ÿÖÜÉý¼¶Í¨¸æ-2023-03-21
Ðû²¼Ê±¼ä 2023-03-21
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_SSRF_Microsoft_Exchange_ProxyLogon_ɨÃè[CVE-2021-26855][CNNVD-202103-192][CVE-2021-26855] |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º | MicrosoftExchangeÖаüÀ¨ÁËÊý¸öÇå¾²Îó²î£¬¹¥»÷ÕßÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏ£¬¿ÉÒÔͨ¹ýÍŽáʹÓÃÊý¸öÎó²îÀ´ÈƹýExchangeÇ°¶ËºÍÉí·ÝÏÞÖÆ£¬ÉÏ´«¶ñÒâÎļþµ½Exchange·þÎñÆ÷ÉÏ£¬¸ÃÎó²îÁ´¼´±»³ÆΪProxyLogon£¬¸ÃÊÂÎñ¼ì²â¶ÔÆäÖеÄSSRFÎó²îɨÃèÐÐΪ£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎó²îÌáÉýȨÏÞ²¢Ö±½Ó»á¼ûºó¶Ë¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÏÂÁîÖ´ÐÐ_Bitbucket-Server&Data-Center_ÇéÐαäÁ¿×¢Èë |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ö÷»úÕýÔÚÊܵ½Bitbucket-Server&Data-CenterÇéÐαäÁ¿×¢È룬¿Éµ¼ÖÂí§ÒâÏÂÁîÖ´ÐС£¸ÃÎó²îÊÇͨ¹ýÇéÐαäÁ¿Òý·¢µÄÏÂÁî×¢ÈëÎó²î£¬¿Éµ¼Ö¾ßÓÐȨÏ޵Ĺ¥»÷Õß¿ØÖÆÓû§Ãû£¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐдúÂë¡£×÷ΪÔÝʱ»º½â²½·¥£¬Atlassian¹«Ë¾½¨ÒéÓû§¹Ø±Õ¡°¹ûÕæ×¢²á¡±Ñ¡Ïî¡£Ç徲ͨ¸æÖ¸³ö£¬¡°½ûÓùûÕæ×¢²á½«Ê¹¹¥»÷ÏòÁ¿´ÓδÈÏÖ¤¹¥»÷¸ü¸ÄΪÈÏÖ¤¹¥»÷£¬´Ó¶ø½µµÍʹÓÃΣº¦¡£¾ÖÎÀíÔ±»òϵͳÖÎÀíÔ±ÈÏÖ¤µÄÓû§Äܹ»ÔÚ½ûÓùûÕæ×¢²áÑ¡ÏîʱʹÓøÃÎó²î¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_Ç徲Σº¦_¿ÉÒÉÐÐΪ_esi±êÇ©ÇëÇó |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | EdgeSideIncludes(ESI)ÊÇÒ»ÖÖ±ê¼ÇÓïÑÔ£¬Ö÷ÒªÔÚ³£¼ûµÄHTTPÊðÀí£¨·´ÏòÊðÀí¡¢¸ºÔØƽºâ¡¢»º´æ·þÎñÆ÷¡¢ÊðÀí·þÎñÆ÷£©ÖÐʹÓá£Í¨¹ýESI×¢ÈëÊÖÒÕ¿ÉÒÔµ¼Ö·þÎñ¶ËÇëÇóαÔ죨SSRF£©£¬ÈƹýHTTPOnlycookieµÄ¿çÕ¾¾ç±¾¹¥»÷£¨XSS£©ÒÔ¼°·þÎñ¶Ë¾Ü¾ø·þÎñ¹¥»÷¡£Í¨¹ý²âÊÔ£¬Óм¸Ê®ÖÖÖ§³Ö´¦Öóͷ£ESIµÄ²úÆ·£ºVarnish£¬SquidProxy£¬IBMWebSphere£¬OracleFusion/WebLogic£¬Akamai£¬Fastly£¬F5£¬Node.jsESI£¬LiteSpeedºÍһЩÌض¨ÓïÑÔ²å¼þ£¬µ«²¢²»ÊÇÕâЩ²úƷĬÈÏÆôÓÃÁËESI¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_RichFaces[CVE-2018-14667] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | RichFacesÊÇÒ»¸ö»ùÓÚLGPLÐÒ鿪·ÅÔ´´úÂëµÄJSF£¨JavaServerFaces£©×é¼þ¿â£¬ËüÄܹ»Ê¹Ó¦Óÿª·¢Àû±ãµØ¼¯³ÉAJAX¡£ÏÖÔÚµÄRichFaces¿âÊÇÓÉAjax4jsfºÍRichFacesÁ½²¿·Ö×é³É¡£JavaRichFaces¿ò¼ÜÖаüÀ¨Ò»¸öRCEÎó²î,¹¥»÷Õ߿ɽṹ°üÀ¨org.ajax4jsf.resource.UserResource$UriDataÐòÁл¯¹¤¾ßµÄÌض¨UserResourceÇëÇó£¬RichFaces»áÏÈ·´ÐòÁл¯¸ÃUriData¹¤¾ß£¬È»ºóʹÓÃEL±í´ïʽÆÊÎö²¢»ñÈ¡resourceµÄmodified¡¢expiresµÈÖµµ¼ÖÂÁËí§ÒâEL±í´ïʽִÐУ¬Í¨¹ý½á¹¹ÌØÊâµÄEL±í´ïʽ¿ÉʵÏÖÔ¶³Ìí§Òâ´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Õã½ÓîÊӿƼ¼ÍøÂçÊÓƵ¼Ïñ»ú_LogReport.php |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÕýÔÚʹÓÃÕã½ÓîÊӿƼ¼ÍøÂçÊÓƵ¼Ïñ»úµÄÎó²î¾ÙÐдúÂëÖ´Ðй¥»÷£» |
