ÿÖÜÉý¼¶²¼¸æ-2022-10-25
°ä²¼¹¦·ò 2022-10-25ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_PropertyPathFactoryBean_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃSnakeYAMLµÄPropertyPathFactoryBean·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_DefaultBeanFactoryPointcutAdvisor_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃSnakeYAMLµÄDefaultBeanFactoryPointcutAdvisor·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_CommonsConfiguration_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃSnakeYAMLµÄCommonsConfiguration·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Grafana_8.3.0_Îļþ¶ÁÈ¡[CVE-2021-43798][CNNVD-202112-482] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃGrafana8.0.0-8.3.0°æ±¾ÖдæÔÚµÄÎļþ¶ÁÈ¡·ì϶£¬´Ó¶øÔÚδÊÚȨµÄÇé¿ö϶Áȡָ±êϵͳÃô¸ÐÎļþ¡£GrafanaÊÇÒ»¸ö¿çƽ̨¡¢¿ªÔ´µÄÊý¾Ý¿ÉÊÓ»¯ÍøÂçÀûÓ÷¨Ê½Æ½Ì¨¡£Óû§ÅäÖÃÏνӵÄÊý¾ÝÔ´Ö®ºó£¬GrafanaÄܹ»ÔÚÍøÂçä¯ÀÀÆ÷ÀïÏÔʾÊý¾Ýͼ±íºÍÖÒ¸æ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_HTTP_ɨÃè |
°²È«ÀàÐÍ£º | °²È«É¨Ãè |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓöÔÖ÷ÕÅÖ÷»úÊÔͼͨ¹ýNMAP»ñÈ¡¶ÔÓ¦Ö÷»úhttp·þÎñÆ÷°æ±¾ºÍ¶ÔÓ¦³§É̵ÄÐÐΪ¡£Õâ¿ÉÄܻᵼÖÂϵͳй¶ÓйØÐÅÏ¢¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_FortiOS_7.2.1_ȨÏÞÈÆ¹ý[CVE-2022-40684][CNNVD-202210-347] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃFortiOS7.2.1¼°ÒÔϰ汾£¬FortiProxy7.2.0¼°ÒÔϰ汾£¬FortiSwitchManager7.2.0¼°ÒÔϰ汾ÖдæÔÚµÄȨÏÞÈÆ¹ý·ì϶£¬ÔÚδÊÚȨµÄÇé¿öÏÂÅú¸ÄÓû§µÄssh¹«Ô¿£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_·ì϶ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âÀûÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÖ÷ÕÅÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´Ðзì϶½øÐÐÀûÓÃÁ´±©ÆÆ¹¥»÷¡£ApacheShiro£¨·ì϶°æ±¾<=1.2.4£©ÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí |
¸üй¦·ò£º | 20221025 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Struts2_S2-032_´úÂëÖ´ÐÐ[CVE-2016-3081] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃStruts2.3.20-StrutsStruts2.3.28(2.3.20.3ºÍ2.3.24.3Ö®±í)ÖдæÔڵĴúÂëÖ´Ðзì϶£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£Struts2ÊÇÒ»¸ö¼ò½àµÄ¡¢¿ÉÀ©´óµÄ¿ò¼Ü£¬¿ÉÓÃÓÚ´´½¨ÆóÒµ¼¶JavawebÀûÓ÷¨Ê½¡£Éè¼ÆÕâ¸ö¿ò¼ÜÊÇΪÁË´Ó¹¹½¨¡¢²¿Êð¡¢µ½ÀûÓ÷¨Ê½ÊØ»¤·½ÃæÀ´¼ò»¯Õû¸ö¿ª·¢ÖÜÆÚ¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_Weblogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2801] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃOracleWeblogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶£¬Ê¹ÓÃt3ºÍ̸·¢ËͶñÒâµÄÐòÁл¯Êý¾Ý£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