ÿÖÜÉý¼¶Í¨¸æ-2023-03-21
Ðû²¼Ê±¼ä 2023-03-21
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_SSRF_Microsoft_Exchange_ProxyLogon_ɨÃè[CVE-2021-26855][CNNVD-202103-192][CVE-2021-26855] |
Äþ¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ʼþÃèÊö£º | MicrosoftExchangeÖаüÂÞÁËÊý¸öÄþ¾²Â©¶´£¬¹¥»÷ÕßÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öÏ£¬¿ÉÒÔͨ¹ý½áºÏʹÓÃÊý¸ö©¶´À´ÈƹýExchangeÇ°¶ËºÍÉí·ÝÏÞÖÆ£¬ÉÏ´«¶ñÒâÎļþµ½Exchange·þÎñÆ÷ÉÏ£¬¸Ã©¶´Á´¼´±»³ÆΪProxyLogon£¬¸Ãʼþ¼ì²â¶ÔÆäÖеÄSSRF©¶´É¨ÃèÐÐΪ£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸Ã©¶´ÌáÉýȨÏÞ²¢Ö±½Ó·ÃÎʺó¶Ë¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ÃüÁîÖ´ÐÐ_Bitbucket-Server&Data-Center_»·¾³±äÁ¿×¢Èë |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ö÷»úÕýÔÚÊܵ½Bitbucket-Server&Data-Center»·¾³±äÁ¿×¢È룬¿Éµ¼ÖÂÈÎÒâÃüÁîÖ´ÐС£¸Ã©¶´ÊÇͨ¹ý»·¾³±äÁ¿Òý·¢µÄÃüÁî×¢È멶´£¬¿Éµ¼Ö¾ßÓÐȨÏ޵Ĺ¥»÷Õß¿ØÖÆÓû§Ãû£¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐдúÂë¡£×÷ΪÁÙʱ»º½â´ëÊ©£¬Atlassian¹«Ë¾½¨ÒéÓû§¹Ø±Õ¡°¹ûÈ»×¢²á¡±Ñ¡Ïî¡£Äþ¾²Í¨¸æÖ¸³ö£¬¡°½ûÓùûÈ»×¢²á½«Ê¹¹¥»÷ÏòÁ¿´ÓδÈÏÖ¤¹¥»÷¸ü¸ÄΪÈÏÖ¤¹¥»÷£¬´Ó¶ø½µµÍÀûÓ÷çÏÕ¡£¾¹ÜÀíÔ±»òϵͳ¹ÜÀíÔ±ÈÏÖ¤µÄÓû§Äܹ»ÔÚ½ûÓùûÈ»×¢²áÑ¡ÏîʱÀûÓø鶴¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ʼþÃû³Æ£º | HTTP_Äþ¾²·çÏÕ_¿ÉÒÉÐÐΪ_esi±êÇ©ÇëÇó |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | EdgeSideIncludes(ESI)ÊÇÒ»ÖÖ±êÖ¾ÓïÑÔ£¬Ö÷ÒªÔÚ³£¼ûµÄHTTPÊðÀí£¨·´ÏòÊðÀí¡¢¸ºÔؾùºâ¡¢»º´æ·þÎñÆ÷¡¢ÊðÀí·þÎñÆ÷£©ÖÐʹÓá£Í¨¹ýESI×¢Èë¼¼Êõ¿ÉÒÔµ¼Ö·þÎñ¶ËÇëÇóαÔ죨SSRF£©£¬ÈƹýHTTPOnlycookieµÄ¿çÕ¾½Å±¾¹¥»÷£¨XSS£©ÒÔ¼°·þÎñ¶Ë¾Ü¾ø·þÎñ¹¥»÷¡£Í¨¹ý²âÊÔ£¬Óм¸Ê®ÖÖÖ§³Ö´¦ÖÃESIµÄ²úÎVarnish£¬SquidProxy£¬IBMWebSphere£¬OracleFusion/WebLogic£¬Akamai£¬Fastly£¬F5£¬Node.jsESI£¬LiteSpeedºÍһЩÌض¨ÓïÑÔ²å¼þ£¬µ«²¢²»ÊÇÕâЩ²úÎïĬÈÏÆôÓÃÁËESI¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_RichFaces[CVE-2018-14667] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | RichFacesÊÇÒ»¸ö»ùÓÚLGPLÐÒ鿪·ÅÔ´´úÂëµÄJSF£¨JavaServerFaces£©×é¼þ¿â£¬ËüÄܹ»Ê¹Ó¦Óÿª·¢·½±ãµØ¼¯³ÉAJAX¡£ÏÖÔÚµÄRichFaces¿âÊÇÓÉAjax4jsfºÍRichFacesÁ½²¿ÃÅ×é³É¡£JavaRichFaces¿ò¼ÜÖаüÂÞÒ»¸öRCE©¶´,¹¥»÷Õ߿ɽṹ°üÂÞorg.ajax4jsf.resource.UserResource$UriDataÐòÁл¯¹¤¾ßµÄÌض¨UserResourceÇëÇó£¬RichFaces»áÏÈ·´ÐòÁл¯¸ÃUriData¹¤¾ß£¬È»ºóʹÓÃEL±í´ïʽ½âÎö²¢»ñÈ¡resourceµÄmodified¡¢expiresµÈÖµµ¼ÖÂÁËÈÎÒâEL±í´ïʽִÐУ¬Í¨¹ý½á¹¹ÌØÊâµÄEL±í´ïʽ¿ÉʵÏÖÔ¶³ÌÈÎÒâ´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20230321 