ÿÖÜÉý¼¶Í¨¸æ-2023-03-28

Ðû²¼Ê±¼ä 2023-03-28

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÐÅϢй¶_MinIO[CVE-2023-28432]

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

MinIO ÊÇÒ»¸ö»ùÓÚApache License v2.0¿ªÔ´Ð­ÒéµÄ¹¤¾ß´æ´¢Ð§ÀÍ¡£¡£¡£Ëü¼æÈÝÑÇÂíÑ·S3ÔÆ´æ´¢Ð§ÀÍ½Ó¿Ú £¬ £¬£¬£¬ºÜÊÇÊʺÏÓÚ´æ´¢´óÈÝÁ¿·Ç½á¹¹»¯µÄÊý¾Ý £¬ £¬£¬£¬ÀýÈçͼƬ¡¢ÊÓÆµ¡¢ÈÕÖ¾Îļþ¡¢±¸·ÝÊý¾ÝºÍÈÝÆ÷/ÐéÄâ»ú¾µÏñµÈ¡£¡£¡£

MinIOÖб£´æÒ»´¦ÐÅϢй¶Îó²î £¬ £¬£¬£¬ÓÉÓÚMinio¼¯Èº¾ÙÐÐÐÅÏ¢½»Á÷µÄ9000¶Ë¿Ú £¬ £¬£¬£¬ÔÚδ¾­ÉèÖõÄÇéÐÎÏÂͨ¹ý·¢ËÍÌØÊâHPPTÇëÇó¾ÙÐÐδÊÚȨ»á¼û £¬ £¬£¬£¬½ø¶øµ¼ÖÂMinIO¹¤¾ß´æ´¢µÄÏà¹ØÇéÐαäÁ¿Ð¹Â¶ £¬ £¬£¬£¬È磺MINIO_SECRET_KEY ºÍ MINIO_ROOT_PASSWORD µÈËùÓÐÇéÐαäÁ¿ÐÅÏ¢¡£¡£¡£µ¼Ö¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÐÅÏ¢í§Òâ»á¼ûMinIO¼¯ÈºÖеÄËùÓÐÎļþ¡£¡£¡£Ê¹ÓùÙÍø¿ÍÕ» docs/orchestration/docker-compose Æô¶¯µÄµÍ°æ±¾¼¯ÈºÄ¬ÈÏÊܵ½¸ÃÎó²îÓ°Ïì¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ÐźôoaСÓÚ2.3.2[CVE-2023-1501][CNNVD-202303-1481]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

RockOA ÊÇÒ»Ì׿ªÔ´µÄ°ì¹«ÏµÍ³ £¬ £¬£¬£¬ÊÊÓÃÓÚÖÐСÐÍÆóÒµµÄͨÓÃÐÍЭͬ OA ÖÎÀíÈí¼þ £¬ £¬£¬£¬ÈÚºÏÁ˺ã¾Ã´ÓÊÂÖÎÀíÈí¼þ¿ª·¢µÄ¸»ºñÂÄÀúÓëÏȽøÊÖÒÕ £¬ £¬£¬£¬¸Ãϵͳ½ÓÄÉÁìÏ鵀 B/S (ä¯ÀÀÆ÷ / ЧÀÍÆ÷) ²Ù×÷·½·¨¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÌØ¶¨Â·ÓɾÙÐÐí§ÒâÎļþÉÏ´« £¬ £¬£¬£¬Ôì³Égetshell¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_·´ÐòÁл¯_Fastjson_1.2.80

