Atlassian¸ßΣ©¶´Ô¤¾¯Í¨±¨ ¶«É­Æ½Ì¨¼¯ÍÅÌṩ½â¾ö·½°¸

Ðû²¼Ê±¼ä 2021-09-18

Atlassian¹Ù·½Ðû²¼Í¨¸æ £¬Åû¶һ¸öAtlassian Confluence Server ×¢È멶´£¨CVE-2021-26084£© £¬ÈëÇÖÕßÀûÓ鶴¿ÉÍêÈ«¿ØÖÆ·þÎñÆ÷¡£Ä¿Ç°¸Ã©¶´POC£¨¿´·¨ÑéÖ¤´úÂ룩ÒѹûÈ» £¬ÇÒ´æÔÚ±»ÍøÂçºÚ²úÀûÓýøÐÐÍÚ¿óľÂíºÍ½©Ê¬ÍøÂçµÈ¹¥»÷ÐÐΪµÄ·çÏÕ¡£¶«É­Æ½Ì¨Â©¶´É¨Ãè²úÎïÍŶӵÚһʱ¼ä¶Ô¸Ã©¶´½øÐнô¼±ÏìÓ¦¡£



Atlassian Confluence ServerÊÇ°Ä´óÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×¾ßÓÐÆóҵ֪ʶ¹ÜÀí¹¦Ð§ £¬²¢Ö§³ÖÓÃÓÚ¹¹½¨ÆóÒµWiKiµÄЭͬÈí¼þµÄ·þÎñÆ÷°æ±¾¡£ConfluenceµÄʹÓÃÃæºÜ¹ã £¬ÔÚijЩÇé¿öÏ £¬Î´ÊÚȨµÄÈëÇÖÕß¿ÉÒԽṹÌØÊâµÄÇëÇó £¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐС£


¸Ã©¶´µÄ×ÛºÏÆÀ¼¶Îª¡°¸ßΣ¡±¡£


©¶´Î£º¦


ÒÔϲúÎï¼°°æ±¾Êܵ½Ó°Ï죺


Atlassian Confluence Server before 6.13.23, from 6.14.0 before 7.4.11, from 7.5.0 before 7.11.6, and from 7.12.0 before 7.12.5


©¶´¼ì²â


¶«É­Æ½Ì¨¼¯ÍÅÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0ÒÑÓÚ2021Äê9ÔÂ4ÈÕ½ô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü £¬Ö§³Ö¶Ô¸Ã©¶´½øÐÐÔ­ÀíɨÃè £¬Óû§Éý¼¶Ì쾵©ɨ²úÎ勇´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃ裺



6070°æ±¾Éý¼¶°üΪ607000377 £¬Éý¼¶°üÏÂÔصØÖ·£º


https://venustech.download.venuscloud.cn/


ÇëÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0²úÎïµÄÓû§¾¡¿ìÉý¼¶µ½×îа汾 £¬¼°Ê±¶Ô¸Ã©¶´½øÐмì²â £¬ÒԱ㾡¿ì½ÓÄÉ·À·¶´ëÊ©¡£


©¶´ÐÞ¸´½¨Òé


Ä¿Ç°³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Â©¶´ £¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º


https://www.atlassian.com/software/confluence/download-archives


ÈçÎÞ·¨Á¢¼´Éý¼¶°æ±¾ £¬½¨Òé²ÎÕÕ¹Ù·½Äþ¾²Í¨¸æ½ÓÄÉ»º½â´ëÊ©£º


https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html