ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ01ÖÜ

°ä²¼¹¦·ò 2020-01-06

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê12ÔÂ30ÈÕÖÁ2020Äê01ÔÂ05ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Solr VelocityÄ£°å´úÂë×¢Èë·ì϶; Tencent WeChatÓû§ÃûºÅÁî×¢Èë·ì϶£»ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´Ðзì϶£»Nagios XI schedulereport.php SHELLºÅÁî×¢Èë·ì϶£»Cisco Data Center Network Manager SOAP API OSºÅÁî×¢Èë·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇNagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©£»ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû£»ÎïÁªÍø¹©¸øÉÌWyzeÒâ±íй¶Լ240Íò¿Í»§ÐÅÏ¢£»°®¶ûÀ¼µ±¾Ö°ä²¼2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ£»ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬¿É½Ó¼ûÄÚ²¿ÏµÍ³¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí


1. Apache Solr VelocityÄ£°å´úÂë×¢Èë·ì϶


Apache Solr VelocityÄ£°åVelocityResponseWriter´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Í¨¹ý½ç˵һ¸ö½«¸ÃÅäÖÃÉèÖÃΪ "true" µÄÏìӦдÈëÆ÷À´ÆôÓà "parms .resource.loader. loader¡±£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£

https://issues.apache.org/jira/browse/SOLR-13971


2. Tencent WeChatÓû§ÃûºÅÁî×¢Èë·ì϶


Tencent WeChat½âÎöusernames´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-19-1035/


3. ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´Ðзì϶


ALE Alcatel-Lucent OmnivistaʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»SYSTEMÓû§Éí·ÝÖ´ÐдúÂë¡£

https://packetstormsecurity.com/files/155595/Alcatel-Lucent-Omnivista-8770-Remote-Code-Execution.html


4. Nagios XI schedulereport.php SHELLºÅÁî×¢Èë·ì϶


Nagios XI schedulereport.php´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâSHELLºÅÁî¡£

https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html


5. Cisco Data Center Network Manager SOAP API OSºÅÁî×¢Èë·ì϶


Cisco Data Center Network Manager SOAP API´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâOSºÅÁî²¢Ö´ÐС£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject


>³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Nagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¹æ»®¡£¸Ã¹æ»®Ö§³Ö¶ÔÀûÓᢷþÎñ¡¢²Ù×÷ϵͳµÈ½øÐÐ¼à¿ØºÍÔ¤¾¯¡£@Cody SixteenÔÚTwitter°ä²¼ÁËÓйØNagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©µÄÓйØÐÅÏ¢£¬¸Ã·ì϶ӰÏìÁËNagios XI 5.6.9°æ±¾£¬¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»Í¨¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊý£¬ÔÚWeb·þÎñÆ÷Óû§ÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ²Ù×÷ϵͳºÅÁĿǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©¡£


Ô­ÎÄÁ´½Ó£º

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534


2¡¢ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢Èí³É¹¦ÊÕÊÜÁËÓɳ¯ÏʺڿÍ×éÖ¯APT37½ÚÔìµÄ50¸öÓòÃû£¬ÕâЩÓòÃû±»¸Ã×éÖ¯ÓÃÀ´ÌáÒéÍøÂç¹¥»÷£¬Ô̺¬·¢ËÍ´¹µöÓʼþºÍÍйܴ¹µöÒ³ÃæµÈ¡£Î¢Èí°µÊ¾ÆäÊý×Ö·¸×ﲿÃÅ£¨DCU£©ºÍÍþвµý±¨ÖÐÐÄ£¨MSTIC£©ÒѾ­¼à¶½APT37³¤´ïÊýԵŦ·ò£¬²¢ÓÚ12ÔÂ18ÈÕÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¸Ã×éÖ¯Ìá¸æ×´ËÏ¡£¸Ã·¨ÔºÊÚÓè΢ÈíȨÏÞÒÔÊÕÊÜAPT37ÔÚ·¸×ï»î¶¯ÖÐʹÓõÄ50¸öÓòÃû¡£Î¢Èí¸ß¹Ü°µÊ¾¸Ã×éÖ¯µÄ´óÎÞÊýÖ¸±ê¶¼Î»ÓÚÃÀ¹ú¡¢ÈÕ±¾ÒÔ¼°º«¹ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-takes-down-50-domains-operated-by-north-korean-hackers/