£WeblogicÊÇĿǰȫÇòÊг¡ÉÏÀûÓÃ×î¿í·ºµÄJ2EE¹¤¾ßÖ®Ò»£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÀûÓ÷¨Ê½·þÎñÆ÷£¬ÆäÓÃÓÚ¹¹½¨J2EEÀûÓ÷¨Ê½£¬Ö§³ÖÐÂÖ°ÄÜ£¬¿É½µµÍÔËÓª³É±¾£¬Ìá¸ß»úÄÜ£¬¼ÓÇ¿¿ÉÀ©´óÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ÓÃÓÑNC6.5_XbrlPersistenceServlet_·´ÐòÁл¯_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | Äܹ»ÐÐΪ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃÓÃÓÑNC6.5ÖÐXbrlPersistenceServlet½Ó¿Ú´æÔڵķ´ÐòÁл¯·ì϶£¬Ê¹ÓÃURLDNSÀûÓÃÁ´Ì½²â¸Ã·ì϶ÊÇ·ñ´æÔÚ¡£ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¹æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯ÀûÓü¯³É¡±µÄÖÎÀíÒµÎñÀíÏë¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯ÀûÓÃϵͳµÄÊ×Ñ¡¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-36189¡¢CVE-2020-36188¡¢CVE-2019-14439¡¢CVE-2019-14361] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | JacksonÊÇÒ»¸ö¿ÉÄܽ«java¶ÔÏóÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²¿ÉÄܽ«JSON×Ö·û´®·´ÐòÁл¯Îªjava¶ÔÏóµÄ¿ò¼Ü¡£¹¥»÷Õß¿ÉÄÜÀûÓÃjacksonµÄ¿ÉÒÉ·´ÐòÁл¯Ààlogback¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2883] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃWebLogicServer10.3.6.0.0£¬12.1.3.0.0£¬12.2.1.3.0£¬12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶£¬´Ó¶ø»ñȡָ±êϵͳµÄȨÏÞ¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplicationserver£¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖÐÑë¼þ£¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀí´óÐÍÉ¢²¼Ê½WebÀûÓá¢ÍøÂçÀûÓúÍÊý¾Ý¿âÀûÓõÄJavaÀûÓ÷þÎñÆ÷¡£½«JavaµÄ¶¯Ì¬Ö°ÄܺÍJavaEnterprise³ß¶ÈµÄ°²È«ÐÔÒýÈë´óÐÍÍøÂçÀûÓõĿª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀíÖ®ÖС£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-8840][CNNVD-202002-354] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | JacksonÊÇÒ»¸ö¿ÉÄܽ«java¶ÔÏóÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²¿ÉÄܽ«JSON×Ö·û´®·´ÐòÁл¯Îªjava¶ÔÏóµÄ¿ò¼Ü¡£´Ë·ì϶Öй¥»÷Õß¿ÉÀûÓÃxbean-reflectµÄÀûÓÃÁ´´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ´Ó¶ø´ïµ½Ô¶³Ì´úÂëÖ´ÐС£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Zabbix_Ó×ÓÚ4.4_δÊÚȨ½Ó¼û |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃZabbixÓ×ÓÚ4.4°æ±¾ÖдæÔÚµÄΪδÊÚȨ½Ó¼û·ì϶£¬´Ó¶øÔÚδ¾ÊÚȨµÄÇé¿öϽӼûZabbix·þÎñÆ÷ÉϵÄÊý¾Ý£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Struts2_S2-055_REST_JacksonLibrary_´úÂëÖ´ÐÐ[CVE-2017-7525] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | Tomcat·þÎñÆ÷ÊÇÒ»¸öÃâ·ÑµÄÊ¢¿ªÔ´´úÂëµÄWebÀûÓ÷þÎñÆ÷¡£Struts2ÊÇApacheÈí¼þ»ù½ð»áÕÆ¹ÜÊØ»¤µÄÒ»¿îÓÃÓÚ´´½¨ÆóÒµ¼¶JavaWebÀûÓõĿªÔ´¿ò¼Ü¡£Struts2ÔÚv2.5-v2.5.14£¬¹¥»÷Õßͨ¹ýŲÓÃREST²å¼þÖеĴæÔÚ·´ÐòÁл¯·ì϶µÄJacksonLibraryÀ´´¦ÖÃJSONÊý¾Ý£¬´Ó¶ø´¥·¢·´ÐòÁл¯·ì϶¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÐÅϢй¶_PACSOne_Server_6.6.2_DICOM_Web_Viewer_Ŀ¼±éÀú |
