Atlassian CrowdÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-11580£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾
Atlassian Crowd 3.4.3
Atlassian Crowd 3.4
Atlassian Crowd 3.3.4
Atlassian Crowd 3.3.3
Atlassian Crowd 3.3.1
Atlassian Crowd 3.3
Atlassian Crowd 3.2.1 - 3.2.7
Atlassian Crowd 3.2
Atlassian Crowd 3.1.5
Atlassian Crowd 3.1
Atlassian Crowd 3.0.4
Atlassian Crowd 2.11.1
Atlassian Crowd 2.11
Atlassian Crowd 2.10.3
Atlassian Crowd 2.10.1
Atlassian Crowd 2.9.7
Atlassian Crowd 2.9.1 - 2.9.5
Atlassian Crowd 2.9
Atlassian Crowd 2.8.8
Atlassian Crowd 2.8.3
Atlassian Crowd 2.7
Atlassian Crowd 2.6.0 - 2.6.3
Atlassian Crowd 2.5.3 - 2.5.4
Atlassian Crowd 2.5.0 - 2.5.2
Atlassian Crowd 2.4.9
Atlassian Crowd 2.4.1
Atlassian Crowd 2.4
Atlassian Crowd 2.3.6 - 2.3.8
Atlassian Crowd 2.3.1 - 2.3.4
Atlassian Crowd 2.2.9
Atlassian Crowd 2.2.7
Atlassian Crowd 2.2.4
Atlassian Crowd 2.2.2
Atlassian Crowd 2.1.1 - 2.1.2

Atlassian Crowd 2.1


·ì϶¸ÅÊö


CrowdÊÇÒ»¸öµ¥Ò»Ò×Óõĵ¥Ò»µÇ¼ºÍÓû§ÖÎÀíÈí¼þ£¬ÎªÓû§Ìṩһ×éÓû§ÃûºÍÃÜÂëÀ´µÇ¼±ØÒª½Ó¼ûµÄËùÓÐÀûÓà ¡£Î޷켯³É Jira¡¢Confluence ºÍ Bitbucket µÈËùÓÐ Atlassian ²úÆ·£¬ÎªÓû§Ìṩµ¥Ò»µÇ¼ (SSO) ÂÄÀú ¡£¼¯Öжà¸öĿ¼£¬½«ËÁÒâĿ¼×éºÏÓ³Éäµ½µ¥¸öÀûÓ㬶øºóÔÚͳһµØÎ»ÖÎÀíÉí·ÝÑé֤ȨÏÞ ¡£ºÏÓÃÓÚ AD¡¢LDAP¡¢Microsoft Azure AD¡¢Novell eDirectory µÈµÄÏÎ½ÓÆ÷ ¡£


Atlassian Crowd´æÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¬´Ë·ì϶ÓÉÓÚAtlassian CrowdµÄcom.atlassian.pdkinstall.PdkInstallFilterÔÊÐí¹¥»÷ÕßÔÚ/admin/uploadplugin.actionõè¾¶ÏÂʹÓÃMultipartÌåʽÉÏ´«Îļþ£¬¹¥»÷ÕßÄܹ»ÀûÓô˷½Ê½Ïò·þÎñÆ÷ÉÏ´«¶ñÒâÎļþ,»ñÈ¡·þÎñÆ÷ȨÏÞ,ʵÏÖÔ¶³ÌºÅÁîÖ´Ðзì϶µÄÀûÓà ¡£


Ŀǰ¾Ýͳ¼Æ,ÔÚÈ«ÇòÁìÓòÄÚ¶Ô»¥ÁªÍøÊ¢¿ªAtlassian CrowdµÄ×ʲúÊýÁ¿¶à´ï14,225̨£¬Öйú610̨£¬É¢²¼ÈçÏ£º 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶ÑéÖ¤


´î½¨ Atlassian Crowd 3.2.3»·¾³ ¡£ÔÚ/crowd/admin/uploadplugin.actionõè¾¶Ï»ú¹ØMultipartÀàÐÍÒªÇó°ü£¬ÔÚfile_cdl²ÎÊýÖд«ÈëÒªÉÏ´«µÄÎļþ£¬×îÖÕ³ÉЧÈçÏÂͼËùʾ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½¨¸´½¨Òé


ĿǰÒѰ䲼а汾£¬Éý¼¶µ½Crowd¶ÔÓ¦µÄ×îа汾3.4.4£¬3.3.5£¬3.2.8£¬3.1.6£¬ 3.0.5 ¡£ÏÂÔØÁ´½Ó£ºhttps://www.atlassian.com/software/crowd/download ¡£


²Î¿¼Á´½Ó


https://confluence.atlassian.com/crowd/crowd-security-advisory-2019-05-22-970260700.html