3¡¢ÎïÁªÍø¹©¸øÉÌWyzeÒâ±íй¶Լ240Íò¿Í»§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎïÁªÍø¹©¸øÉÌWyzeÈ·ÈÏÆäÒ»¸öElasticsearch·þÎñÆ÷й¶ÁËÔ¼240ÍòÓû§µÄ¾ßÌåÐÅÏ¢¡£¸ÃÊý¾Ý¿â²¢²»Êdzö²úϵͳ£¬µ«´æ´¢ÁËÓÐЧµÄÓû§Êý¾Ý£¬Ô̺¬ÓÃÓÚ´´½¨WyzeÕÊ»§µÄµç×ÓÓʼþµØÖ·¡¢·ÖÅ䏸ÆäWyze°²È«ÉãÏñ»úµÄÓû§êdzơ¢WiFiÍøÂç±êʶ·ûSSIDÒÔ¼°2.4ÍòÓû§µÄAlexaÁîÅÆµÈ¡£¸ÃÊý¾Ý¿âÓÚ12ÔÂ4ÈÕ±»ÃýÎóµØÂ¶³öÔÚ¹«ÍøÉÏ£¬°²È«¹«Ë¾Twelve SecurityÓÚ12ÔÂ26ÈÕ·¢ÏÖÁ˸ÃÊý¾Ý¿â²¢Í¨ÖªÁËWyze£¬WyzeËæºó¶ÔÊý¾Ý¿â½øÐÐÁ˱£»¤¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/iot-vendor-wyze-confirms-server-leak/


4¡¢°®¶ûÀ¼µ±¾Ö°ä²¼2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°®¶ûÀ¼µ±¾Ö°ä²¼ÁË¡¶2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ¡·£¬ÕâÊǸùúÓÚ2015Äê°ä²¼µÄÊ׸ö°²È«Õ½ÊõµÄ¸üа汾¡£¸ÃÕ½Êõ»ã±¨¸ÅÊöÁ˵±¾Ö½«ÈôºÎ³ÖÐøÍÆ½ø¸Ã¹úÍÆËã»úÍøÂçºÍÓйػù´¡ÉèÊ©µÄ°²È«¡£»ã±¨ÖвûÁËÈ»µ±¾Ö¶Ô°²È«ºÍ¿¿µÃסµÄÍøÂç¿Õ¼äµÄÔ¸¾°ÒÔ¼°½«²ÉÈ¡µÄÐж¯£¬Ô̺¬³ÖÐøÌá¸ß¹Ø¼ü»ù´¡¼Ü¹¹ºÍ¹«¹²·þÎñÖеÄÍøÂ絯ÐÔ£»Ìá¸ßÆóÒµºÍ¹«Ãñ¶ÔÍøÂ簲ȫ³ÁÒªÐÔµÄÒâʶ£»Í¨¹ýÓë½ÌÓýϵͳ¡¢ÐÐÒµºÍѧÊõ½çµÄºÏ×÷£¬½øÒ»²½·¢Õ¹È«Éç»áµÄÍøÂ簲ȫÎÄ»¯£»³ÖÐø¼áÈͰ®¶ûÀ¼×÷Ϊ¼¼ÊõºÍÐÅÏ¢°²È«ÖÐÐĵÄÈ«ÇòÃûÓþ£¬²¢Ô®ÊÖÍÆ½ø°®¶ûÀ¼³ÉΪICTÆóÒµµÄÊ×Ñ¡µØÖ·¡£¸Ã»ã±¨»¹¶½ÍƽøÐж¦ÐÂÒÔ±£»¤¹Ø¼ü»ù´¡¼Ü¹¹ÃâÊܳÁ´óÍøÂçÍþвµÄÓ°Ï죬ͬʱ»¹ÖÒ¸æ³Æ±í¹ú¿ÉÄÜ»á¹ýÎʰ®¶ûÀ¼µÄÑ¡¾Ù¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95825/laws-and-regulations/irish-national-cyber-security-strategy.html


5¡¢ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬¿É½Ó¼ûÄÚ²¿ÏµÍ³


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×¨¼ÒVinoth KumarÔÚÒ»¸ö¹«¿ª¿ÉÓõÄGithub´æ´¢¿âÖз¢ÏÖÐǰͿ˵ÄÒ»¸öAPIÃÜÔ¿ÔÚÏß¶³ö£¬¹¥»÷ÕßÄܹ»ÀûÓøÃÃÜÔ¿À´½Ó¼û¹«Ë¾µÄÄÚ²¿ÏµÍ³²¢´Û¸ÄÊÚȨÓû§Áбí¡£¸ÃÃÜÔ¿¿ÉÓÃÓÚ½Ó¼ûÐǰͿËJumpCloud API£¬JumpCloudÊÇÒ»¸öActive DirectoryÖÎÀíÆ½Ì¨£¬ÌṩÓû§ÖÎÀí¡¢WebÀûÓ÷¨Ê½µ¥µãµÇ¼£¨SSO£©½Ó¼û½ÚÔìºÍÇáÐÍĿ¼½Ó¼ûºÍ̸£¨LDAP£©·þÎñ¡£Kumar»¹ÌṩÁ˸ÃÎÊÌâµÄPoC´úÂ룬ÑÝʾÁËÈôºÎÁгöϵͳºÍÓû§¡¢½ÚÔìAWSÕÊ»§¡¢ÔÚϵͳÉÏÖ´ÐкÅÁîÒÔ¼°Ôö³¤»òɾ³ýÓÐȨ½Ó¼ûÄÚ²¿ÏµÍ³µÄÓû§¡£ÐǰͿËÈ·ÈÏÁËÕâÒ»ÎÊÌⲢѸ¿ì³·ÏúÁ˸ÃÃÜÔ¿¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95826/security/starbucks-api-key-exposed-online.html