ÿÖÜÉý¼¶Í¨¸æ-2023-04-25
Ðû²¼Ê±¼ä 2023-04-25ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_·´ÐòÁл¯_Spring_Boot_Actuator_Snakeyaml_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.cloud.bootstrap.locationÉèÖÃΪ¶ñÒâyamlÎļþURLµØÖ·¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_Spring_Boot_logging.config_logback_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«logging.configÉèÖÃΪ¶ñÒâxmlÎļþµØÖ·¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_Îļþ°üÂÞ_spring-boot-actuator-logview[CVE-2021-21234][CNNVD-202101-261] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃspring-boot-actuator-logviewÎļþ°üÂÞ©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£spring-boot-actuator-logviewÊÇÒ»¸ö¼òµ¥µÄÈÕÖ¾Îļþ¼ì²ìÆ÷×÷ΪSpringBootÖ´ÐÐÆ÷¶Ëµã£¬ÔÚ0.2.12¼°Ö®Ç°°æ±¾ÖдæÔÚ×ÅÎļþ°üÂÞ©¶´£¬±àºÅCVE-2021-21234¡£Â©¶´±¾ÖÊÊÇSpringBootÖ´ÐÐÆ÷ͨ¹ýÇëÇóµÄ²ÎÊýÀ´Ö¸¶¨ÎļþÃûºÍÎļþ¼Ð·¾¶£¬¾¹ý×éºÏÆ´½Óµ½´ïĿ¼±éÀú£¬ËäȻԴÂëÖмì²éÁËÎļþÃû£¨filename£©²ÎÊýÀ´·ÀֹĿ¼±éÀú£¬µ«ÊÇûÓмì²éÎļþ¼Ð£¨base£©²ÎÊý£¬Ôì³ÉÁ˹¥»÷Õß¿ÉÒÔ½øÐÐĿ¼±éÀú¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | DNS_ľÂíºóÃÅ_AgentTesla_C2ÓòÃû½âÎöÇëÇó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½ÊÔͼÇëÇó½âÎöAgentTeslaµÄC2ÓòÃû¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAgentTesla Keylogger¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_CommonsConfiguration_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÄ¿µÄÖ÷»úsnakeyaml CommonsConfiguration jndi×¢È멶´¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | DNS_ÃüÁî¿ØÖÆ_ľÂíºóÃÅ_SalityѬȾÐͲ¡¶¾_ÓòÃû½âÎöÇëÇó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´Ö÷»úÕýÔÚʵÑé½âÎö SalityѬȾÐͲ¡¶¾ µÄ¶ñÒâÓòÃû£¬Ô´Ö÷»ú¿ÉÄÜÒѾ±»Ö²Èë SalityѬȾÐͲ¡¶¾¡£Sality Äܹ»ÔÚWindows²Ù×÷ϵͳµÄ¼ÆËã»úÉϽøÐÐ×ÔÎÒ¸´ÖƺÍÁ÷´«£¬Í¬Ê±»¹Äܹ»½øÐÐÔ¶³Ì¿ØÖƺÍÐÅÏ¢ÇÔÈ¡¡£Sality²¡¶¾µÄÁ÷´«·½Ê½·Ç³£Áé»î£¬¿ÉÒÔͨ¹ýÖÖÖÖ·½Ê½½øÐÐÁ÷´«£¬ÀýÈçÀûÓÿÉÒƶ¯É豸¡¢Í¨¹ýÎļþ¹²ÏíÈí¼þ¡¢µç×ÓÓʼþµÈ·½Ê½¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_ÃüÁîÓë¿ØÖÆ_Ô¶¿ØºóÃÅ_FiveSys_Á¬½ÓC2·þÎñÆ÷ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½FiveSysľÂíºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£FiveSysľÂíÖ÷Òª¹¦Ð§Êǽ«Ê¹ÓÃÕßÁ÷Á¿µ¼Òýµ½Ìض¨¶ñÒâÊðÀí·þÎñÆ÷£»FiveSysÄ¿µÄÊÇÔÚÓû§Á¬½ÓÏßÉÏÓÎϷʱ£¬½«Óû§Á÷Á¿µ¼ÏòÊðÀí·þÎñÆ÷ʱ£¬½è´ËÀ¹½Ø¡¢ÇÔÈ¡Óû§ÕÊÃܵÈÑéÖ¤ÐÅÏ¢¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ÎļþÏÂÔØ_RuoYiºǫ́¹ÜÀíϵͳ[CVE-2023-27025][CNNVD-202304-021] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | RuoyiÔÚv4.7.6¼°ÒÔÏ°汾ÖдæÔÚÈÎÒâÎļþÏÂÔØ©¶´£¬¾¹ýÉí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉÒÔÀûÓö¨Ê±ÈÎÎñÏÂÔØÈÎÒâÎļþ¡£Èç¹ûϵͳδ¶Ô¶ÁÈ¡/ÏÂÔØÎļþµÄÎļþĿ¼×öÏÞÖÆ£¬¹¥»÷ÕßÀûÓôË©¶´¿ÉÖ±½Ó¶ÁÈ¡webĿ¼ÏÂÈÎÒâÎļþ£¬ºÃ±ÈÅäÖÃÎļþ¡¢Êý¾Ý¿âÎļþµÈ£¬ÉõÖÁÖ±½Ó»ñÈ¡·þÎñÆ÷ÉÏÈÎÒâÎļþÄÚÈÝ¡£Ruoyiºǫ́¹ÜÀíϵͳÊÇ»ùÓÚSpringBootµÄȨÏÞ¹ÜÀíϵͳ¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JndiRefForwardingDataSource_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÄ¿µÄÖ÷»úsnakeyaml JndiRefForwardingDataSource jndi×¢È멶´¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_Spring_Boot_spring.main.sources_groovy_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.main.sourcesÉèÖÃΪ¶ñÒâgroovyÎļþµØÖ·¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Spring_Boot_Actuator_datasource_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.datasource.dataÊôÐÔÉèÖÃΪ¶ñÒâsqlÎļþµÄURLµØÖ·¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_·´ÐòÁл¯_SnakeYaml_MarshalOutputStream_ÈÎÒâÎļþдÈë |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÄ¿µÄÖ÷»úsnakeyaml MarshalOutputStream ÎļþдÈ멶´¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ÓÃÓÑNC_uapjs_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃÓÃÓÑNC6.5ÖÐjsinvoke½Ó¿Ú´æÔÚµÄÈÎÒâÒªÁìµ÷Ó鶴¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ÎļþÏÂÔØ_ͨ´ïOA_video_file.php |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ÀûÓÃMEDIA_DIRÓëMEDIA_NAME²ÎÊýÖµÁýÕÖ½øÐз¾¶´©Ô½²¢½ÓÄÉhttpµÄÏìÓ¦Content-DispositionÍ·×Ö¶ÎʵÏÖÈÎÒâÎļþµÄÏÂÔØ¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_PostgreSQL-JDBC-Driver_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-21724] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | PostgreSQLÊý¾Ý¿âµÄjdbcÇý¶¯·¨Ê½ÖдæÔÚÒ»¸öÄþ¾²Â©¶´¡£µ±¹¥»÷Õß¿ØÖÆjdbcurl»òÕßÊôÐÔʱ£¬Ê¹ÓÃPostgreSQLÊý¾Ý¿âµÄϵͳ½«Êܵ½¹¥»÷¡£pgjdbcƾ¾Ýͨ¹ýauthenticationPluginClassName¡¢sslhostnameverifier¡¢socketFactory¡¢sslfactory¡¢sslpasswordcallbackÁ¬½ÓÊôÐÔÌṩÀàÃûʵÀý»¯²å¼þʵÀý¡£µ«ÊÇ£¬Çý¶¯·¨Ê½ÔÚʵÀý»¯Àà֮ǰûÓÐÑéÖ¤ÀàÊÇ·ñʵÏÖÁËÔ¤ÆڵĽӿڡ£Õâ¿ÉÄܵ¼ÖÂͨ¹ýÈÎÒâÀà¼ÓÔØÔ¶³Ì´úÂëÖ´ÐлòÎļþдÈë¹¥»÷¡£Ó°Ïì°æ±¾£ºpostgresql_jdbc_driver<42.2.25£¬42.3.0<=postgresql_jdbc_driver<=42.3.1 |