¸üÐÂʱ¼ä£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÐÅϢй¶_Ametys_auto-completion_plugin[CVE-2022-26159] |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÕýÔÚʹÓÃAmetys_CMSµÄauto-completion²å¼þ±£´æµÄÐÅϢй¶Îó²î£¬ÇÔÈ¡Ä¿µÄÖ÷»úIPµÄÐÅÏ¢¡£AmetysCmsÊÇÓÃÓÚÔÚͳһ̨·þÎñÆ÷ÉÏÔËÐдóÐÍÆóÒµÍøÕ¾£¬²©¿Í£¬IntranetºÍExtranet¡££¨Ametys£©ÉçÇøµÄCmsÒ»¸öÓÃJava±àдµÄÃâ·Ñ¿ªÔ´ÄÚÈÝÖÎÀíϵͳ¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Confluence[CVE-2021-26084][CNNVD-202108-2421] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | AtlassianConfluenceÊÇAtlassian¹«Ë¾³öÆ·µÄרҵµÄÆóҵ֪ʶÖÎÀíÓëÐͬÈí¼þ£¬¿ÉÓÃÓÚ¹¹½¨ÆóÒµÎÄ¿âµÈ¡£ConfluenceServerºÍConfluenceDataCenter(<6.13.23¡¢<7.11.6¡¢<7.12.5¡¢<7.4.11°æ±¾)Éϱ£´æÒ»¸öOGNL×¢ÈëÎó²î£¬ÔÊÐí¾ÓÉÉí·ÝÑéÖ¤»òÔÚijЩÇéÐÎÏÂδÊÚȨµÄ¹¥»÷Õߣ¬ÔÚConfluenceServer»òConfluenceDataCenterʵÀýÉÏÖ´ÐÐí§Òâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Apache_AXIS[CVE-2019-0227] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | Apache AxisÊÇÃÀ¹ú°¢ÅÁÆ棨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°ÖÖÖÖ¹«Ó÷þÎñ¼°API£¬ÒÔÌìÉúºÍ°²ÅÅWeb·þÎñÓ¦Óá£Îó²îʵÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÉèÖùýʧ¡£µ±enableRemoteAdminÊôÐÔÉèÖÃΪtrueʱ£¬¹¥»÷Õß¿ÉÒԽṹWebServiceŲÓÃfreemarker×é¼þÖеÄtemplate.utility.ExecuteÀ࣬Զ³ÌʹÓÃAdminService½Ó¿Ú¾ÙÐÐWebServiceÐû²¼£¬Ôٴλá¼ûÌìÉúµÄWebService½Ó¿Ú£¬´«ÈëÒªÖ´ÐеÄÏÂÁ¾Í¿ÉÒÔ¾ÙÐÐÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îµÄʹÓᣠ|
¸üÐÂʱ¼ä£º | 20230321 |
ÊÂÎñÃû³Æ£º | TCP_Îó²îʹÓÃ_δÊÚȨ»á¼û_Hadoop_Yarn_RPC |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃHadoopYarnµÄÎó²î¾ÙÐÐδÊÚȨ»á¼û£»¹ØÓÚ8032̻¶ÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬±àдӦÓóÌÐòŲÓÃyarnClient.getApplications()¼´¿ÉÉó²éËùÓÐÓ¦ÓÃÐÅÏ¢£»Hadoop×÷Ϊһ¸öÂþÑÜʽÅÌËãÓ¦Óÿò¼Ü£¬ÖÖÀ๦Ч·±¶à£¬¶øHadoopYarn×÷ΪÆä½¹µã×é¼þÖ®Ò»¡£ |
¸üÐÂʱ¼ä£º | 20230321 |