Confluence±¾µØÎļþй¶·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-08-29?·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-3394£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
?Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ÒÔϰ漼ÇÉÓòÄÚµÄ Confluence Server ºÍ Data Center Êܵ½·ì϶ӰÏ죺
6.1.0 <= version < 6.6.16
6.7.0 <= version < 6.13.7
6.14.0 <= version < 6.15.8
?·ì϶¸ÅÊö
8 Ô 28 ÈÕ£¬Atlassian Confluence¹Ù·½°ä²¼°²È«¹«¸æ£¬½¨¸´ÁË´æÔÚÓÚConfluence ÖеÄÒ»´¦±¾µØÎļþй¶·ì϶£¨CVE-2019-3394£©¡£
Atlassian Confluence ServerºÍAtlassian Data Center¶¼ÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄ²úÆ·¡£Atlassian Confluence ServerÊÇÒ»Ì×רҵµÄÆóҵ֪ʶÖÎÀíÓëÐͬÈí¼þ£¬Ò²Äܹ»ÓÃÓÚ¹¹½¨ÆóÒµWiKi¡£Atlassian Data CenterÊÇÒ»Ì×Êý¾ÝÖÐÐÄϵͳ¡£
Confluence ServerºÍ Data CenterÔÚÒ³Ãæµ¼³öÖ°ÄÜÖдæÔÚ±¾µØÎļþй¶·ì϶£º¾ßÓÓ×°Ôö³¤Ò³Ã桱¿Õ¼äȨÏÞµÄÔ¶³Ì¹¥»÷Õߣ¬¿ÉÄܶÁÈ¡<install-directory>/confluence/WEB-INF/Ŀ¼ÏµÄËÁÒâÎļþ¡£¸ÃĿ¼¿ÉÄÜÔ̺¬ÓÃÓÚÓëÆäËû·þÎñ¼¯³ÉµÄÅäÖÃÎļþ£¬¿ÉÄÜ»áй©ÈÏ֤ʹ´¦£¬ÀýÈçLDAPÈÏ֤ʹ´¦»òÆäËûÃô¸ÐÐÅÏ¢¡£
?·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
?½¨¸´½¨Òé
Éý¼¶Confluenceµ½Òѽ¨¸´·ì϶µÄ¸üа汾£º6.15.8 »ò 6.13.7 »ò 6.6.16£º
https://www.atlassian.com/software/confluence/download
https://www.atlassian.com/software/confluence/download-archives
ͬʱ²é³<install-directory>/confluence/WEB-INFĿ¼¼°Æä×ÓĿ¼£¨ÓÈÆäÊÇ/classes/Ŀ¼£©£¬¿´ÊÇ·ñÓÐÎļþÔ̺¬LDAP»òCrowdÈÏ֤ʹ´¦£¨ºÃ±Ècrowd.propertiesºÍatlassian-user.xmlÎļþ£©£¬ÒÔ¼°ÆäËû¿ÉÄܺ¬ÓÐÃô¸ÐÐÅÏ¢µÄÎļþ¡£ÈçÈô·¢ÏÖº¬ÓÐÈÏ֤ʹ´¦µÄÃô¸ÐÎļþ£¬½¨Òé¶ÔÓйØÃÜÂë½øÐÐÅú¸Ä¡£
?²Î¿¼Á´½Ó
https://confluence.atlassian.com/doc/confluence-security-advisory-2019-08-28-976161720.html


¾©¹«Íø°²±¸11010802024551ºÅ