Confluence õè¾¶´©Ô½·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-18

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3398 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì²úÆ·


Confluence Server

Confluence Data Center


Ó°Ïì°æ±¾


6.6.14֮ǰµÄËùÓа汾
ËùÓÐ6.7.x-6.11.x°æ±¾
6.12.4 ֮ǰµÄËùÓÐ6.12.x°æ±¾
6.13.4 ֮ǰµÄËùÓÐ6.13.x°æ±¾
6.14.3 ֮ǰµÄËùÓÐ6.14.x°æ±¾

6.15.2 ֮ǰµÄËùÓÐ6.15.x°æ±¾


·ì϶¸ÅÊö


4 Ô 17 ÈÕ £¬Atlassian Confluence ¹Ù·½°ä²¼°²È«¹«¸æ £¬½¨¸´ÁË´æÔÚÓÚ Confluence ÖеÄÒ»´¦õè¾¶´©Ô½·ì϶¡£
Confluence Server ºÍ Data Center ÔÚ downloadallattachments ×ÊÔ´ÖдæÔÚõè¾¶´©Ô½·ì϶¡£¹¥»÷Õßͨ¹ýÀûÓô˷ì϶ £¬Äܹ»ÔÚ·þÎñÆ÷ÉÏËÁÒâĿ¼ÉÏ´«Îļþ´Ó¶ø´ïµ½Ô¶³Ì´úÂëÖ´ÐеķçÏÕ¡£
´Ë·ì϶µÄÀûÓñØÒª¹¥»÷ÕßÕ¼ÓÐÒÔÏÂȨÏÞÖ®Ò»£º
1. ¿ÉÄÜÏòÒ³Ãæ»ò²©¿ÍÔö³¤¸½¼þ
2. ¿ÉÄÜ´´½¨ÐµĿռ䣨space£©

3. ¶Ôij¿Õ¼ä£¨space£©ÓÐ Admin ȨÏÞ


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


1¡¢Éý¼¶Confluence Server»òData Center°æ±¾£º
6.6.13
6.13.4
6.14.3

6.15.2


2¡¢Ö´Ðйٷ½»º½â´ëÊ©£º
ÖÕ³¡Confluence
±à×ë/conf/server.xml
ÈôÊÇÄãûÓÐΪ Confluence ÅäÖà context path £¬Ôò½«ÒÔÏ´úÂëÔö³¤ÖÁ ÔªËØÖУº
path="/pages/downloadallattachments.action" docBase="" >
className="org.apache.catalina.valapps.RemoteAddrValapp" deny="*" />

ÈôÊÇÄãΪ Confluence ÅäÖÃÁË context path £¬ºÃ±È˵ /wiki £¬Ôò±ØÒª½«ÒÔÏ´úÂëÔö³¤ÖÁ ÔªËØÖУº
path="/wiki/pages/downloadallattachments.action" docBase="" >


±£ÁôÎļþ £¬³ÁÆôConfluence
ÑéÖ¤»º½â´ëÊ©ÊÇ·ñÉúЧ£º
½Ó¼ûº¬ÓÐ2¸ö»òÒÔÉϸ½¼þµÄÒ³Ãæ/²©¿Í £¬µã»÷... > ¸½¼þ > ÏÂÔØÈ«Êý

Èô·µ»Ø404Ò³Ãæ £¬Ôò×¢Ã÷»º½â´ëÊ©ÒÑÉúЧ¡£


²Î¿¼Á´½Ó


https://confluence.atlassian.com/doc/confluence-security-advisory-2019-04-17-968660855.html