ÿÖÜÉý¼¶Í¨¸æ-2021-11-02
Ðû²¼Ê±¼ä 2021-11-09ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_UEditor±à¼Æ÷_ÈÎÒâÎļþÉÏ´«Â©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃUEditor±à¼Æ÷µÄcontroller.ashxÒ³ÃæÉÏ´«Îļþ¡£UEditorÊÇÓÉ°Ù¶ÈWEBÇ°¶ËÑз¢²¿¿ª·¢µÄËù¼û¼´ËùµÃµÄ¿ªÔ´¸»Îı¾±à¼Æ÷£¬¸ÃÒ³Ãæ´æÔÚÒ»¸öÉÏ´«ÈÎÒâÎļþµÄ©¶´£¬¹¥»÷Õßͨ¹ýαÔìǰ׺ºÏ·¨µÄÎļþÃû£¬ÖмäÌí¼Ó½Ø¶Ï·ûºÅ£¬Ê¹µÃÈÎÒâÎļþ¾ù¿ÉÉÏ´«¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_×¢Èë¹¥»÷_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-24616][CNNVD-202008-1195] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´ÏòÄ¿µÄip½øÐз´ÐòÁл¯¹¥»÷£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | TCP_ľÂí_NetWire±äÖÖ_Ô¶¿ØľÂí |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWin32.NetWire¡£Win32.NetWireÊÇÒ»¸ö¹¦Ð§Ç¿´óµÄÔ¶¿ØľÂí£¬¿ÉÔ¶³Ì¿ØÖÆÊܺ¦Ö÷»úÖ´ÐÐÈÎÒâ²Ù×÷¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_ͨÓÃʼþ_·¢ÏÖʹÓÃunicode±àÂë |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | JavaĬÈϵıàÂ뷽ʽΪUnicode£¬ÔÚjavaÓïÑԺͲ¿ÃÅ.net·¨Ê½ÖУ¬unicode±àÂë¿É±»×Ô¶¯´¦ÖýâÎö³É×Ö·û´®¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_URLȨÏÞÈƹý©¶´[CVE-2020-1957][CNNVD-202003-1579] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ApacheShiroÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí¡£Ä¿Ç°³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖнøÐÐÉí·ÝÑéÖ¤£¬ÊÚȨµÈ¡£¶ÔÓÚApacheShiro1.5.1֮ǰµÄ°æ±¾£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤Èƹý¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´ÏòÄ¿µÄip½øÐз´ÐòÁл¯¹¥»÷£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_VantageVelocity_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2020-9020][CNNVD-202002-889] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | IterisVantageVelocityFieldUnitÊÇÃÀ¹úIteris¹«Ë¾µÄÒ»¿îÃÅ·¼à²âÏÖ³¡É豸¡£IterisVantageVelocityFieldUnit2.3.1°æ±¾¡¢2.4.2°æ±¾ºÍ3.0°æ±¾ÖдæÔÚ²Ù×÷ϵͳÃüÁî×¢È멶´¡£ÔÚVantageVelocity²úÎïSynchronizeWithNTPServer´¦£¬Óû§¿ÉÒÔÉèÖÃÖ¸¶¨µÄntp·þÎñÆ÷µØÖ·¡£ÓÉÓÚδ¶ÔÓû§Ð´ÈëµÄhtmlNtpServer±äÁ¿¹ýÂË£¬µ¼Ö¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÄÚÈÝ´¥·¢ÃüÁîÖ´ÐЩ¶´¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Terramaster-TOS-exportUser.php_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-15568][CNNVD-202101-2598] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | TerramasterTOSÊÇÖйúÌúÍþÂí£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NAS·þÎñÆ÷µÄ²Ù×÷ϵͳ¡£TerraMasterTOSbefore4.1.29´æÔÚÊäÈëÑéÖ¤´íÎ󩶴£¬¸Ã©¶´Ô´ÓÚÎÞЧµÄ²ÎÊý¼ì²é£¬µ¼Ö´úÂëÒÔroot×¢Èë¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Master-IP-CAM-01_ÃüÁî×¢È멶´[CVE-2020-10971][CNNVD-202005-271][CVE-2019-8387][CNNVD-201902-725][CVE-2019-8387][CNNVD-201902-725] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | MasterIPCAM01ÊÇÒ»¿îÍøÂçÉãÏñ»ú¡£MasterIPCAM013.3.4.2103°æ±¾ÖдæÔÚÃüÁî×¢È멶´¡£¸Ã©¶´Ô´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹¿ÉÖ´ÐÐÃüÁî¹ý³ÌÖУ¬ÍøÂçϵͳ»ò²úÎïδÕýÈ·¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¹¥»÷Õß¿ÉÀûÓø鶴ִÐзǷ¨ÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_InoERP_0.7.2_Ô¶³Ì´úÂëÖ´ÐÐ/ÊäÈëÑéÖ¤´íÎ󩶴[CVE-2020-28870] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | InoERPÊÇÒ»Ì×»ùÓÚPHPµÄ¿ªÔ´ÆóÒµ¹ÜÀíϵͳ¡£InoERPÖдæÔÚÊäÈëÑéÖ¤´íÎó/Ô¶³Ì´úÂëÖ´ÐЩ¶´£¬¸Ã©¶´Ô´ÓÚÍøÂçϵͳ»ò²úÎïδ¶ÔÊäÈëµÄÊý¾Ý½øÐÐÕýÈ·µÄÑéÖ¤£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_Äþ¾²É¨Ãè_WEBɨÃèÆ÷ÐÐΪ |
