ÿÖÜÉý¼¶²¼¸æ-2022-06-21

°ä²¼¹¦·ò 2022-06-21

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Spring-Cloud-Gateway_´úÂë×¢Èë[CVE-2022-22947][CNNVD-202203-161]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

SpringCloudGatewayÊÇ»ùÓÚSpringFrameworkºÍSpringBoot¹¹½¨µÄAPIÍø¹Ø £¬ËüÖ¼ÔÚΪ΢·þÎñ¼Ü¹¹ÌṩһÖÖµ¥Ò»¡¢ÓÐЧ¡¢Í³Ò»µÄAPI·ÓÉÖÎÀí·½Ê½¡£·ì϶Ϊµ±SpringCloudGatewayÆôÓúͶ³öGatewayActuator¶Ëµãʱ £¬Ê¹ÓÃSpringCloudGatewayµÄÀûÓ÷¨Ê½¿ÉÊܵ½´úÂë×¢Èë¹¥»÷¡£¹¥»÷ÕßÄܹ»·¢ËÍÌØÔìµÄ¶ñÒâÒªÇó £¬´Ó¶øÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220621

 

ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_Jdk8u20_ÀûÓÃÁ´¹¥»÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃJdk8u20µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËJDK°æ±¾Îª8u20¼°ÒÔϰ汾 £¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë £¬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220621

 

ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_CommonsCollections7_ÀûÓÃÁ´¹¥»÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCommonsCollections7µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËcommons-collections3.1 £¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë £¬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220621


 

ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_CommonsCollections8_ÀûÓÃÁ´¹¥»÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCommonsCollections8µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËcommons-collections4 £¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë £¬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220621

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_H2_Database_Console_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2022-23221][CNNVD-202201-1749]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

H2DatabaseConsole£¨2.1.210°æ±¾Ö®Ç°£©ÖдæÔÚÒ»¸öÔ¶³ÌºÅÁîÖ´Ðзì϶ £¬¸Ã·ì϶¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýÔ̺¬IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT×Ó×Ö·û´®µÄjdbc:h2:memJDBCURLÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220621

 

ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_CommonsCollections9_ÀûÓÃÁ´¹¥»÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCommonsCollections9µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËcommons-collections3.1 £¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë £¬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220621

 

ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_CommonsCollections10_ÀûÓÃÁ´¹¥»÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCommonsCollections10µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËcommons-collections3.1 £¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë £¬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220621

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Discuz_1.5-2.5_ºÅÁîÖ´Ðзì϶[CVE-2018-14729][CVE-2018-14729][CNNVD-201905-886]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Discuz1.5-2.5°æ±¾Öкó¶ÜÊý¾Ý¿â±¸·ÝÖ°ÄÜÖдæÔÚÒ»¸öºÅÁîÖ´Ðзì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬»ñÈ¡·þÎñÆ÷ȨÏÞÖ´ÐÐËÁÒâºÅÁî £¬Ê¹¹¥»÷ÕßÄܹ»ÒÔWEBȨÏÞÔÚϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220621

 

½ØÍ¼20220623132255.png


ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Microsoft_SMB_»Ø¾ø·þÎñ·ì϶1[CVE-2022-32230][CNNVD-202006-681]

°²È«ÀàÐÍ£º

»Ø¾ø·þÎñ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú¿ÉÄÜÔÚ¶ÔÖ÷ÕÅÖ÷»ú½øÐÐCVE-2022-32230·ì϶ÀûÓõÄÐÐΪ £¬ÔÚSMBv3ÖдæÔÚÒ»¸ö¿ÕÖ¸ÕëÒýÓ÷ì϶ £¬¹¥»÷ÕßÄܹ»ÔÚδ¾­¹ýÉí·ÝÑéÖ¤µÄ2Çé¿öÏ £¬Í¨¹ýnetlogonµÈ²»±ØÒª½øÐÐÉí·ÝÑéÖ¤µÄ¹Ü·Զ³Ì·¢ËÍÊý¾ÝʵÏÖ·ì϶ÀûÓà £¬·ì϶ÀûÓóɹ¦ºó»áʹÊܺ¦ÕßÀ¶ÆÁ¡£

¸üй¦·ò£º

20220621


ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Microsoft_SMB_»Ø¾ø·þÎñ·ì϶2[CVE-2022-32230][CNNVD-202006-681]

