AtlassianÖдæÔÚ0day·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2019-12-06·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-15006£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Atlassian Confluence server
·ì϶¸ÅÊö
°²È«ÈËÔ±SwiftOnSecurityÖܶþ¸üÐÂTwitter£¬ÎÞÒâÖÐÅû¶ÁËÒ»¸öÓ°ÏìÆóÒµÈí¼þÒµÎñAtlassianµÄÁãÈÕ·ì϶£¬¸Ã·ì϶¿ÉÄÜÔÚIBMµÄAsperaÈí¼þÖеõ½ÌåÏÖ¡£SwiftOnSecurity TwitterÕÊ»§ÏÔʾ£¬AtlassianÌṩÁËÒ»¸öʹÓÃÆäConfluenceÔÆ·þÎñʹÓÃͨÓÃSSLÖ¤Êé½âÎöµ½±¾µØ·þÎñÆ÷µÄÓò£¬ÒÔʹAtlassian CompanionÀûÓ÷¨Ê½Äܹ»ÔÚÊ×Ñ¡±¾µØÀûÓ÷¨Ê½Öбà×ëÎļþ²¢½«Îļþ±£Áô»ØConfluence¡£ÈκÎÓµÓÐ×ã¹»¼¼Êõ֪ʶµÄÈ˶¼Äܹ»¸´ÔìSSLÃÜÔ¿£¬¶øºóʹÓÃËü½øÐÐÖÐÑëÈ˹¥»÷£¬Õâ¿ÉÄÜʹ¹¥»÷Õß½«ÀûÓ÷¨Ê½Á÷Á¿³Á¶¨Ïòµ½¶ñÒâÕ¾µã¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌûÓа䲼·ì϶½¨¸´·¨Ê½£¬Çëʵʱ¹Ø×¢¸üУºhttps://confluence.atlassian.com/doc/administering-the-atlassian-companion-app-958456281.html¡£
²Î¿¼Á´½Ó
https://www.theregister.co.uk/2019/12/05/atlassian_zero_day_bug/


¾©¹«Íø°²±¸11010802024551ºÅ