ÿÖÜÉý¼¶Í¨¸æ-2023-03-28
Ðû²¼Ê±¼ä 2023-03-28ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ÐÅϢй¶_MinIO[CVE-2023-28432] |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | MinIO ÊÇÒ»¸ö»ùÓÚApache License v2.0¿ªÔ´ÐÒéµÄ¹¤¾ß´æ´¢·þÎñ¡£Ëü¼æÈÝÑÇÂíÑ·S3ÔÆ´æ´¢·þÎñ½Ó¿Ú£¬·Ç³£ÊʺÏÓÚ´æ´¢´óÈÝÁ¿·Ç½á¹¹»¯µÄÊý¾Ý£¬ÀýÈçͼƬ¡¢ÊÓƵ¡¢ÈÕÖ¾Îļþ¡¢±¸·ÝÊý¾ÝºÍÈÝÆ÷/ÐéÄâ»ú¾µÏñµÈ¡£ MinIOÖдæÔÚÒ»´¦ÐÅϢ鶩¶´£¬ÓÉÓÚMinio¼¯Èº½øÐÐÐÅÏ¢½»»»µÄ9000¶Ë¿Ú£¬ÔÚδ¾ÅäÖõÄÇé¿öÏÂͨ¹ý·¢ËÍÌØÊâHPPTÇëÇó½øÐÐδÊÚȨ·ÃÎÊ£¬½ø¶øµ¼ÖÂMinIO¹¤¾ß´æ´¢µÄÏà¹Ø»·¾³±äÁ¿Ð¹Â¶£¬È磺MINIO_SECRET_KEY ºÍ MINIO_ROOT_PASSWORD µÈËùÓл·¾³±äÁ¿ÐÅÏ¢¡£µ¼Ö¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩÐÅÏ¢ÈÎÒâ·ÃÎÊMinIO¼¯ÈºÖеÄËùÓÐÎļþ¡£Ê¹ÓùÙÍø¶ÑÕ» docs/orchestration/docker-compose Æô¶¯µÄµÍ°æ±¾¼¯ÈºÄ¬ÈÏÊܵ½¸Ã©¶´Ó°Ïì¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ÎļþÉÏ´«_ÐźôoaСÓÚ2.3.2[CVE-2023-1501][CNNVD-202303-1481] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | RockOA ÊÇÒ»Ì׿ªÔ´µÄ°ì¹«ÏµÍ³£¬ÊÊÓÃÓÚÖÐСÐÍÆóÒµµÄͨÓÃÐÍÐͬ OA ¹ÜÀíÈí¼þ£¬ÈÚºÏÁ˺ã¾Ã´ÓʹÜÀíÈí¼þ¿ª·¢µÄ¸»ºñ¾ÑéÓëÏȽø¼¼Êõ£¬¸Ãϵͳ½ÓÄÉÁìÏ鵀 B/S (ä¯ÀÀÆ÷ / ·þÎñÆ÷) ²Ù×÷·½Ê½¡£¹¥»÷Õß¿Éͨ¹ýÌض¨Â·ÓɽøÐÐÈÎÒâÎļþÉÏ´«£¬Ôì³Égetshell¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_·´ÐòÁл¯_Fastjson_1.2.80 |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬ÊÔͼͨ¹ý´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£fastjsonÔÚ1.2.83ÒÔ¼°Ö®Ç°°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣÄþ¾²Â©¶´¡£¿ª·¢ÕßÔÚʹÓÃfastjsonʱ£¬Èç¹û±àд²»Í×£¬¿ÉÄܵ¼ÖÂJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬µ±·¨Ê½Ö´ÐÐJSON·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÊµÑé½øÐжñÒâÃüÁî»ò´úÂë×¢È룬Զ³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ÎļþÉÏ´«_ÓÃÓÑGRP-U8²ÆÕþ¹ÜÀíÈí¼þ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½µ±Ç°Ö÷»úÕýÔÚÔâÊÜÓÃÓÑGRP-U8²ÆÕþ¹ÜÀíÈí¼þÈÎÒâÎļþÉÏ´«¹¥»÷£¬ÓÃÓÑGRP-U8²ÆÕþ¹ÜÀíÈí¼þ×÷Ϊ²ÆÕþ¹ÜÀíÈí¼þ£¬×÷ÓÃÓÚ²ÆÕþ¹ÜÀí£¬ÊÇÏà¶ÔÃô¸ÐµÄÒµÎñ£¬ÓÉÓÚ¶ÔÉÏ´«Îļþ¹¦Ð§Î´½øÐгäʵÄþ¾²¿¼ÂÇ£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«¶ñÒâ½Å±¾ÊµÏÖ¶ÔÖ÷»úµÄ¿ØÖÆ£¬·çÏÕ½Ï´ó¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ÎļþÉÏ´«_ÓÃÓÑU8Cloud |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ö÷»úÕýÔÚÔâÊÜÓÃÓÑU8Cloud_ÎļþÉÏ´«¹¥»÷£¬U8cloudÊÇÓÃÓÑÍƳöµÄÐÂÒ»´úÔÆERP£¬ÓÉÓÚ¶ÔÉÏ´«Îļþ¹¦Ð§Î´½øÐгäʵÄþ¾²¿¼ÂÇ£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«¶ñÒâ½Å±¾ÊµÏÖ¶ÔÖ÷»úµÄ¿ØÖÆ£¬·çÏÕ½Ï´ó¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_δÊÚȨ·ÃÎÊ_Wavlink[CVE-2022-48165] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ö÷»úÕýÔÚÔâÊÜWavlink_δÊÚȨ·ÃÎʹ¥»÷£¬WavlinkWL-WN530H4M30H4.V5030.210121µÄ/cgi-bin/ExportLogs.sh×é¼þÖдæÔÚ·ÃÎÊ¿ØÖÆÎÊÌ⣬ÔÊÐíδ¾ÈÏÖ¤µÄ¹¥»÷ÕßÏÂÔØÅäÖÃÊý¾ÝºÍÈÕÖ¾Îļþ²¢»ñµÃ¹ÜÀíÖ¤Êé¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_δÊÚȨ·ÃÎÊ_Apache_AXIS_Services |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Apache AxisÊÇÃÀ¹ú°¢ÅÁÆ棨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÎï°üÂÞÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°ÖÖÖÖ¹«Ó÷þÎñ¼°API£¬ÒÔÉú³ÉºÍ²¿ÊðWeb·þÎñÓ¦Óá£Â©¶´±¾ÖÊÊǹÜÀíÔ±¶ÔAdminServiceµÄÅäÖôíÎó¡£µ±Ïà¹Ø½Ó¿Úδ½øÐмøȨ´¦Ö㬹¥»÷Õß¿Éͨ¹ýδÊÚȨ·ÃÎʵ½servicesµÄwsdl½Ó¿Ú»òͨ¹ýĬÈÏ¿ÚÁî·ÃÎʵ½servicesµÄupload½Ó¿Ú£¬²¢Í¨¹ý»ñÈ¡Ãô¸Ð½Ó¿ÚÎĵµÐÅÏ¢»ò²¿Êð¶ñÒâ·þÎñ½øÐкóÐø¹¥»÷ÐÐΪ¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_Îļþ¶ÁÈ¡_jetty[CVE-2021-28169] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¿±êÖ÷»úÕýÔÚÔâÊÜjettyÎļþ¶ÁÈ¡[CVE-2021-28169]¹¥»÷¡£JettyServletsÖеÄConcatServlet¡¢WelcomeFilterÀà´æÔÚ¶àÖؽâÂëÎÊÌ⣬µ±Ó¦Óõ½ÕâÁ½¸öÀà֮һʱ£¬¹¥»÷Õ߾ͿÉÒÔÀûÓÃË«ÖØURL±àÂëÈƹýÏÞÖÆÀ´·ÃÎÊWEB-INFĿ¼ÏµÄÃô¸ÐÎļþ£¬Ôì³ÉÃô¸ÐÐÅϢй¶¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ÎļþÉÏ´«_·ºÎ¢OA_ajax.php |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓ÷ºÎ¢OA´æÔÚµÄÎļþÉÏ´«Â©¶´½øÐÐÈÎÒâÎļþÉÏ´«¡£¹¥»÷Õß¿ÉÀûÓø鶴ÉÏ´«¶ñÒâÎļþ£¬»ñÈ¡Ä¿±êϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_ÃüÁî¿ØÖÆ_C2ͨÐÅ_BruteRatelC4.badger_ÐÄÌø_ÀÖ³É |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½ºÚ¿Í¹¤¾ßBruteRatelC4(ÒÔϼò³ÆBRC4)Éú³ÉµÄºóÃÅbadgerʵÑéÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBruteRatelC4.badger¡£BruteRatelC4£¨ÒÔϼò³ÆBRC4£©ÓÃÒÔÌæ´úÒòʹÓù㷺¶ø±»Äþ¾²¹«Ë¾Öصã·À·¶µÄCobaltStrike¿ò¼Ü¡£BRC4ʹÓÃÁËÖÚ¶àÓÃÓÚ¹æ±ÜºÍ¼ì²âEDRµÄ¼¼Êõ£¬ÆäÍⲿC2ºËÐÄͨÐÅÂß¼Êǽ«ÓÐЧ¸ºÔØÊä³öÒþ²ØÔںϷ¨ÍøÂçÁ÷Á¿ÖС£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_À¶ÁèOA_datajson.js |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÀ¶ÁèOAÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£ÉîÛÚÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£¹¥»÷Õß¿Éͨ¹ýdatajson.js£¬ÔÚÄ¿±ê·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | TCP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Weblogic_T3ÐÒé[CVE-2019-2890] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨£¬ÓÃÓÚÔÚµ±µØºÍÔƶ˿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÓ¦Ó÷¨Ê½£¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£CVE-2019-2890©¶´¿ÉÒÔʹÓÃPersistentContextÀàÈƹý²¹¶¡£¬Í¨¹ý·´ÐòÁл¯´¥·¢rmi¹ý³ÌÖв»Äþ¾²µÄjrmpÒªÁ죬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ÐÒéÍøÂç·ÃÎʲ¢ÆÆ»µÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½Ó¹Ü»òÃô¸ÐÐÅϢй¶¡£Ó°Ï췶Χ£º-Weblogic10.3.6.0.0-Weblogic12.1.3.0.0-Weblogic12.2.1.3.0 |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | TCP_©¶´ÀûÓÃ_ÃüÁîÖ´ÐÐ_Exim[CVE-2019-10149] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃEximµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¸Ã©¶´Ó°ÏìExim4.87~4.91°æ±¾£¬ÔÚ4.87°æ±¾Ö®Ç°Èç¹ûÊÖ¶¯ÆôÓÃÁËEXPERIMENTAL_EVENTÑ¡Ï·þÎñÆ÷Ò²»á´æÔÚ©¶´£¬¸Ã©¶´ÔÚĬÈÏÅäÖÃÏ¿ɱ»µ±µØ¹¥»÷ÕßÖ±½ÓÀûÓã¬Í¨¹ýµÍȨÏÞÓû§Ö´ÐÐrootȨÏÞÃüÁԶ³Ì¹¥»÷ÕßÐèÒªÐÞ¸ÄĬÈÏÅäÖá£ÎªÁËÔÚĬÈÏÅäÖÃÏÂÔ¶³ÌÀûÓø鶴£¬Ô¶³Ì¹¥»÷ÕßÐèÒªÓë´æÔÚ©¶´µÄ·þÎñÆ÷½¨Á¢7ÌìµÄÁ¬½Ó£¨Ã¿¸ô¼¸·ÖÖÓ·¢ËÍ1¸ö×Ö½Ú£©¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_H2database_console |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndi·þÎñÆ÷µØÖ·¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇ棬½ÓÄÉjavaÓïÑÔ±àд£¬²»ÊÜƽ̨µÄÏÞÖÆ£¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸öÊ®·Ö·½±ãµÄweb¿ØÖÆ̨ÓÃÓÚ²Ù×÷ºÍ¹ÜÀíÊý¾Ý¿âÄÚÈÝ¡£H2Database»¹Ìṩ¼æÈÝģʽ£¬¿ÉÒÔ¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â£¬Òò´Ë½ÓÄÉH2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿â·Ç³£·½±ã¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Ruby_conversions.rb_Ruby[CVE-2013-0156] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄÖ÷»úÉϵÄRuby½á¹¹¶ñÒâµÄXMLÍⲿʵÌå×¢Èë´úÂë½øÐй¥»÷£»RubyonRailsÊÇÒ»¸ö¿ÉÒÔʹ¿ª·¢¡¢²¿Êð¡¢Î¬»¤webÓ¦Ó÷¨Ê½±äµÃ¼òµ¥µÄ¿ò¼Ü¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Kibana[CVE-2019-7609] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | KibanaÊÇΪElasticsearchÉè¼ÆµÄ¿ªÔ´·ÖÎöºÍ¿ÉÊÓ»¯Æ½Ì¨¡£¿ÉÒÔʹÓÃKibanaÀ´ËÑË÷£¬¼ì²ì´æ´¢ÔÚElasticsearchË÷ÒýÖеÄÊý¾Ý²¢ÓëÖ®½»»¥¡£¿ÉÒÔºÜÈÝÒ×ʵÏָ߼¶µÄÊý¾Ý·ÖÎöºÍ¿ÉÊÓ»¯£¬ÒÔͼ±êµÄÐÎʽչÏÖ³öÀ´¡£¹¥»÷ÕßÀûÓ鶴¿ÉÒÔͨ¹ýTimelion×é¼þÖеÄJavaScriptÔÐÍÁ´ÎÛȾ¹¥»÷£¬ÏòKibanaÌᳫÏà¹ØÇëÇ󣬴Ӷø½Ó¹ÜËùÔÚ·þÎñÆ÷£¬ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâÃüÁ©¶´Ó°Ï췶Χ°üÂÞKibana<6.6.1¡¢Kibana<5.6.15¡£ |
¸üÐÂʱ¼ä£º | 20230328 |