°²È«ÀàÐÍ£º

»Ø¾ø·þÎñ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú¿ÉÄÜÔÚ¶ÔÖ÷ÕÅÖ÷»ú½øÐÐCVE-2022-32230·ì϶ÀûÓõÄÐÐΪ £¬ÔÚSMBv3ÖдæÔÚÒ»¸ö¿ÕÖ¸ÕëÒýÓ÷ì϶ £¬¹¥»÷ÕßÄܹ»ÔÚδ¾­¹ýÉí·ÝÑéÖ¤µÄ2Çé¿öÏ £¬Í¨¹ýnetlogonµÈ²»±ØÒª½øÐÐÉí·ÝÑéÖ¤µÄ¹Ü·Զ³Ì·¢ËÍÊý¾ÝʵÏÖ·ì϶ÀûÓà £¬·ì϶ÀûÓóɹ¦ºó»áʹÊܺ¦ÕßÀ¶ÆÁ¡£

¸üй¦·ò£º

20220621


ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Microsoft_SMB_»Ø¾ø·þÎñ·ì϶[CVE-2022-32230][CNNVD-202006-681]

°²È«ÀàÐÍ£º

»Ø¾ø·þÎñ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú¿ÉÄÜÔÚ¶ÔÖ÷ÕÅÖ÷»ú½øÐÐCVE-2022-32230·ì϶ÀûÓõÄÐÐΪ £¬ÔÚSMBv3ÖдæÔÚÒ»¸ö¿ÕÖ¸ÕëÒýÓ÷ì϶ £¬¹¥»÷ÕßÄܹ»ÔÚδ¾­¹ýÉí·ÝÑéÖ¤µÄ2Çé¿öÏ £¬Í¨¹ýnetlogonµÈ²»±ØÒª½øÐÐÉí·ÝÑéÖ¤µÄ¹Ü·Զ³Ì·¢ËÍÊý¾ÝʵÏÖ·ì϶ÀûÓà £¬·ì϶ÀûÓóɹ¦ºó»áʹÊܺ¦ÕßÀ¶ÆÁ¡£

¸üй¦·ò£º

20220621

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_LinuxºÅÁî×¢Èë¹¥»÷

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

ºÅÁî×¢Èë¹¥»÷ £¬ÊÇÖ¸ÕâÑùÒ»ÖÖ¹¥»÷¼¿Á© £¬ºÚ¿Íͨ¹ý°ÑϵͳºÅÁî²ÎÓëµ½webÒªÇóÒ³ÃæÍ·²¿ÐÅÏ¢ÖÐ £¬Ò»¸ö¶ñÒâºÚ¿ÍÒÔÀûÓÃÕâÖÖ¹¥»÷²½ÖèÀ´·¸·¨»ñÈ¡Êý¾Ý»òÕßÍøÂ硢ϵͳ×ÊÔ´¡£null

¸üй¦·ò£º

20220621


 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_GitLab_Ó²±àÂë·ì϶[CVE-2022-1162][CNNVD-202204-1842]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

GitLabÊÇÒ»¸öÓÃÓÚ²Ö¿âÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿ £¬Ê¹ÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß £¬¿Éͨ¹ýWeb½çÃæ½Ó¼û¹«¿ª»ò¸öÈËÏîÄ¿¡£ÔÚGitLabCE/EE°æ±¾14.7(14.7.7֮ǰ)¡¢14.8(14.8.5֮ǰ)ºÍ14.9(14.9.2֮ǰ)ÖÐʹÓÃOmniAuthÌṩÉÌ(ÈçOAuth¡¢LDAP¡¢SAML)×¢²áµÄÕÊ»§ÉèÖÃÁËÓ²±àÂëÃÜÂë £¬ÔÊÐí¹¥»÷ÕßDZÔڵؽÚÔìÕÊ»§¡£

¸üй¦·ò£º

20220621

 

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Linux.DDoS.Gafgyt_½ÚÔìºÅÁî

°²È«ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÃèÊö£º

¼ì²âµ½Gafgyt·þÎñÆ÷ÊÔͼ·¢ËͺÅÁî¸øGafgyt £¬Ö÷ÕÅIPÖ÷»ú±»Ö²ÈëÁËGafgyt¡£DDoS.GafgytÊÇÒ»¸öÀàLinuxƽ̨ϵĽ©Ê¬ÍøÂç £¬ÖØÒªÖ°ÄÜÊǶÔÖ¸¶¨Ö¸±ê»úеÌáÒéDDoS¹¥»÷¡£¶ÔÖ¸¶¨Ö¸±êÖ÷»úÌáÒéDDoS¹¥»÷¡£

¸üй¦·ò£º

20220621


 

ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃÊÂÎñ_·¢ÏÖÂÅ´Îunicode±àÂëÐÐΪ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

JavaĬÈϵıàÂ뷽ʽΪUnicode £¬ÔÚjava˵»°ºÍ²¿ÃÅ.net·¨Ê½ÖÐ £¬unicode±àÂë¿É±»×Ô¶¯´¦ÖýâÎö³É×Ö·û´®¡£ÂÅ´Îunicode±àÂë¿ÉÄÜΪ¹¥»÷Õß³¢ÊÔÈÆ¹ý¼ì²âÉ豸µÄÐÐΪ¡£

¸üй¦·ò£º

20220621