteAPIÉèÖò»µ±Ê±µ¼ÖµÄδÊÚȨ»á¼ûÎó²îdockerclient»òÕßhttpÖ±½ÓÇëÇó»á¼ûÕâ¸öAPI£¬£¬£¬ £¬£¬£¬ £¬´Ó¶øÖ±½Ó»á¼ûËÞÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢£¬£¬£¬ £¬£¬£¬ £¬»ò¶ÔÃô¸ÐÎļþ¾ÙÐÐÐ޸쬣¬£¬ £¬£¬£¬ £¬×îÖÕÍêÈ«¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¡£DockerRemoteAPIÊÇÒ»¸öÈ¡´úÔ¶³ÌÏÂÁîÐнçÃæ£¨rcli£©µÄRESTAPI¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ShiroAttack¹¤¾ßʹÓÃ_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬£¬ £¬£¬£¬ £¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬£¬ £¬£¬£¬ £¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬£¬£¬ £¬£¬£¬ £¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ_ÄÚ´æÂí×¢Èë_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐÐʹÓ㬣¬£¬ £¬£¬£¬ £¬²¢ÔÚÇëÇóÌ崦עÈëÄÚ´æÂí¡£¡£¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬£¬ £¬£¬£¬ £¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âʹÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐÐʹÓÃÁ´±©ÆÆ¹¥»÷¡£¡£¡£¡£¡£¡£ApacheShiro£¨Îó²î°æ±¾<=1.2.4£©ÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬£¬ £¬£¬£¬ £¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí

¸üÐÂʱ¼ä£º

20221025