2020-11-17
°ä²¼¹¦·ò 2020-11-18ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_JIRA_δÊÚȨSSRF·ì϶[CVE-2019-8451][CNNVD-201909-556] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | JIRAÊÇAtlassian¹«Ë¾³öÆ·µÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß£¬±»¿í·ºÀûÓÃÓÚȱµã¸ú×Ù¡¢¿Í»§·þÎñ¡¢ÐèÒªÍøÂç¡¢Á÷³ÌÉóÅú¡¢¹¤×÷¸ú×Ù¡¢ÏîÄ¿¸ú×ٺͻð¿ìÖÎÀíµÈ¹¤×÷ÁìÓò¡£JiraµÄ/plugins/servlet/gadgets/makeRequest×ÊÔ´´æÔÚSSRF·ì϶£¬ÔÒòÔÚÓÚJiraWhitelistÕâ¸öÀàµÄÂ߼ȱµã£¬³É¹¦ÀûÓô˷ì϶µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÒÔJira·þÎñ¶ËµÄÉí·Ý½Ó¼ûÄÚÍø×ÊÔ´¡£ |
¸üй¦·ò£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Nagios_XI_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-5791][CNNVD-202010-1115] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Nagios XIÊÇÒ»¸ö³ÉÁ¢ÔÚNagiosÖ÷ÌâÉÏµÄÆóÒµ¼¶¼à²âºÍ±¨¾¯¹æ»®µÄ¿ªÔ´×é¼þ¡£Ö°ÄÜÔ̺¬PHPÍøÕ¾½çÃæ¡¢×ۺϲû·¢Í¼¡¢¿É¶¨ÔìµÄÒDZí°å¡¢ÍøÂç½á¹¹¡¢ÅäÖÃGUI(ͼÐÎÓû§½Ó¿Ú)¡¢Óû§ÖÎÀíµÈ¡£Nagios XI 5.7.3ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðа²È«·ì϶£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÒÔ¡°apache¡±Óû§Ö´ÐÐËÁÒâºÅÁî¡£ |
¸üй¦·ò£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉ.NET·´ÐòÁл¯Êý¾Ý |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚ¶Ô¿ÉÄÜ´æÔÚ.NET·´ÐòÁл¯·ì϶µÄÒ³Ãæ·¢ËÍ¿ÉÒÉ·´ÐòÁл¯Êý¾Ý¡£ |
¸üй¦·ò£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_ÒÉËÆnodejs´úÂë×¢Èë |
°²È«ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÒÉËÆÔÚÀûÓÃnodejs´úÂë×¢Èë¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£ |
¸üй¦·ò£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_ActiveMQ_ËÁÒâÎļþÉÏ´«·ì϶[CVE-2016-3088][CNNVD-201605-596] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ActiveMQ ÊÇ Apache Èí¼þ»ù½ð»áϵÄÒ»¸ö¿ªÔ´ÐÂÎÅÇý¶¯ÖÐÑë¼þÈí¼þ¡£Jetty ÊÇÒ»¸ö¿ªÔ´µÄ servlet ÈÝÆ÷£¬ËüΪ»ùÓÚ Java µÄ web ÈÝÆ÷£¬ÀýÈç "font-family:ËÎÌå">ºÍ servlet ÌṩÔËÐл·¾³¡£ActiveMQ 5.0 ¼°ÒÔÀ´°æ±¾Ä¬Èϼ¯³ÉÁËjetty¡£ActiveMQ ÖÐµÄ FileServer ·þÎñÔÊÐíÓû§Í¨¹ý HTTP PUT ²½ÖèÉÏ´«Îļþµ½Ö¸¶¨Ä¿Â¼£¬¿ÉʹԶ³Ì¹¥»÷ÕßÓöñÒâ´úÂë´úÌæWebÀûÓã¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐÐÔ¶³Ì´úÂë¡£ |
¸üй¦·ò£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_´úÂëÖ´ÐÐ_yii·´ÐòÁл¯´úÂëÖ´ÐÐ[CVE-2020-15148][CNNVD-202009-926] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃyii·´ÐòÁл¯Ô¶³ÌºÅÁîÖ´Ðзì϶½øÐкÅÁîÖ´ÐеÄÐÐΪ¡£YiiÊÇÒ»¸ö¸ß»úÄܵÄPHP5µÄwebÀûÓ÷¨Ê½¿ª·¢¿ò¼Ü¡£Í¨¹ýÒ»¸öµ¥Ò»µÄºÅÁîÐй¤¾ß yiic Äܹ»¼±¾ç´´½¨Ò»¸öwebÀûÓ÷¨Ê½µÄ´úÂë¿ò¼Ü£¬¿ª·¢ÕßÄܹ»ÔÚÌìÉúµÄ´úÂë¿ò¼Ü»ù´¡ÉÏÔö³¤ÒµÎñÂß¼£¬ÒÔ¼±¾çʵÏÖÀûÓ÷¨Ê½µÄ¿ª·¢¡£ |
¸üй¦·ò£º | 20201117 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_fastjson_1.2.60_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´®£¬Ö§³Ö½«Java BeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã£¬ÀûÓÃÁìÓòºÜ¹ã¡£ |
¸üй¦·ò£º | 20201117 |
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_MSAServices.Bitter.Rat(ÂûÁ黨)_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½ BitterľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£ |
¸üй¦·ò£º | 20201117 |
ÊÂÎñÃû³Æ£º | TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-2551] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-2551£©£¬Oracle WebLogicÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-2551£©£¬ÊÔͼͨ¹ýGIOPºÍ̸´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£·ì϶´æÔÚµÄweblogic°æ±¾:10.3.6.0.012.1.3.0.012.2.1.3.012.2.1.4.0ÈôÊDZ»¹¥»÷»úеûÓÐÉý¼¶ÏàÓ¦µÄ²¹¶¡£¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£³¢ÊÔ½øÐжñÒâºÅÁî»ò´úÂë×¢È룬Զ³ÌÖ´ÐÐËÁÒâ´úÂë¡£ |
¸üй¦·ò£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃ_Ŀ¼´©Ô½·ì϶[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902] [CNNVD-201904-1243/CNNVD-202006-075/CNNVD-201912-908/CNNVD-202007-053] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚ³¢ÊÔ¶ÔÖ÷ÕÅIPÖ÷»ú½øÐÐĿ¼´©Ô½·ì϶¹¥»÷³¢ÊÔµÄÐÐΪ¡£Ä¿Â¼´©Ô½·ì϶ÄÜʹ¹¥»÷ÕßÈÆ¹ýWeb·þÎñÆ÷µÄ½Ó¼ûÏÞ¶È£¬¶Ôweb¸ùĿ¼ÒÔ±íµÄÎļþ¼Ð£¬ËÁÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£ |
¸üй¦·ò£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_fastjson_1.2.61_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅIPÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´®£¬Ö§³Ö½«Java BeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã£¬ÀûÓÃÁìÓòºÜ¹ã¡£ |
¸üй¦·ò£º | 20201117 |


¾©¹«Íø°²±¸11010802024551ºÅ