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ £¬ £¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£fastjsonÔÚ1.2.83ÒÔ¼°Ö®Ç°°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¡£¡£¿£¿ª·¢ÕßÔÚʹÓÃfastjsonʱ £¬ £¬£¬£¬ÈôÊDZàд²»µ± £¬ £¬£¬£¬¿ÉÄܵ¼ÖÂJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂë £¬ £¬£¬£¬µ±³ÌÐòÖ´ÐÐJSON·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂë £¬ £¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ÊµÑé¾ÙÐжñÒâÏÂÁî»ò´úÂë×¢Èë £¬ £¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ÓÃÓÑGRP-U8²ÆÎñÖÎÀíÈí¼þ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¿½ñÖ÷»úÕýÔÚÔâÊÜÓÃÓÑGRP-U8²ÆÎñÖÎÀíÈí¼þí§ÒâÎļþÉÏ´«¹¥»÷ £¬ £¬£¬£¬ÓÃÓÑGRP-U8²ÆÎñÖÎÀíÈí¼þ×÷Ϊ²ÆÎñÖÎÀíÈí¼þ £¬ £¬£¬£¬×÷ÓÃÓÚ²ÆÎñÖÎÀí £¬ £¬£¬£¬ÊÇÏà¶ÔÃô¸ÐµÄÓªÒµ £¬ £¬£¬£¬ÓÉÓÚ¶ÔÉÏ´«Îļþ¹¦Ð§Î´¾ÙÐгä·ÖÇ徲˼Á¿ £¬ £¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«¶ñÒâ¾ç±¾ÊµÏÖ¶ÔÖ÷»úµÄ¿ØÖÆ £¬ £¬£¬£¬Î£º¦½Ï´ó¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ÓÃÓÑU8Cloud

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ö÷»úÕýÔÚÔâÊÜÓÃÓÑU8Cloud_ÎļþÉÏ´«¹¥»÷ £¬ £¬£¬£¬U8cloudÊÇÓÃÓÑÍÆ³öµÄÐÂÒ»´úÔÆERP £¬ £¬£¬£¬ÓÉÓÚ¶ÔÉÏ´«Îļþ¹¦Ð§Î´¾ÙÐгä·ÖÇ徲˼Á¿ £¬ £¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«¶ñÒâ¾ç±¾ÊµÏÖ¶ÔÖ÷»úµÄ¿ØÖÆ £¬ £¬£¬£¬Î£º¦½Ï´ó¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_δÊÚȨ»á¼û_Wavlink[CVE-2022-48165]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ö÷»úÕýÔÚÔâÊÜWavlink_δÊÚȨ»á¼û¹¥»÷ £¬ £¬£¬£¬WavlinkWL-WN530H4M30H4.V5030.210121µÄ/cgi-bin/ExportLogs.sh×é¼þÖб£´æ»á¼û¿ØÖÆÎÊÌâ £¬ £¬£¬£¬ÔÊÐíδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÏÂÔØÉèÖÃÊý¾ÝºÍÈÕÖ¾Îļþ²¢»ñµÃÖÎÀíÖ¤Êé¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_δÊÚȨ»á¼û_Apache_AXIS_Services

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWebЧÀͼܹ¹¡£¡£¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAPЧÀÍÆ÷ £¬ £¬£¬£¬ÒÔ¼°ÖÖÖÖ¹«ÓÃЧÀͼ°API £¬ £¬£¬£¬ÒÔÌìÉúºÍ°²ÅÅWebЧÀÍÓ¦Óᣡ£¡£Îó²îʵÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÉèÖùýʧ¡£¡£¡£µ±Ïà¹Ø½Ó¿Úδ¾ÙÐмøÈ¨´¦Öóͷ£ £¬ £¬£¬£¬¹¥»÷Õß¿Éͨ¹ýδÊÚȨ»á¼ûµ½servicesµÄwsdl½Ó¿Ú»òͨ¹ýĬÈÏ¿ÚÁî»á¼ûµ½servicesµÄupload½Ó¿Ú £¬ £¬£¬£¬²¢Í¨¹ý»ñÈ¡Ãô¸Ð½Ó¿ÚÎĵµÐÅÏ¢»ò°²ÅŶñÒâЧÀ;ÙÐкóÐø¹¥»÷ÐÐΪ¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_Îļþ¶ÁÈ¡_jetty[CVE-2021-28169]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¿µÄÖ÷»úÕýÔÚÔâÊÜjettyÎļþ¶ÁÈ¡[CVE-2021-28169]¹¥»÷¡£¡£¡£JettyServletsÖеÄConcatServlet¡¢WelcomeFilterÀà±£´æ¶àÖØ½âÂëÎÊÌâ £¬ £¬£¬£¬µ±Ó¦Óõ½ÕâÁ½¸öÀà֮һʱ £¬ £¬£¬£¬¹¥»÷Õ߾ͿÉÒÔʹÓÃË«ÖØURL±àÂëÈÆ¹ýÏÞÖÆÀ´»á¼ûWEB-INFĿ¼ÏµÄÃô¸ÐÎļþ £¬ £¬£¬£¬Ôì³ÉÃô¸ÐÐÅϢй¶¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_·ºÎ¢OA_ajax.php

