¡¾·ì϶¹«¸æ¡¿Atlassian ConfluenceÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-22527£©
°ä²¼¹¦·ò 2024-01-16Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Atlassian ConfluenceÔ¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2023-22527 | ||
·ì϶ÀàÐÍ | Ä£°å×¢Èë | ·¢ÏÖ¹¦·ò | 2024-01-16 |
·ì϶ÆÀ·Ö | 10.0 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
ConfluenceÊÇAtlassian¹«Ë¾¿ª·¢µÄÒ»¿îרҵµÄÆóҵ֪ʶÖÎÀíÓëÐͬÈí¼þ£¬¿ÉÓÃÓÚ¹¹½¨ÆóÒµwiki¡£
2024Äê1ÔÂ16ÈÕ£¬GA»Æ½ð¼×VSRC¼à²âµ½Atlassian°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËConfluence Data CenterºÍConfluence ServerÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-22527£©£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ10.0¡£
Confluence Data CenterºÍConfluence Server¶à¸öÊÜÓ°Ïì°æ±¾ÖдæÔÚÄ£°å×¢Èë·ì϶£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÀûÓø÷ì϶ÔÚÊÜÓ°ÏìµÄÊ·ýÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
¶þ¡¢Ó°ÏìÁìÓò
Confluence Data CenterºÍConfluence Server 8.0.x
Confluence Data CenterºÍConfluence Server 8.1.x
Confluence Data CenterºÍConfluence Server 8.2.x
Confluence Data CenterºÍConfluence Server 8.3.x
Confluence Data CenterºÍConfluence Server 8.4.x
Confluence Data CenterºÍConfluence Server 8.5.0 - 8.5.3
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ¸Ã·ì϶ÒѾ½¨¸´£¬ÊÜÓ°ÏìÓû§¿Éƾ¾Ý±ØÒªÉý¼¶µ½ÒÔÏÂÏàÓ¦½¨¸´°æ±¾£º
²úÆ· | CVE-2023-22527µÄ½¨¸´°æ±¾ | ×îа汾£¨Ô̺¬ÆäËü·ì϶µÄ°²È«¸üУ© |
Confluence Data CenterºÍConfluence Server | 8.5.4 (LTS) | 8.5.5 (LTS) |
Confluence Data Center | 8.6.0£¨½ö(Data Center) 8.7.1£¨½ö(Data Center) | 8.7.2»ò¸ü¸ß°æ±¾£¨½ö(Data Center) |
×¢£ºConfluence Data Center ºÍ Confluence Server µÄ×îÐÂÊÜÖ§³Ö°æ±¾²»ÊÜCVE-2023-22527µÄÓ°Ï죬ÕâЩ×îа汾ÖÐÔ̺¬ÆäËü¶à¸ö·Ç¹Ø¼ü·ì϶µÄ°²È«¸üУ¬Óû§¿ÉÉý¼¶µ½×îн¨¸´°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://www.atlassian.com/software/confluence/download-archives
3.2 һʱ´ëÊ©
½öÔÊÐíÊÜÐÅÍøÂç½Ó¼û¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://jira.atlassian.com/browse/CONFSERVER-93833
https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-01-16 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