ÿÖÜÉý¼¶²¼¸æ-2023-03-21
°ä²¼¹¦·ò 2023-03-21
ÊÂÎñÃû³Æ£º | HTTP_·ì϶ÀûÓÃ_SSRF_Microsoft_Exchange_ProxyLogon_ɨÃè[CVE-2021-26855][CNNVD-202103-192][CVE-2021-26855] |
°²È«ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º | MicrosoftExchangeÖÐÔ̺¬ÁËÊý¸ö°²È«·ì϶£¬¹¥»÷ÕßÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öÏ£¬Äܹ»Í¨¹ý½áºÏʹÓÃÊý¸ö·ì϶À´ÈƹýExchangeǰ¶ËºÍÉí·ÝÏÞ¶È£¬ÉÏ´«¶ñÒâÎļþµ½Exchange·þÎñÆ÷ÉÏ£¬¸Ã·ì϶Á´¼´±»³ÆÎªProxyLogon£¬¸ÃÊÂÎñ¼ì²â¶ÔÆäÖеÄSSRF·ì϶ɨÃèÐÐΪ£¬¹¥»÷ÕßÄܹ»Í¨¹ý¸Ã·ì϶ÌáÉýȨÏÞ²¢Ö±½Ó½Ó¼ûºó¶Ë¡£ |
¸üй¦·ò£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_·ì϶ÀûÓÃ_ºÅÁîÖ´ÐÐ_Bitbucket-Server&Data-Center_»·¾³±äÁ¿×¢Èë |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ö÷»úÔÚÊܵ½Bitbucket-Server&Data-Center»·¾³±äÁ¿×¢È룬¿Éµ¼ÖÂËÁÒâºÅÁîÖ´ÐС£¸Ã·ì϶ÊÇͨ¹ý»·¾³±äÁ¿Òý·¢µÄºÅÁî×¢Èë·ì϶£¬¿Éµ¼ÖÂÓµÓÐȨÏ޵Ĺ¥»÷Õß½ÚÔìÓû§Ãû£¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐдúÂë¡£×÷Ϊһʱ»º½â´ëÊ©£¬Atlassian¹«Ë¾½¨ÒéÓû§¹Ø¹Ø¡°¹«¿ª×¢²á¡±Ñ¡Ïî¡£°²È«²¼¸æÖ¸³ö£¬¡°½ûÓù«¿ª×¢²á½«Ê¹¹¥»÷ÏòÁ¿´ÓδÈÏÖ¤¹¥»÷¸ü¸ÄΪÈÏÖ¤¹¥»÷£¬´Ó¶ø½µµÍÀûÓ÷çÏÕ¡£¾ÖÎÀíÔ±»òϵͳÖÎÀíÔ±ÈÏÖ¤µÄÓû§¿ÉÄÜÔÚ½ûÓù«¿ª×¢²áÑ¡ÏîʱÀûÓø÷ì϶¡£ |
¸üй¦·ò£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·çÏÕ_¿ÉÒÉÐÐΪ_esi±êǩҪÇó |
°²È«ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÃèÊö£º | EdgeSideIncludes(ESI)ÊÇÒ»ÖÖÏóÕ÷˵»°£¬ÖØÒªÔÚ³£¼ûµÄHTTP´úÀí£¨·´Ïò´úÀí¡¢¸ºÔØÆ½ºâ¡¢»º´æ·þÎñÆ÷¡¢´úÀí·þÎñÆ÷£©ÖÐʹÓá£Í¨¹ýESI×¢Èë¼¼ÊõÄܹ»µ¼Ö·þÎñ¶ËÒªÇóαÔ죨SSRF£©£¬ÈƹýHTTPOnlycookieµÄ¿çÕ¾¾ç±¾¹¥»÷£¨XSS£©ÒÔ¼°·þÎñ¶Ë»Ø¾ø·þÎñ¹¥»÷¡£Í¨¹ý²âÊÔ£¬Óм¸Ê®ÖÖÖ§³Ö´¦ÖÃESIµÄ²úÆ·£ºVarnish£¬SquidProxy£¬IBMWebSphere£¬OracleFusion/WebLogic£¬Akamai£¬Fastly£¬F5£¬Node.jsESI£¬LiteSpeedºÍÒ»Ð©ÌØ¶¨Ëµ»°²å¼þ£¬µ«²¢²»ÊÇÕâЩ²úƷĬÈÏÆôÓÃÁËESI¡£ |
¸üй¦·ò£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_RichFaces[CVE-2018-14667] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | RichFacesÊÇÒ»¸ö»ùÓÚLGPLºÍ̸ʢ¿ªÔ´´úÂëµÄJSF£¨JavaServerFaces£©×é¼þ¿â£¬Ëü¿ÉÄÜʹÀûÓÿª·¢·½±ãµØ¼¯³ÉAJAX¡£´Ë¿ÌµÄRichFaces¿âÊÇÓÉAjax4jsfºÍRichFacesÁ½²¿ÃÅ×é³É¡£JavaRichFaces¿ò¼ÜÖÐÔ̺¬Ò»¸öRCE·ì϶,¹¥»÷Õ߿ɻú¹ØÔ̺¬org.ajax4jsf.resource.UserResource$UriDataÐòÁл¯¶ÔÏóµÄÌØ¶¨UserResourceÒªÇó£¬RichFaces»áÏÈ·´ÐòÁл¯¸ÃUriData¶ÔÏ󣬶øºóʹÓÃEL±í°×ʽ½âÎö²¢»ñÈ¡resourceµÄmodified¡¢expiresµÈÖµµ¼ÖÂÁËËÁÒâEL±í°×ʽִÐУ¬Í¨¹ý»ú¹ØÌØÊâµÄEL±í°×ʽ¿ÉʵÏÖÔ¶³ÌËÁÒâ´úÂëÖ´ÐС£ |
