ÿÖÜÉý¼¶Í¨¸æ-2022-08-03
Ðû²¼Ê±¼ä 2022-08-03ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Spring-Data-MongoDB_SpEL±í´ïʽעÈë_ÃüÁîÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | SpringDataforMongoDBÊÇSpringDataÏîÄ¿µÄÒ»²¿ÃÅ£¬¸ÃÏîĿּÔÚΪеÄÊý¾Ý´æ´¢ÌṩÊìϤºÍÒ»ÖµĻùÓÚSpringµÄ±à³ÌÄ£ÐÍ£¬Í¬Ê±±£Áô´æ´¢µÄÌØ¶¨ÌØÕ÷ºÍ¹¦Ð§¡£6ÔÂ20ÈÕ£¬VMwareÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËSpringDataMongoDBÖеÄÒ»¸öSpEL±í´ïʽעÈë©¶´£¨CVE-2022-22980£©£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.2¡£SpringDataMongoDBÓ¦Ó÷¨Ê½ÔÚ¶Ô°üÂÞ²éѯ²ÎÊýռλ·ûµÄSpEL±í´ïʽʹÓÃ@Query»ò@Aggregation×¢½âµÄ²éѯҪÁì½øÐÐÖµ°ó¶¨Ê±£¬Èç¹ûÊäÈëδ±»¹ýÂË£¬ÔòÈÝÒ×Êܵ½SpEL×¢Èë¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20220803 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Ææ°²ÐÅÌìÇæ_ÎļþÉÏ´« |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Ææ°²ÐÅÌìÇæÖÕ¶ËÄþ¾²¹ÜÀíϵͳÊÇÆæ°²ÐŵÄÐÂÒ»´úÖÕ¶ËÄþ¾²·ÀÓùÌåϵ¡£ÆäÖдæÔÚÎļþÉÏ´«Â©¶´£¬¹¥»÷Õß¿ÉÒÔÉÏ´«¶ñÒâÎļþÖÁÖ¸¶¨Ä¿Â¼£¬»ñȡĿ±êϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220803 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA-Ecology-template-import_ÎļþÉÏ´« |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£ÆäÖÐ/api/mobilemode/admin/template/import½Ó¿Ú´æÔÚ©¶´£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÉÏ´«¶ñÒâѹËõÎļþ£¬Ö²Èëwebshell£¬»ñȡĿ±êϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220803 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA-Ecology_app-import_ÎļþÉÏ´« |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£ÆäÖÐ/api/mobilemode/admin/app/import½Ó¿Ú´æÔÚÈÎÒâÎļþÉÏ´«Â©¶´£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÉÏ´«¶ñÒâѹËõÎļþ£¬Ö²Èëwebshell£¬»ñȡĿ±êϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220803 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA-Ecology-skin-import_ÎļþÉÏ´« |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£ÆäÖÐ/api/mobilemode/admin/template/import½Ó¿Ú´æÔÚ©¶´£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÉÏ´«¶ñÒâѹËõÎļþ£¬Ö²Èëwebshell£¬»ñȡĿ±êϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220803 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Apache-Commons-Configuration_´úÂëÖ´ÐÐ[CVE-2022-33980][CNNVD-202207-428] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ApacheCommonsConfigurationÊÇÓÃÓÚ¹ÜÀíÅäÖÃÎļþµÄ×é¼þ£¬ÔÚ2.8ÒÔǰµÄ²¿ÃŰ汾ÖÐÖ§³ÖÁ˶àÖÖ±äÁ¿È¡Öµ·½Ê½£¬°üÂÞjavax.script¡¢dnsºÍurl£¬µ¼Ö¿ÉÒÔÖ´ÐÐÈÎÒâ´úÂë»ò½øÐÐÍøÂç·ÃÎÊ¡£ |
¸üÐÂʱ¼ä£º | 20220803 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Apache_Shiro_v1.7.1ÒÔÏÂ_·ÇÊÚȨ·ÃÎÊ[CVE-2020-17523][CNNVD-202102-238] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ApacheShiroÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí¡£Ä¿Ç°³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖнøÐÐÉí·ÝÑéÖ¤£¬ÊÚȨµÈ¡£¶ÔÓÚApacheShiro1.7.1֮ǰµÄ°æ±¾£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£ |
¸üÐÂʱ¼ä£º | 20220803 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Elasticsearch_δÊÚȨ·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷¡£ËüÌṩÁËÒ»¸öÂþÑÜʽ¶àÓû§ÄÜÁ¦µÄÈ«ÎÄËÑË÷ÒýÇæ£¬»ùÓÚRESTfulweb½Ó¿Ú¡£Elasticsearch¿ÉÄÜ´æÔÚδÊÚȨ·ÃÎÊ©¶´¡£¸Ã©¶´µ¼Ö£¬¹¥»÷Õß¿ÉÒÔÓµÓÐElasticsearchµÄËùÓÐȨÏÞ¡£¿ÉÒÔ¶ÔÊý¾Ý½øÐÐÈÎÒâ²Ù×÷¡£ÒµÎñϵͳ½«ÃæÁÙÃô¸ÐÊý¾Ýй¶¡¢Êý¾Ý¶ªÊ§¡¢Êý¾ÝÔâµ½ÆÆ»µÉõÖÁÔâµ½¹¥»÷ÕßµÄÀÕË÷¡£ |
¸üÐÂʱ¼ä£º | 20220803 |