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓ÷ºÎ¢OA±£´æµÄÎļþÉÏ´«Îó²î¾ÙÐÐí§ÒâÎļþÉÏ´«¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÉÏ´«¶ñÒâÎļþ £¬ £¬£¬£¬»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_ÏÂÁî¿ØÖÆ_C2ͨѶ_BruteRatelC4.badger_ÐÄÌø_ÀÖ³É

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºÚ¿Í¹¤¾ßBruteRatelC4(ÒÔϼò³ÆBRC4)ÌìÉúµÄºóÃÅbadgerʵÑéÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBruteRatelC4.badger¡£¡£¡£BruteRatelC4£¨ÒÔϼò³ÆBRC4£©ÓÃÒÔÌæ»»ÒòʹÓÃÆÕ±é¶ø±»Çå¾²¹«Ë¾ÖصãÌá·ÀµÄCobaltStrike¿ò¼Ü¡£¡£¡£BRC4ʹÓÃÁËÖÚ¶àÓÃÓÚ¹æ±ÜºÍ¼ì²âEDRµÄÊÖÒÕ £¬ £¬£¬£¬ÆäÍⲿC2½¹µãͨѶÂß¼­Êǽ«ÓÐÓøºÔØÊä³öÒþ²ØÔÚÕýµ±ÍøÂçÁ÷Á¿ÖС£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_À¶ÁèOA_datajson.js

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÀ¶ÁèOAÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£ÉîÛÚÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýdatajson.js £¬ £¬£¬£¬ÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Weblogic_T3ЭÒé[CVE-2019-2890]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨ £¬ £¬£¬£¬ÓÃÓÚÔÚÍâµØºÍÔÆ¶Ë¿ª·¢¡¢°²ÅźÍÔËÐÐÆóÒµÓ¦ÓóÌÐò £¬ £¬£¬£¬ÀýÈçJava¡£¡£¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£¡£¡£CVE-2019-2890Îó²î¿ÉÒÔʹÓÃPersistentContextÀàÈÆ¹ý²¹¶¡ £¬ £¬£¬£¬Í¨¹ý·´ÐòÁл¯´¥·¢rmiÀú³ÌÖв»Çå¾²µÄjrmpÒªÁì £¬ £¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ЭÒéÍøÂç»á¼û²¢ÆÆËðÒ×Êܹ¥»÷µÄWebLogicЧÀÍÆ÷ £¬ £¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂOracleWebLogicЧÀÍÆ÷±»½ÓÊÜ»òÃô¸ÐÐÅϢй¶¡£¡£¡£Ó°Ïì¹æÄ££º-Weblogic10.3.6.0.0-Weblogic12.1.3.0.0-Weblogic12.2.1.3.0

