ÿÖÜÉý¼¶Í¨¸æ-2022-04-19
Ðû²¼Ê±¼ä 2022-04-19
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_·ÉËþSSL-VPNÎļþ¶Áȡ©¶´[CVE-2018-13379][CNNVD-201905-1026] |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ·¢ÏÖÄ¿±êÕýÔÚÔâÊÜ·ÉËþSSL-VP.NÎļþ¶Áȡ©¶´[CVE-2018-13379]¹¥»÷ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Apache-Tapestry-HMAC_ÐÅϢй¶ |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | ApacheTapestryÊÇÒ»ÖÖÓÃJava±àдµÄÃæÏò×é¼þµÄWebÓ¦Ó÷¨Ê½¿ò¼Ü¡£Tapestry¿ÉÒÔÔÚÈκÎÓ¦Ó÷¨Ê½·þÎñÆ÷ÏÂÊÂÇ飬¶øÇÒ¿ÉÒÔÇáËɼ¯³ÉËùÓкó¶Ë£¬ÈçSpring£¬HibernateµÈ¡£http://localhost:8080/assets/something/services/AppModule.class/ÔÚºÚÃûµ¥¼ì²éºó£¬Ð±Ïß±»°þÀ룬AppModule.classÎļþ±»¼ÓÔص½ÏìÓ¦ÖС£Õâ¸öÀàͨ³£°üÂÞÓÃÓÚ¶ÔÐòÁл¯µÄJava¹¤¾ß½øÐÐÇ©ÃûµÄHMACÃØÔ¿£¬ÔÚÖªµÀ¸ÃÃÜÔ¿µÄÇé¿öÏ£¬¹¥»÷Õ߾ͿÉÒÔÇ©ÊðJavaС¹¤¾ßÁ´£¨ÀýÈçysoserialµÄCommonsBeanUtils1£©£¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2021-27850£©¡£CVE-2021-27850Ó°Ï췶Χ:ApacheTapestry5.4.5ApacheTapestry5.5.0ApacheTapestry5.6.2ApacheTapestry5.7.0 |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Apache_Kylin_δÊÚȨÅäÖÃ鶩¶´[CVE-2020-13937][CNNVD-202010-896] |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | ApacheKylinÊÇÒ»¸ö¿ªÔ´µÄÂþÑÜʽ·ÖÎöÒýÇ棬Ëü×î³õÓÉeBay¿ª·¢£¬ÏÖÔÚÊÇApacheSoftwareFoundationµÄÏîÄ¿¡£ApacheKylin½¨Á¢ÔÚApacheHadoop£¬ApacheHive£¬ApacheHBase£¬ApacheParquet£¬ApacheCalcite£¬ApacheSparkºÍÆäËû¼¼ÊõÖ®ÉÏ¡£ÕâЩ¼¼ÊõʹKylin¿ÉÒÔÇáËÉÀ©Õ¹ÒÔÖ§³Öº£Á¿Êý¾Ý¸ºÔØ¡£ApacheKylinÓÐÒ»¸örestfulapi»áÔÚûÓÐÈÏ¿ÉÈÏÖ¤µÄÇé¿öÏÂ̻¶ÅäÖÃÐÅÏ¢¡£¹¥»÷Õß¿ÉÀûÓø鶴»ñȡϵͳÃô¸ÐÐÅÏ¢¡£ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Jira_δ¾Éí·ÝÑéÖ¤Óû§Ãûö¾Ù©¶´[CVE-2020-14181][CNNVD-202009-1072] |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | AtlassianJiraÊÇÆóÒµ¹ã·ºÊ¹ÓõÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß£¬±»¹ã·ºÓ¦ÓÃÓÚȱÏݸú×Ù¡¢¿Í»§·þÎñ¡¢ÐèÇóÊÕ¼¯¡¢Á÷³ÌÉóÅú¡¢ÈÎÎñ¸ú×Ù¡¢ÏîÄ¿¸ú×ÙºÍÃô½Ý¹ÜÀíµÈÊÂÇéÁìÓò¡£¸Ã©¶´¿ÉÓÃÓÚö¾ÙÓû§Õ˺š£ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | HTTP_Apache_Druid_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2021-26919][CNNVD-202101-2542] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ApacheDruidʹÓÃJDBC´ÓÆäËüÊý¾Ý¿â¶ÁÈ¡Êý¾Ý£¬´Ë¹¦Ð§ÊÇΪÁËÈÃÊÜÐÅÈεÄÓû§Í¨¹ýÊʵ±µÄȨÏÞÀ´ÉèÖòéÕÒ»òÌá½»ÌáÈ¡ÈÎÎñ¡£ÓÉÓÚApacheDruidĬÈÏÇé¿öÏÂȱ·¦ÊÚȨÈÏÖ¤£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóÖ´ÐÐÈÎÒâ´úÂ룬´Ó¶ø¿ØÖÆ·þÎñÆ÷¡£ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | HTTP_IOT©¶´_Trend_Micro_InterScan_WebSecurity_Virtual_Appliance_ÃüÁî×¢È멶´[CVE-2020-8466][CNNVD-202012-1205] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | TrendMicroInterScanWebSecurityVirtualAppliance6.5SP2´æÔÚÒ»¸öÃüÁî×¢È멶´¡£¸Ã©¶´ÊÇÓÉÓÚ¶ÔHTTPÇëÇóÖÐÓû§ÌṩµÄÊý¾ÝµÄÑéÖ¤²»Í×Ôì³ÉµÄ¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿±ê·þÎñÆ÷·¢ËͶñÒâÇëÇóÀ´ÀûÓÃÕâЩ©¶´£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÄÜÔÊÐíÔÚiscanÕÊ»§µÄÄþ¾²ÉÏÏÂÎÄÖÐÔÚÄ¿±ê·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Nexus_EL±í´ïʽעÈ멶´[CVE-2018-16341] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | NuxeoPlatformÊÇÒ»¿î¿çƽ̨¿ªÔ´µÄÆóÒµ¼¶ÄÚÈݹÜÀíϵͳ(CMS)¡£ÓÉÓÚnuxeo-jsf-ui×é¼þ´¦ÖÃfaceletÄ£°å²»Í×£¬µ±·ÃÎʵÄfaceletÄ£°å²»´æÔÚʱ£¬Ïà¹ØµÄÎļþÃû»áÊä³öµ½´íÎóÒ³ÃæÉÏ£¬¶ø´íÎóÒ³Ãæ»áµ±³ÉÄ£°å±»½âÎö£¬ÎļþÃû°üÂÞ±í´ïʽ»á±»Êä³öͬʱ±»½âÎöÖ´ÐУ¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Zoho_ManageEngine_Applications_Manager_upload.php_ÈÎÒâÎļþÉÏ´«Â©¶´[CVE-2020-14008][CNNVD-202009-296] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ZohoManageEngineApplicationsManager14710¼°Ö®Ç°°æ±¾ÔÊÐí¾¹ýÉí·ÝÑéÖ¤µÄ¹ÜÀíÔ±Óû§ÔÚÌض¨Î»ÖÃÉÏ´«ÈÎÒâjarÎļþ£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | TCP_½©Ê¬ÍøÂç_Fodcha_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½½©Ê¬ÍøÂçFodchaÊÔͼÁ¬½ÓC&C·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFodcha¡£FodchaÖ÷Ҫͨ¹ýNDay©¶´ºÍTelnet/SSHÈõ¿ÚÁîÁ÷´«£¬°üÂÞCVE-2021-22