ÿÖÜÉý¼¶Í¨¸æ-2023-03-07

Ðû²¼Ê±¼ä 2023-03-07

ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_ȨÏÞÈƹý_Apache_Shiro_v1.5.3ÒÔÏÂ[CVE-2020-11989][CNNVD-202006-1556]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ApacheShiroÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü £¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí¡£Ä¿Ç°³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖнøÐÐÉí·ÝÑéÖ¤ £¬ÊÚȨµÈ¡£¶ÔÓÚApacheShiro1.5.3֮ǰµÄ°æ±¾ £¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ £¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤Èƹý¡£

¸üÐÂʱ¼ä£º

20230307

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Apache_Log4j2_jndi×¢ÈëǶÌ×lookupÈƹý[CVE-2021-44228]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ApacheLog4j2ÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Ç¼¿â £¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´Ëʼþ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãlog4j2×é¼þÖ§³ÖµÄÄÚÖÃlookup¸ñʽµÄ×Ö·û´® £¬µ±Ä¿µÄIPÖ÷»úºó¶Ë½ÓÊÕµ½´Ë¸ñʽµÄ×Ö·û´®Ê± £¬»á×Ô¶¯µ÷ÓÃlookup¹¦Ð§¡£´Ëʼþ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ £¬´ËÐÐΪ¾ßÓнϸ߷çÏÕ £¬ÈÝÒ×±»¹¥»÷ÕßÀÄÓà £¬ÈçÈƹýWAF¼ì²â £¬²¢½øÐзÇÔ¤ÆÚµÄjndiµ÷Óà £¬´Ó¶øÖ´ÐжñÒâ´úÂë»òÃüÁî¡£log4j22.15.0-RC1Ö®ºóµÄ°æ±¾Ä¬ÈϹرÕÁËʹÓôËÊÖ·¨µ÷ÓÃjndiµ÷ÓõĹ¦Ð§ £¬²¢ÏÞÖÆÁË°×Ãûµ¥ £¬¹ÊʹÓÃδ¾­ÏÞÖƵÄÀÏ°æ±¾log4j2×é¼þ¿ÉÄÜ»á´æÔÚjndi×¢ÈëµÄ·çÏÕ¡£

¸üÐÂʱ¼ä£º

20230307

 

ʼþÃû³Æ£º

TCP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Apache_Log4j2_jndi×¢ÈëǶÌ×lookupÈƹý[CVE-2021-44228]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Ç¼¿â £¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´Ëʼþ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookup¸ñʽµÄ×Ö·û´® £¬µ±Ä¿µÄIPÖ÷»úºó¶Ë½ÓÊÕµ½´Ë¸ñʽµÄ×Ö·û´®Ê± £¬»á×Ô¶¯µ÷ÓÃlookup¹¦Ð§¡£´Ëʼþ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ £¬´ËÐÐΪ¾ßÓÐÒ»¶¨·çÏÕ £¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓà £¬ÈçÈƹýWAF¼ì²â £¬²¢½øÐзÇÔ¤ÆÚµÄjndiµ÷Óá£

¸üÐÂʱ¼ä£º

20230307