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ÏÂÁîÖ´ÐÐ_Exim[CVE-2019-10149]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃEximµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¸ÃÎó²îÓ°ÏìExim4.87~4.91°æ±¾ £¬ £¬£¬£¬ÔÚ4.87°æ±¾Ö®Ç°ÈôÊÇÊÖ¶¯ÆôÓÃÁËEXPERIMENTAL_EVENTÑ¡Ïî £¬ £¬£¬£¬Ð§ÀÍÆ÷Ò²»á±£´æÎó²î £¬ £¬£¬£¬¸ÃÎó²îÔÚĬÈÏÉèÖÃÏ¿ɱ»ÍâµØ¹¥»÷ÕßÖ±½ÓʹÓà £¬ £¬£¬£¬Í¨¹ýµÍȨÏÞÓû§Ö´ÐÐrootȨÏÞÏÂÁî £¬ £¬£¬£¬Ô¶³Ì¹¥»÷ÕßÐèÒªÐÞ¸ÄĬÈÏÉèÖᣡ£¡£ÎªÁËÔÚĬÈÏÉèÖÃÏÂÔ¶³ÌʹÓøÃÎó²î £¬ £¬£¬£¬Ô¶³Ì¹¥»÷ÕßÐèÒªÓë±£´æÎó²îµÄЧÀÍÆ÷½¨Éè7ÌìµÄÅþÁ¬£¨Ã¿¸ô¼¸·ÖÖÓ·¢ËÍ1¸ö×Ö½Ú£©¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_H2database_console

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndiЧÀÍÆ÷µØµã¡£¡£¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ £¬ £¬£¬£¬½ÓÄÉjavaÓïÑÔ±àд £¬ £¬£¬£¬²»ÊÜÆ½Ì¨µÄÏÞÖÆ £¬ £¬£¬£¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸öÊ®·ÖÀû±ãµÄweb¿ØÖÆÌ¨ÓÃÓÚ²Ù×÷ºÍÖÎÀíÊý¾Ý¿âÄÚÈÝ¡£¡£¡£H2Database»¹Ìṩ¼æÈÝģʽ £¬ £¬£¬£¬¿ÉÒÔ¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â £¬ £¬£¬£¬Òò´Ë½ÓÄÉH2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿âºÜÊÇÀû±ã¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Ruby_conversions.rb_Ruby[CVE-2013-0156]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄÖ÷»úÉϵÄRuby½á¹¹¶ñÒâµÄXMLÍⲿʵÌå×¢Èë´úÂë¾ÙÐй¥»÷£»£»£»RubyonRailsÊÇÒ»¸ö¿ÉÒÔʹ¿ª·¢¡¢°²ÅÅ¡¢Î¬»¤webÓ¦ÓóÌÐò±äµÃ¼òÆÓµÄ¿ò¼Ü¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Kibana[CVE-2019-7609]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

KibanaÊÇΪElasticsearchÉè¼ÆµÄ¿ªÔ´ÆÊÎöºÍ¿ÉÊÓ»¯Æ½Ì¨¡£¡£¡£¿£¿ÉÒÔʹÓÃKibanaÀ´ËÑË÷ £¬ £¬£¬£¬Éó²é´æ´¢ÔÚElasticsearchË÷ÒýÖеÄÊý¾Ý²¢ÓëÖ®½»»¥¡£¡£¡£¿£¿ÉÒÔºÜÈÝÒ×ʵÏָ߼¶µÄÊý¾ÝÆÊÎöºÍ¿ÉÊÓ»¯ £¬ £¬£¬£¬ÒÔͼ±êµÄÐÎʽչÏÖ³öÀ´¡£¡£¡£¹¥»÷ÕßʹÓÃÎó²î¿ÉÒÔͨ¹ýTimelion×é¼þÖеÄJavaScriptÔ­ÐÍÁ´ÎÛȾ¹¥»÷ £¬ £¬£¬£¬ÏòKibanaÌᳫÏà¹ØÇëÇó £¬ £¬£¬£¬´Ó¶ø½ÓÊÜËùÔÚЧÀÍÆ÷ £¬ £¬£¬£¬ÔÚЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî £¬ £¬£¬£¬Îó²îÓ°Ïì¹æÄ£°üÀ¨Kibana<6.6.1¡¢Kibana<5.6.15¡£¡£¡£

¸üÐÂʱ¼ä£º

20230328