205¡¢CVE-2021-35394¡¢AndroidADBDebugServerRCE¡¢LILINDVRRCEµÈ©¶´¡£Ã¿ÈÕÉÏÏß¾³ÄÚÈ⼦ÊýÒÔIPÊý¼ÆËãÒÑÁè¼Ý1Íò£¬ÇÒÿÈÕ»áÕë¶ÔÁè¼Ý100¸ö¹¥»÷Ä¿±êÌᳫDDoS¹¥»÷£¬¹¥»÷·Ç³£»îÔ¾¡£FodchaʹÓÃChaCha20¼ÓÃܺÍC&CµÄͨÐÅÊý¾Ý¡£ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ExifTool_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2021-22204] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ExifToolÊÇÒ»¸ö¶ÀÁ¢ÓÚƽ̨µÄPerl¿â£¬Ò²ÓÐÒ»¸öÃüÁîÐÐÓ¦Ó÷¨Ê½£¬ÓÃÓÚ¶ÁÈ¡£¬Ð´ÈëºÍ±à¼ÖÖÖÖÎļþÖеÄÔªÐÅÏ¢¡£¸Ã©¶´ÊÇÓÉÓÚExifTool°æ±¾7.44°æ±¾ÖдæÔÚ¶ÔDjVuÎļþ¸ñʽµÄÊý¾Ý´¦Öò»Íס£¹¥»÷Õß¿ÉÀûÓø鶴ÔÚº¬ÓЩ¶´°æ±¾µÄExifTool¿âµÄÓ¦Ó÷þÎñÆ÷»òÕßÓ¦Ó÷¨Ê½Ï£¬½á¹¹¶ñÒâDjVuÎļþ£¬·þÎñÆ÷»òÕßÓ¦Ó÷¨Ê½Ô¶³Ìµ±µØ½âÎö´ËÎļþ£¬µ¼ÖÂÈÎÒâ´úÂëÖ´ÐУ¬×îÖÕ»ñÈ¡·þÎñÆ÷×î¸ßȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_IBM_QRada_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2018-1418][CNNVD-201804-1475] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | IBMQRadarÊÇÒ»¿îÆóÒµÄþ¾²ÐÅÏ¢ºÍʼþ¹ÜÀí²úÎÓÃÓÚ×ÊÖúÄþ¾²·ÖÎöʦʶ±ðÆäÍøÂçÖеÄÅÓ´óÍþв²¢¸ÄÉÆʼþÐÞ²¹´ëÊ©¡£IBMSecurityQRadarSIEM7.2ºÍ7.3´æÔÚÒ»¸öÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¬¸Ã©¶´ÔÊÐíÓû§ÈƹýÉí·ÝÑéÖ¤£¬²¢Ö´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20220419 |
ʼþÃû³Æ£º | TCP_ºóÃÅ_FatalRat_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½ºóÃÅFatalRatÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFatalRat¡£FatalRatÊÇÒ»ÖÖÅÓ´óµÄC++RAT£¬¿ÉΪ¹¥»÷ÕßʵÏֹ㷺µÄÔ¶¿Ø¹¦Ð§¡£×ϺüľÂíPurpleFox×Ô2018ÄêÒÔÀ´¾ÍÒ»Ö±¿ªÊ¼»îÔ¾¡£×î½üPurpleFoxͨ¹ý¸ïÐÂÆäÎäÆ÷¿â£¬ÓÖ¿ªÊ¼ÁËÐÂÒ»²¨µÄ¹¥»÷¡£ÆäÎäÆ÷¿â¾Í°üÂÞÁ˺óÃÅFatalRat¡£ |
¸üÐÂʱ¼ä£º | 20220419 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_Struts2_S2-061Ô¶³ÌÃüÁîÖ´Ðй¥»÷[CVE-2020-17530][CNNVD-202012-449][CVE-2020-17530/CVE-2021-31805][CNNVD-202012-449/CNNVD-202204-3223] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄÇëÇó£¬Òý·¢OGNL±í´ïʽ½âÎö£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡£ |
¸üÐÂʱ¼ä£º | 20220419 |