2020-03-24

°ä²¼¹¦·ò 2020-03-24

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_jackson-2658,2659-jackson-databind-JNDI×¢Èë-Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

CMS¹¥»÷¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9548]¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ

¸üй¦·ò£º

20200324








ÊÂÎñÃû³Æ£º

HTTP_ÁéͨOA_ÎļþÉÏ´«ÓëÎļþÔ̺¬µ¼ÖµĺÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚʹÓÃHTTP_ÁéͨOA_ÎļþÉÏ´«ÓëÎļþÔ̺¬µ¼ÖµĺÅÁîÖ´Ðзì϶¶ÔÖ÷ÕÅIPÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£ºÅÁîÖ´Ðзì϶ÊÇÓÉÁéͨOAÖдæÔÚµÄÁ½Ã¶·ì϶(ÎļþÉÏ´«·ì϶ £¬ÎļþÔ̺¬·ì϶)Ëùµ¼Ö¡£¸Ã·ì϶ÎÞÐèµÇ¼ £¬¹¥»÷ÕßÀûÓ÷ì϶¿É»ñÈ¡·þÎñÆ÷½ÚÔìȨ £¬·çÏÕÑϳÁ¡£

¸üй¦·ò£º

20200324










ÊÂÎñÃû³Æ£º

HTTP_Atlassian-Jira_ÐÅϢй¶[CVE-2019-8449]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýHTTP_Atlassian-Jira_ÐÅϢй¶[CVE-2019-8449]·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£

Atlassian Jira 8.4.0֮ǰ°æ±¾/rest/api/latest/groupuserpicker½Ó¿ÚÔÊÐíδÊÚȨ²éÎÊÔ±¹¤ÐÅÏ¢ £¬¹¥»÷ÕßÄܹ»Í¨¹ý±¬ÆÆÓû§ÃûÃûµ¥µÈ²½Öè»ñÈ¡Óû§ÐÅÏ¢

¸üй¦·ò£º

20200324










ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32.Wacatac_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíWacatac¡£

WacatacÊÇÒ»¸öÔ¶¿Ø·¨Ê½ £¬Äܹ»ÇÔÈ¡Êܺ¦Ö÷»úµÄÃô¸ÐÐÅÏ¢ £¬²¢½Ó¹ÜC2·þÎñÆ÷µÄºÅÁîÖ´ÐÐÉÏ´«ÏÂÔØÎļþ £¬¹ý³ÌÖÎÀíµÈÔ¶¿Ø²Ù×÷¡£

¸üй¦·ò£º

20200324










Åú¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

TCP_Jackson_Databind_¿ÉÒÉ·´ÐòÁл¯Àà_xbean[CVE-2020-8840]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃTCP_Jackson_databind_¿ÉÒÉ·´ÐòÁл¯À๥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£

¸üй¦·ò£º

20200324