2020-11-17

°ä²¼¹¦·ò 2020-11-18

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_JIRA_δÊÚȨSSRF·ì϶[CVE-2019-8451][CNNVD-201909-556]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

JIRAÊÇAtlassian¹«Ë¾³öÆ·µÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß £¬±»¿í·ºÀûÓÃÓÚȱµã¸ú×Ù¡¢¿Í»§·þÎñ¡¢ÐèÒªÍøÂç¡¢Á÷³ÌÉóÅú¡¢¹¤×÷¸ú×Ù¡¢ÏîÄ¿¸ú×ٺͻð¿ìÖÎÀíµÈ¹¤×÷ÁìÓò¡£JiraµÄ/plugins/servlet/gadgets/makeRequest×ÊÔ´´æÔÚSSRF·ì϶ £¬Ô­ÒòÔÚÓÚJiraWhitelistÕâ¸öÀàµÄÂß¼­È±µã £¬³É¹¦ÀûÓô˷ì϶µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÒÔJira·þÎñ¶ËµÄÉí·Ý½Ó¼ûÄÚÍø×ÊÔ´¡£

¸üй¦·ò£º

20201117


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Nagios_XI_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-5791][CNNVD-202010-1115]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Nagios XIÊÇÒ»¸ö³ÉÁ¢ÔÚNagiosÖ÷ÌâÉÏµÄÆóÒµ¼¶¼à²âºÍ±¨¾¯¹æ»®µÄ¿ªÔ´×é¼þ¡£Ö°ÄÜÔ̺¬PHPÍøÕ¾½çÃæ¡¢×ۺϲû·¢Í¼¡¢¿É¶¨ÔìµÄÒDZí°å¡¢ÍøÂç½á¹¹¡¢ÅäÖÃGUI(ͼÐÎÓû§½Ó¿Ú)¡¢Óû§ÖÎÀíµÈ¡£Nagios XI 5.7.3ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðа²È«·ì϶ £¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÒÔ¡°apache¡±Óû§Ö´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20201117


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉ.NET·´ÐòÁл¯Êý¾Ý

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚ¶Ô¿ÉÄÜ´æÔÚ.NET·´ÐòÁл¯·ì϶µÄÒ³Ãæ·¢ËÍ¿ÉÒÉ·´ÐòÁл¯Êý¾Ý¡£

¸üй¦·ò£º

20201117


ÊÂÎñÃû³Æ£º

HTTP_ÒÉËÆnodejs´úÂë×¢Èë

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÒÉËÆÔÚÀûÓÃnodejs´úÂë×¢Èë¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£

¸üй¦·ò£º

20201117


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ActiveMQ_ËÁÒâÎļþÉÏ´«·ì϶[CVE-2016-3088][CNNVD-201605-596]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ActiveMQ ÊÇ Apache Èí¼þ»ù½ð»áϵÄÒ»¸ö¿ªÔ´ÐÂÎÅÇý¶¯ÖÐÑë¼þÈí¼þ¡£Jetty ÊÇÒ»¸ö¿ªÔ´µÄ servlet ÈÝÆ÷ £¬ËüΪ»ùÓÚ Java µÄ web ÈÝÆ÷ £¬ÀýÈç "font-family:ËÎÌå">ºÍ servlet ÌṩÔËÐл·¾³¡£ActiveMQ 5.0 ¼°ÒÔÀ´°æ±¾Ä¬Èϼ¯³ÉÁËjetty¡£ActiveMQ ÖÐµÄ FileServer ·þÎñÔÊÐíÓû§Í¨¹ý HTTP PUT ²½ÖèÉÏ´«Îļþµ½Ö¸¶¨Ä¿Â¼ £¬¿ÉʹԶ³Ì¹¥»÷ÕßÓöñÒâ´úÂë´úÌæWebÀûÓà £¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐÐÔ¶³Ì´úÂë¡£

¸üй¦·ò£º

20201117


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_yii·´ÐòÁл¯´úÂëÖ´ÐÐ[CVE-2020-15148][CNNVD-202009-926]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÀûÓÃyii·´ÐòÁл¯Ô¶³ÌºÅÁîÖ´Ðзì϶½øÐкÅÁîÖ´ÐеÄÐÐΪ¡£YiiÊÇÒ»¸ö¸ß»úÄܵÄPHP5µÄwebÀûÓ÷¨Ê½¿ª·¢¿ò¼Ü¡£Í¨¹ýÒ»¸öµ¥Ò»µÄºÅÁîÐй¤¾ß yiic Äܹ»¼±¾ç´´½¨Ò»¸öwebÀûÓ÷¨Ê½µÄ´úÂë¿ò¼Ü £¬¿ª·¢ÕßÄܹ»ÔÚÌìÉúµÄ´úÂë¿ò¼Ü»ù´¡ÉÏÔö³¤ÒµÎñÂß¼­ £¬ÒÔ¼±¾çʵÏÖÀûÓ÷¨Ê½µÄ¿ª·¢¡£

¸üй¦·ò£º

20201117


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_fastjson_1.2.60_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ £¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â £¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´® £¬Ö§³Ö½«Java BeanÐòÁл¯ÎªJSON×Ö·û´® £¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean £¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã £¬ÀûÓÃÁìÓòºÜ¹ã¡£

¸üй¦·ò£º

20201117


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_MSAServices.Bitter.Rat(ÂûÁ黨)_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ BitterľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£

¸üй¦·ò£º

20201117


ÊÂÎñÃû³Æ£º

TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-2551]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-2551£© £¬Oracle WebLogicÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-2551£© £¬ÊÔͼͨ¹ýGIOPºÍ̸´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£·ì϶´æÔÚµÄweblogic°æ±¾:10.3.6.0.012.1.3.0.012.2.1.3.012.2.1.4.0ÈôÊDZ»¹¥»÷»úеûÓÐÉý¼¶ÏàÓ¦µÄ²¹¶¡ £¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£³¢ÊÔ½øÐжñÒâºÅÁî»ò´úÂë×¢Èë £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20201117


ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½·ì϶[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

[CNNVD-201904-1243/CNNVD-202006-075/CNNVD-201912-908/CNNVD-202007-053]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚ³¢ÊÔ¶ÔÖ÷ÕÅIPÖ÷»ú½øÐÐĿ¼´©Ô½·ì϶¹¥»÷³¢ÊÔµÄÐÐΪ¡£Ä¿Â¼´©Ô½·ì϶ÄÜʹ¹¥»÷ÕßÈÆ¹ýWeb·þÎñÆ÷µÄ½Ó¼ûÏÞ¶È £¬¶Ôweb¸ùĿ¼ÒÔ±íµÄÎļþ¼Ð £¬ËÁÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£

¸üй¦·ò£º

20201117


ÊÂÎñÃû³Æ£º

HTTP_fastjson_1.2.61_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅIPÖ÷»ú½øÐй¥»÷µÄÐÐΪ £¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â £¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´® £¬Ö§³Ö½«Java BeanÐòÁл¯ÎªJSON×Ö·û´® £¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean £¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã £¬ÀûÓÃÁìÓòºÜ¹ã¡£

¸üй¦·ò£º

20201117