Äþ¾²ÀàÐÍ£º | Äþ¾²É¨Ãè |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPµØÖ·µÄÖ÷»úÕýÔÚʹÓÃWEBɨÃ蹤¾ß¶ÔÄ¿µÄIPµØÖ·½øÐЩ¶´É¨Ãè¡£WEBɨÃèÆ÷ͨ³£Êǹ¥»÷ÕßÓÃÀ´×ö·þÎñɨÃ衢©¶´²âÊԵȡ£Í¨¹ý©¶´É¨Ã裬¿ÉÒÔ×Ô¶¯¿ìËÙ̽²âһЩ³£¼û©¶´Çé¿ö£¬µ±´æÔÚ©¶´Ê±±ãÓÚºóÐø½øÐÐÀûÓù¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_ľÂí_Win32.DTLoaderÏÂÔØÕßľÂí_ÏÂÔضñÒâPayload |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½DTLoaderÏÂÔØÕßľÂíÕýÔÚÏÂÔضñÒâPayload¡£DTLoaderÊÇÒ»¸öÏÂÔØÕßľÂí£¬ÂôÁ¦ÏÂÔضñÒâ´úÂ룬ÏÂÔصĶñÒâ´úÂëÓÐAgentTesla,NanoCoreµÈ¡£Ê¹ÓÃDTLoaderC#ÓïÑÔ±àд¶ø³É£¬Ò»°ã¾¹ý»ìÏý¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_ͨÓÃʼþ_·¢ÏÖ¶à´Îunicode±àÂëÐÐΪ |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | JavaĬÈϵıàÂ뷽ʽΪUnicode£¬ÔÚjavaÓïÑԺͲ¿ÃÅ.net·¨Ê½ÖУ¬unicode±àÂë¿É±»×Ô¶¯´¦ÖýâÎö³É×Ö·û´®¡£¶à´Îunicode±àÂë¿ÉÄÜΪ¹¥»÷ÕßʵÑéÈƹý¼ì²âÉ豸µÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_Fastjson©¶´_hex±àÂëÀûÓà |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | FastJsonÊÇ°¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬Ëü¿ÉÒÔ½âÎöJSON¸ñʽµÄ×Ö·û´®£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌص㣬ӦÓ÷¶Î§ºÜ¹ã¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£fastjson¿É½ÓÊܲ¢½âÎöhex±àÂëÄÚÈÝ£¬Òò´Ë¹¥»÷Õß¿ÉÀûÓÃhex±àÂëÈƹý¼ì²âÉ豸¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_GitLab_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2021-22205][CNNVD-202104-1685] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | GitLabÊÇÓÉGitLabInc.¿ª·¢£¬Ê¹ÓÃMITÐí¿ÉÖ¤µÄ»ùÓÚÍøÂçµÄGit¶ÑÕ»¹ÜÀí¹¤¾ß£¬¾ßÓÐissue¸ú×Ù¹¦Ð§¡£ËüÊÇʹÓÃGit×÷Ϊ´úÂë¹ÜÀí¹¤¾ß£¬²¢ÔÚ´Ë»ù´¡ÉϴÆðÀ´µÄweb·þÎñ¡£¸Ã©¶´ÊÇÓÉÓÚGitLabûÓÐÕýÈ·µÄ´¦Öô«ÈëµÄͼÏñÎļþ£¬µ¼Ö¹¥»÷Õß¿ÉÀûÓø鶴½á¹¹¶ñÒâÊý¾ÝÖ´ÐÐÔ¶³ÌÃüÁ×îÖÕÔì³É·þÎñÆ÷Ãô¸ÐÐÔÐÅϢй¶¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_GitLab_Ô¶³ÌÃüÁîÖ´ÐЩ¶´ [CVE-2021-22205][CNNVD-202104-1685] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | GitLabÊÇÓÉGitLabInc.¿ª·¢£¬Ê¹ÓÃMITÐí¿ÉÖ¤µÄ»ùÓÚÍøÂçµÄGit¶ÑÕ»¹ÜÀí¹¤¾ß£¬¾ßÓÐissue¸ú×Ù¹¦Ð§¡£ËüÊÇʹÓÃGit×÷Ϊ´úÂë¹ÜÀí¹¤¾ß£¬²¢ÔÚ´Ë»ù´¡ÉϴÆðÀ´µÄweb·þÎñ¡£¸Ã©¶´ÊÇÓÉÓÚGitLabûÓÐÕýÈ·µÄ´¦Öô«ÈëµÄͼÏñÎļþ£¬µ¼Ö¹¥»÷Õß¿ÉÀûÓø鶴½á¹¹¶ñÒâÊý¾ÝÖ´ÐÐÔ¶³ÌÃüÁ×îÖÕÔì³É·þÎñÆ÷Ãô¸ÐÐÔÐÅϢй¶¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ʼþÃû³Æ£º | DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÇëÇó2 |
Äþ¾²ÀàÐÍ£º | Èä³æ²¡¶¾ |
ʼþÃèÊö£º | ¼ì²âµ½ÍÚ¿óľÂíÊÔͼÁ¬½ÓÓòÃû·þÎñÆ÷½âÎö¿ó³ØµØÖ·¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂíʵÑéÁ¬½Ó¿ó³Ø£¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý£¬ÏûºÄCPU×ÊÔ´¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_fastjson_1.2.47_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | FastjsonÊÇÒ»¸öJava¿â£¬¿ÉÒÔ½«Java¹¤¾ßת»»ÎªJSON¸ñʽ£¬fastjsonÔÚ1.2.47ÒÔ¼°Ö®Ç°°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣÄþ¾²Â©¶´¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬µ±·¨Ê½Ö´ÐÐJSON·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20211102 |