°²È«ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýPACSOneServerÖдæÔÚµÄĿ¼±éÀú·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúnocache.php¾ç±¾µÄ¡®path¡¯²ÎÊýÖеġ®..¡¯×Ö·ûÀûÓø÷ì϶¶ÁÈ¡ËÁÒâÎļþ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_ÁéͨOA_print.php_Îļþɾ³ý |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃÁéͨOAµÄV11.6¼°ÒÔǰµÄ°æ±¾´æÔÚµÄÎļþɾ³ý·ì϶½øÐй¥»÷¡£ÁéͨOAÊÇOfficeAnywhereµÄ¼ò³Æ£¬¸Ãϵͳѡȡµ±ÏȵÄB/S(ä¯ÀÀÆ÷/·þÎñÆ÷)²Ù×÷·½Ê½£¬Ê¹µÃÍøÂç°ì¹«²»ÊܵØÓòÏÞ¡£OfficeAnywhereѡȡ»ùÓÚWEBµÄÆóÒµÍÆË㣬Ö÷HTTP·þÎñÆ÷ѡȡÁËÊÀ½çÉÏ×îÏȽøµÄApache·þÎñÆ÷£¬»úÄܲ»±ä¿¿µÃס¡£Êý¾Ý´æÈ¡¼¯ÖнÚÔ죬Ԥ·ÀÁËÊý¾Ýй©µÄ¿ÉÄÜ¡£ÌṩÊý¾Ý±¸·Ý¹¤¾ß£¬±£»¤ÏµÍ³Êý¾Ý°²È«¡£¶à¼¶µÄȨÏÞ½ÚÔ죬ÃÀÂúµÄÃÜÂëÑéÖ¤ÓëµÇ¼ÑéÖ¤»úÔìÔ½·¢Ç¿ÁËϵͳ°²È«ÐÔ¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14645][CVE-2020-14625][CVE-2020-14644][CVE-2020-14687] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃOracleWebLogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÆäËü¿ÉÒÉÐÐΪ_PHPαºÍ̸ |
°²È«ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚʹÓÃPHPµÄһЩ·â×°ºÍ̸£¬Èçphp://input,php://filterµÈÌá½»Ò»¾ä»°Ä¾Âí£¬»òÔ¶³ÌÖ´ÐкÅÁîÀ´¹¥»÷Êܺ¦Õß·þÎñÆ÷£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-1000353] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃJenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶½øÐй¥»÷£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£JenkinsÊÇÒ»¸ö¿ÉÀ©´óµÄ¿ªÔ´³ÖÐø¼¯³É·þÎñÆ÷£¬ÔںöàÆóÒµµÄÄÚÍøÖж¼²¿ÊðÁËÕâ¸öϵͳ¡£Jenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòJenkinsCLI´«µÝÐòÁл¯µÄJava¡®SignedObject¡¯¶ÔÏóÀûÓø÷ìÏ¶ÈÆ¹ý»ùÓÚºÚÃûµ¥µÄ±£»¤»úÔì¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2015-8103] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃJenkins1.637¼°Ö®Ç°°æ±¾¡¢JenkinsLTS1.625.1¼°Ö®Ç°°æ±¾´æÔڵķ´ÐòÁл¯·ì϶½øÐдúÂëÖ´Ðй¥»÷£¬´Ó¶ø»ñȡָ±êÖ÷»úȨÏÞ¡£JenkinsÊÇÒ»¸ö¿ÉÀ©´óµÄ¿ªÔ´³ÖÐø¼¯³É·þÎñÆ÷¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JBossMQ_JMS·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-7504][CNNVD-201705-937] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | RedHatJBossApplicationServerÊÇÒ»¿î»ùÓÚJavaEEµÄ¿ªÔ´ÀûÓ÷þÎñÆ÷¡£JBossAS4.x¼°Ö®Ç°°æ±¾ÖУ¬JbossMQʵÏÖ¹ý³ÌµÄJMSoverHTTPInvocationLayerµÄHTTPServerILServlet.javaÎļþ´æÔÚ·´ÐòÁл¯·ì϶£¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÔìµÄÐòÁл¯Êý¾ÝÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