AtlassianÖдæÔÚ0day·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-06

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15006£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Atlassian Confluence server


·ì϶¸ÅÊö


°²È«ÈËÔ±SwiftOnSecurityÖܶþ¸üÐÂTwitter£¬ÎÞÒâÖÐÅû¶ÁËÒ»¸öÓ°ÏìÆóÒµÈí¼þÒµÎñAtlassianµÄÁãÈÕ·ì϶£¬¸Ã·ì϶¿ÉÄÜÔÚIBMµÄAsperaÈí¼þÖеõ½ÌåÏÖ¡£SwiftOnSecurity TwitterÕÊ»§ÏÔʾ£¬AtlassianÌṩÁËÒ»¸öʹÓÃÆäConfluenceÔÆ·þÎñʹÓÃͨÓÃSSLÖ¤Êé½âÎöµ½±¾µØ·þÎñÆ÷µÄÓò£¬ÒÔʹAtlassian CompanionÀûÓ÷¨Ê½Äܹ»ÔÚÊ×Ñ¡±¾µØÀûÓ÷¨Ê½Öбà×ëÎļþ²¢½«Îļþ±£Áô»ØConfluence¡£ÈκÎÓµÓÐ×ã¹»¼¼Êõ֪ʶµÄÈ˶¼Äܹ»¸´ÔìSSLÃÜÔ¿£¬¶øºóʹÓÃËü½øÐÐÖÐÑëÈ˹¥»÷£¬Õâ¿ÉÄÜʹ¹¥»÷Õß½«ÀûÓ÷¨Ê½Á÷Á¿³Á¶¨Ïòµ½¶ñÒâÕ¾µã¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌûÓа䲼·ì϶½¨¸´·¨Ê½£¬Çëʵʱ¹Ø×¢¸üУºhttps://confluence.atlassian.com/doc/administering-the-atlassian-companion-app-958456281.html¡£


²Î¿¼Á´½Ó


https://www.theregister.co.uk/2019/12/05/atlassian_zero_day_bug/