ÿÖÜÉý¼¶²¼¸æ-2022-06-07

°ä²¼¹¦·ò 2022-06-07

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_apache-solr_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_apache-solr_Ô¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£2019Äê11ÔÂ16ÈÕ £¬Apache¹Ù·½°ä²¼ApacheSolrÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ £¬´Ë·ì϶´æÔÚÓÚ¿Éѡģ¿éDataImportHandlerÖÐ £¬DataImportHandlerÊÇÓÃÓÚ´ÓÊý¾Ý¿â»òÆäËûÔ´ÌáÈ¡Êý¾ÝµÄ³£ÓÃÄ£¿é £¬¸ÃÄ£¿éÖÐËùÓÐDIHÅäÖö¼Äܹ»Í¨¹ý±í²¿ÒªÇóµÄdataConfig²ÎÊýÀ´ÉèÖà £¬ÓÉÓÚDIHÅäÖÃÄܹ»Ô̺¬¾ç±¾ £¬Òò¶ø¸Ã²ÎÊý´æÔÚ°²È«Òþ»¼¡£¹¥»÷Õß¿ÉÀûÓÃdataConfig²ÎÊý»ú¹Ø¶ñÒâÒªÇó £¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ £¬ÇëÓйØÓû§¾¡¿ìÉý¼¶SolrÖÁ°²È«°æ±¾ £¬ÒÔÈ·±£¶Ô´Ë·ì϶µÄÓÐЧ·À»¤¡£¹¥»÷³É¹¦ £¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220607

 

ÊÂÎñÃû³Æ£º

HTTP_Éó¼ÆÊÂÎñ_ApacheCouchDB_banner·¢ÏÖ

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

ApacheCouchDBÊý¾Ý¿â £¬ËüÀàËÆÓÚRedis £¬CassandraºÍMongoDB £¬Ò²ÊÇÒ»¸öNoSQLÊý¾Ý¿â¡£CouchDB½«Êý¾Ý´æ´¢Îª·Ç¹ØÏµÐÔµÄJSONÎĵµ¡£ÕâʹµÃCouchDBµÄÓû§Äܹ»ÒÔÓëÏÖʵÊÀ½çÀàËÆµÄ·½Ê½À´´æ´¢Êý¾Ý¡£¹¥»÷Õßͨ¹ýĬÈ϶˿Ú4396µÄbannerÐÅÏ¢Äܹ»È·¶¨Ö¸±êϵͳ¡£Í¨¹ý4396¶Ë¿ÚÒà¿ÉÖ´ÐÐCVE-2022-24706¹¥»÷¡£

¸üй¦·ò£º

20220607

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Spring-Security-RegexRequestMatcher_ÈÏÖ¤ÈÆ¹ý

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

µ±SpringSecurityÖÐʹÓÃRegexRequestMatcher½øÐÐȨÏÞÅäÖà £¬Çҹ涨ÖÐʹÓôøµãºÅ(.)µÄÕýÔò±í°×ʽʱ £¬Î´¾­ÊÚȨµÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâÊý¾Ý°üÈÆ¹ýÉí·ÝÈÏÖ¤ £¬µ¼ÖÂÅäÖõÄȨÏÞÑé֤ʧЧ¡£

¸üй¦·ò£º

20220607

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Jenkins_Ô¶³ÌºÅÁîÖ´ÐÐ[CVE-2016-0792][CNNVD-201602-484]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Jenkins1.650֮ǰ°æ±¾ºÍLTS1.642.2֮ǰ°æ±¾ÖÐÓжà¸öδָ¶¨µÄAPI¶Ëµã £¬Ô¶³ÌÉí·ÝÑéÖ¤Óû§Äܹ»Í¨¹ýXMLÎļþÖÐÓëXStreamºÍgroovyÓйصÄÐòÁл¯Êý¾ÝÖ´ÐÐËÁÒâ´úÂë.

¸üй¦·ò£º

20220607

 

ÊÂÎñÃû³Æ£º

DNS_ľÂí_Kworkers_AutoUpdate_HolesWarmÍÚ¿óľÂí_³¢ÊÔÏνӿó³Ø(XMR)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö£º

¼ì²âµ½ÍÚ¿óľÂíKworkers³¢ÊÔÏνӿ󳨡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKworkersÍÚ¿óľÂí¡£KworkersÊÇÒ»¿î˫ƽ̨ÍÚ¿óľÂí £¬±ðÃûAutoUpdate»òHolesWarm £¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´ £¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üй¦·ò£º

20220607

 

 

Åú¸ÄÊÂÎñ

 

 

ÊÂÎñÃû³Æ£º

DNS_ÍÚ¿óÈ䳿_WannaMine_ÏνÓDNS·þÎñÆ÷ͨѶ

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö£º

¼ì²âµ½ÍÚ¿óÈ䳿WannaMineÏνÓDNS·þÎñÆ÷ͨѶ¡£WannamineÊÇÀûÓÃÓëNSAÓйصÄEternalBlue(ÓÀºãÖ®À¶)·ì϶½øÐд«²¼µÄ¼ÓÃÜÍÚ¿óÈ䳿¡£¾Ý×êÑÐÈËÔ±²âÊÔ £¬WannaMine¿ÉÄÜϰȾ´ÓWindows2000ÆðµÄËùÓÐWindowsϵͳ£¨Ô̺¬64λ°æ±¾ºÍWindowsServer2003£© £¬²¢Ê¹ÆäÉ豸»úÄÜÏÔÖø½µÂä¡£

¸üй¦·ò£º

20220607

 

ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_³¢ÊÔÀûÓÃËÁÒâÎļþ¶ÁÈ¡·ì϶

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

ÓÉÓÚÒ»Ð©ÍøÕ¾µÄÒµÎñ±ØÒª,ÍùÍù±ØÒªÌṩÎļþ¶ÁÈ¡»òÏÂÔØµÄÒ»¸öÄ£¿é,µ«ÈôÊÇûÓжԶÁÈ¡»òÏÂÔØ×öÒ»¸ö°×Ãûµ¥»òÕßȨÏÞÏÞ¶È £¬¿ÉÄܵ¼Ö¶ñÒâ¹¥»÷Õß¶ÁÈ¡ÏÂÔØÒ»Ð©Ãô¸ÐÐÅÏ¢(etc/passwdµÈ),¶Ô·þÎñÆ÷×öÏÂÒ»²½µÄ½ø¹¥ÓëÍþв¡£´ËÊÂÎñÄܹ»Í¨ÓÃÐԵؼì²â³¢ÊÔÀûÓÃËÁÒâÎļþ¶ÁÈ¡·ì϶µÄÐÐΪ¡£

¸üй¦·ò£º

20220607