¸üÐÂʱ¼ä£º | 20230425 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ScriptEngineManager_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃSnakeYAMLScriptEngineManager·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£SnakeYamlÊÇJavaÓÃÓÚ½âÎöYaml£¨YetAnotherMarkupLanguage£©¸ñʽÊý¾ÝµÄÀà¿â£¬ËüÌṩÁËdumpÒªÁì¿ÉÒÔ½«Ò»¸öJava¹¤¾ßתΪYaml¸ñʽ×Ö·û´®,ÆäloadÒªÁìÒ²Äܹ»½«Yaml×Ö·û´®×ªÎªJava¹¤¾ß¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_H2database_console |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndi·þÎñÆ÷µØÖ·¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇ棬½ÓÄÉjavaÓïÑÔ±àд£¬²»ÊÜƽ̨µÄÏÞÖÆ£¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸öÊ®·Ö·½±ãµÄweb¿ØÖÆ̨ÓÃÓÚ²Ù×÷ºÍ¹ÜÀíÊý¾Ý¿âÄÚÈÝ¡£H2Database»¹Ìṩ¼æÈÝģʽ£¬¿ÉÒÔ¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â£¬Òò´Ë½ÓÄÉH2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿â·Ç³£·½±ã¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Groovy1_Java·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃGroovy1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£ApacheGroovyÊÇÒ»¸ö¹¦Ð§Ç¿´óµÄ¶¯Ì¬±à³ÌÓïÑÔ£¬¿¿×ÅÆä¼ò½à¡¢ÓëJava·Ç³£ÏàËÆÒÔ¼°Ò×ÓÚѧϰµÄÓï·¨£¬»ùÓÚJavaƽ̨µÄGroovy¹Ø×¢ÓÚÌá¸ß¿ª·¢ÕßµÄÉú²úÐÔ¡£Ëü¿ÉÒÔºÍÈκÎJavaÓïÑÔ½øÐÐÎ޷켯³É£¬Ö§³ÖDSL£¬ÌṩÔËÐн׶κͱàÒë½×¶ÎÔªÊý¾Ý±à³ÌµÈÇ¿´óµÄ¹¦Ð§¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_Îļþ¶ÁÈ¡_Grafana_8.3.0[CVE-2021-43798][CNNVD-202112-482] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃGrafana8.0.0-8.3.0°æ±¾ÖдæÔÚµÄÎļþ¶Áȡ©¶´£¬´Ó¶øÔÚδÊÚȨµÄÇé¿ö϶ÁÈ¡Ä¿±êϵͳÃô¸ÐÎļþ¡£GrafanaÊÇÒ»¸ö¿çƽ̨¡¢¿ªÔ´µÄÊý¾Ý¿ÉÊÓ»¯ÍøÂçÓ¦Ó÷¨Ê½Æ½Ì¨¡£Óû§ÅäÖÃÁ¬½ÓµÄÊý¾ÝÔ´Ö®ºó£¬Grafana¿ÉÒÔÔÚÍøÂçä¯ÀÀÆ÷ÀïÏÔʾÊý¾Ýͼ±íºÍ¾¯¸æ |
¸üÐÂʱ¼ä£º | 20230425 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_logging.config |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/evn½Ó¿Úͨ¹ýlogging.config²ÎÊýʵÑéÔ¶³Ì´úÂëÖ´ÐС£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØϵͳÊý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØºÜ¶àºÜ¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬¿ÉÒÔ¼ì²ìÓ¦ÓÃÅäÖõÄÏêϸÐÅÏ¢¡£ |
¸üÐÂʱ¼ä£º | 20230425 |