2020-03-24

Ðû²¼Ê±¼ä 2020-03-24

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_jackson-2658,2659-jackson-databind-JNDI×¢Èë-Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

CMS¹¥»÷¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9548]¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ

¸üÐÂʱ¼ä£º

20200324








ÊÂÎñÃû³Æ£º

HTTP_ͨ´ïOA_ÎļþÉÏ´«ÓëÎļþ°üÀ¨µ¼ÖµÄÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_ͨ´ïOA_ÎļþÉÏ´«ÓëÎļþ°üÀ¨µ¼ÖµÄÏÂÁîÖ´ÐÐÎó²î¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£ÏÂÁîÖ´ÐÐÎó²îÊÇÓÉͨ´ïOAÖб£´æµÄÁ½Ã¶Îó²î(ÎļþÉÏ´«Îó²î£¬Îļþ°üÀ¨Îó²î)Ëùµ¼Ö¡£¸ÃÎó²îÎÞÐèµÇ¼£¬¹¥»÷ÕßʹÓÃÎó²î¿É»ñÈ¡·þÎñÆ÷¿ØÖÆȨ£¬Î£º¦ÑÏÖØ¡£

¸üÐÂʱ¼ä£º

20200324










ÊÂÎñÃû³Æ£º

HTTP_Atlassian-Jira_ÐÅϢй¶[CVE-2019-8449]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýHTTP_Atlassian-Jira_ÐÅϢй¶[CVE-2019-8449]Îó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£

Atlassian Jira 8.4.0֮ǰ°æ±¾/rest/api/latest/groupuserpicker½Ó¿ÚÔÊÐíδÊÚȨÅÌÎÊÔ±¹¤ÐÅÏ¢£¬¹¥»÷Õß¿ÉÒÔͨ¹ý±¬ÆÆÓû§ÃûÃûµ¥µÈÒªÁì»ñÈ¡Óû§ÐÅÏ¢

¸üÐÂʱ¼ä£º

20200324










ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32.Wacatac_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíWacatac¡£

WacatacÊÇÒ»¸öÔ¶¿Ø³ÌÐò£¬¿ÉÒÔÇÔÈ¡Êܺ¦Ö÷»úµÄÃô¸ÐÐÅÏ¢£¬²¢ÎüÊÕC2·þÎñÆ÷µÄÏÂÁîÖ´ÐÐÉÏ´«ÏÂÔØÎļþ£¬Àú³ÌÖÎÀíµÈÔ¶¿Ø²Ù×÷¡£

¸üÐÂʱ¼ä£º

20200324










ÐÞ¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

TCP_Jackson_Databind_¿ÉÒÉ·´ÐòÁл¯Àà_xbean[CVE-2020-8840]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃTCP_Jackson_databind_¿ÉÒÉ·´ÐòÁл¯À๥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200324