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Õã½ÓîÊӿƼ¼ÍøÂçÊÓƵ¼Ïñ»ú_LogReport.php |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÕýÔÚÀûÓÃÕã½ÓîÊӿƼ¼ÍøÂçÊÓƵ¼Ïñ»úµÄ©¶´½øÐдúÂëÖ´Ðй¥»÷£» |
¸üÐÂʱ¼ä£º | 20230321 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ÐÅϢй¶_Ametys_auto-completion_plugin[CVE-2022-26159] |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÕýÔÚÀûÓÃAmetys_CMSµÄauto-completion²å¼þ´æÔÚµÄÐÅϢ鶩¶´£¬ÇÔÈ¡Ä¿µÄÖ÷»úIPµÄÐÅÏ¢¡£AmetysCmsÊÇÓÃÓÚÔÚͬһ̨·þÎñÆ÷ÉÏÔËÐдóÐÍÆóÒµÍøÕ¾£¬²©¿Í£¬IntranetºÍExtranet¡££¨Ametys£©ÉçÇøµÄCmsÒ»¸öÓÃJava±àдµÄÃâ·Ñ¿ªÔ´ÄÚÈݹÜÀíϵͳ¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Confluence[CVE-2021-26084][CNNVD-202108-2421] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | AtlassianConfluenceÊÇAtlassian¹«Ë¾³öÆ·µÄרҵµÄÆóҵ֪ʶ¹ÜÀíÓëÐͬÈí¼þ£¬¿ÉÓÃÓÚ¹¹½¨ÆóÒµÎÄ¿âµÈ¡£ConfluenceServerºÍConfluenceDataCenter(<6.13.23¡¢<7.11.6¡¢<7.12.5¡¢<7.4.11°æ±¾)ÉÏ´æÔÚÒ»¸öOGNL×¢È멶´£¬ÔÊÐí¾¹ýÉí·ÝÑéÖ¤»òÔÚijЩÇé¿öÏÂδÊÚȨµÄ¹¥»÷Õߣ¬ÔÚConfluenceServer»òConfluenceDataCenterʵÀýÉÏÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20230321 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Apache_AXIS[CVE-2019-0227] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Apache AxisÊÇÃÀ¹ú°¢ÅÁÆ棨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÎï°üÂÞÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°ÖÖÖÖ¹«Ó÷þÎñ¼°API£¬ÒÔÉú³ÉºÍ²¿ÊðWeb·þÎñÓ¦Óá£Â©¶´±¾ÖÊÊǹÜÀíÔ±¶ÔAdminServiceµÄÅäÖôíÎó¡£µ±enableRemoteAdminÊôÐÔÉèÖÃΪtrueʱ£¬¹¥»÷Õß¿ÉÒԽṹWebServiceµ÷ÓÃfreemarker×é¼þÖеÄtemplate.utility.ExecuteÀ࣬Զ³ÌÀûÓÃAdminService½Ó¿Ú½øÐÐWebServiceÐû²¼£¬ÔٴηÃÎÊÉú³ÉµÄWebService½Ó¿Ú£¬´«ÈëÒªÖ´ÐеÄÃüÁ¾Í¿ÉÒÔ½øÐÐÔ¶³ÌÃüÁîÖ´ÐЩ¶´µÄÀûÓᣠ|
¸üÐÂʱ¼ä£º | 20230321 |
ʼþÃû³Æ£º | TCP_©¶´ÀûÓÃ_δÊÚȨ·ÃÎÊ_Hadoop_Yarn_RPC |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃHadoopYarnµÄ©¶´½øÐÐδÊÚȨ·ÃÎÊ£»¶ÔÓÚ8032̻¶ÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬±àдӦÓ÷¨Ê½µ÷ÓÃyarnClient.getApplications()¼´¿É¼ì²ìËùÓÐÓ¦ÓÃÐÅÏ¢£»Hadoop×÷Ϊһ¸öÂþÑÜʽ¼ÆËãÓ¦Óÿò¼Ü£¬ÖÖÀ๦Ч·±¶à£¬¶øHadoopYarn×÷ΪÆäºËÐÄ×é¼þÖ®Ò»¡£ |
¸üÐÂʱ¼ä£º | 20230321 |