JACKSON-databind_2670_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-11113][CNNVD-202003-1735] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÔÚÀûÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´Ðзì϶ÏòÖ÷ÕÅip½øÐз´ÐòÁл¯¹¥»÷£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îºÏÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßº±¼û¾Ý°ó¶¨Ö°ÄܵÄ×é¼þ¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_InfluxDB_δÊÚȨ½Ó¼û |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | influxdbÊÇÒ»¿î³ÛÃûµÄʱÐòÊý¾Ý¿â£¬ÆäʹÓÃjwt×÷Ϊ¼øÈ¨·½Ê½¡£ÔÚÓû§¿ªÆôÁËÈÏÖ¤£¬µ«Î´ÉèÖòÎÊýshared-secretµÄÇé¿öÏ£¬jwtµÄÈÏÖ¤ÃÜԿΪ¿Õ×Ö·û´®£¬´Ëʱ¹¥»÷ÕßÄܹ»Î±ÔìËÁÒâÓû§Éí·ÝÔÚinfluxdbÖÐÖ´ÐÐSQLÓï¾ä¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_IncomCMS_2.0_ÎļþÉÏ´«[CVE-2020-29597][CNNVD-202012-431] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | IncomCMS2.0ÒÔ¼°Ö®Ç°µÄ°æ±¾´æÔÚÎļþÉÏ´«·ì϶£¬¹¥»÷ÕßÄܹ»ÉÏ´«webshell»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Docker_Remote_API_δÊÚȨ½Ó¼û |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃDockerRemoteAPIÅäÖò»Æäʱµ¼ÖµÄδÊÚȨ½Ó¼û·ì϶dockerclient»òÕßhttpÖ±½ÓÒªÇó½Ó¼ûÕâ¸öAPI£¬´Ó¶øÖ±½Ó½Ó¼ûËÞÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢£¬»ò¶ÔÃô¸ÐÎļþ½øÐÐÅú¸Ä£¬×îÖÕÆëÈ«½ÚÔì·þÎñÆ÷¡£DockerRemoteAPIÊÇÒ»¸öÈ¡´úÔ¶³ÌºÅÁîÐнçÃæ£¨rcli£©µÄRESTAPI¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ShiroAttack¹¤¾ßʹÓÃ_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÖ÷ÕÅÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´Ðзì϶½øÐй¥»÷¡£ApacheShiro£¨·ì϶°æ±¾<=1.2.4£©ÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨºÅÁî×¢Èë |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬exportovpn½Ó¿Ú´æÔÚºÅÁî×¢È룬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâºÅÁî¡£ |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_·ì϶ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ_ÄÚ´æÂí×¢Èë_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÖ÷ÕÅÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´Ðзì϶½øÐÐÀûÓ㬲¢ÔÚÒªÇóÌ崦עÈëÄÚ´æÂí¡£ApacheShiro£¨·ì϶°æ±¾<=1.2.4£©ÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí |
¸üй¦·ò£º | 20221025 |
ÊÂÎñÃû³Æ£º | TCP_·ì϶ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âÀûÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÖ÷ÕÅÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´Ðзì϶½øÐÐÀûÓÃÁ´±©ÆÆ¹¥»÷¡£ApacheShiro£¨·ì϶°æ±¾<=1.2.4£©ÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí |
¸üй¦·ò£º | 20221025 |


¾©¹«Íø°²±¸11010802024551ºÅ