¸üй¦·ò£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Õã½ÓîÊӿƼ¼ÍøÂçÊÓÆµÂ¼Ïñ»ú_LogReport.php |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÔÚÀûÓÃÕã½ÓîÊӿƼ¼ÍøÂçÊÓÆµÂ¼Ïñ»úµÄ·ì϶½øÐдúÂëÖ´Ðй¥»÷£» |
¸üй¦·ò£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_·ì϶ÀûÓÃ_ÐÅϢй¶_Ametys_auto-completion_plugin[CVE-2022-26159] |
°²È«ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÔÚÀûÓÃAmetys_CMSµÄauto-completion²å¼þ´æÔÚµÄÐÅϢй¶·ì϶£¬ÇÔÈ¡Ö÷ÕÅÖ÷»úIPµÄÐÅÏ¢¡£AmetysCmsÊÇÓÃÓÚÔÚͳһ̨·þÎñÆ÷ÉÏÔËÐдóÐÍÆóÒµÍøÕ¾£¬²©¿Í£¬IntranetºÍExtranet¡££¨Ametys£©ÉçÇøµÄCmsÒ»¸öÓÃJava±àдµÄÃâ·Ñ¿ªÔ´ÄÚÈÝÖÎÀíϵͳ¡£ |
¸üй¦·ò£º | 20230321 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Confluence[CVE-2021-26084][CNNVD-202108-2421] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | AtlassianConfluenceÊÇAtlassian¹«Ë¾³öÆ·µÄרҵµÄÆóҵ֪ʶÖÎÀíÓëÐͬÈí¼þ£¬¿ÉÓÃÓÚ¹¹½¨ÆóÒµÎÄ¿âµÈ¡£ConfluenceServerºÍConfluenceDataCenter(<6.13.23¡¢<7.11.6¡¢<7.12.5¡¢<7.4.11°æ±¾)ÉÏ´æÔÚÒ»¸öOGNL×¢Èë·ì϶£¬ÔÊÐí¾¹ýÉí·ÝÑéÖ¤»òÔÚijЩÇé¿öÏÂδÊÚȨµÄ¹¥»÷Õߣ¬ÔÚConfluenceServer»òConfluenceDataCenterÊ·ýÉÏÖ´ÐÐËÁÒâ´úÂë¡£ |
¸üй¦·ò£º | 20230321 |
ÊÂÎñÃû³Æ£º | HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Apache_AXIS[CVE-2019-0227] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·Ô̺¬ÁËJavaºÍC++˵»°ÊµÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°¸÷À๫Ó÷þÎñ¼°API£¬ÒÔÌìÉúºÍ²¿ÊðWeb·þÎñÀûÓ᣷ì϶ÐÔÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÅäÖÃÃýÎó¡£µ±enableRemoteAdminÊôÐÔÉèÖÃΪtrueʱ£¬¹¥»÷ÕßÄܹ»»ú¹ØWebServiceŲÓÃfreemarker×é¼þÖеÄtemplate.utility.ExecuteÀ࣬Զ³ÌÀûÓÃAdminService½Ó¿Ú½øÐÐWebService°ä²¼£¬ÔٴνӼûÌìÉúµÄWebService½Ó¿Ú£¬´«ÈëÒªÖ´ÐеĺÅÁ¾ÍÄܹ»½øÐÐÔ¶³ÌºÅÁîÖ´Ðзì϶µÄÀûÓᣠ|
¸üй¦·ò£º | 20230321 |
ÊÂÎñÃû³Æ£º | TCP_·ì϶ÀûÓÃ_δÊÚȨ½Ó¼û_Hadoop_Yarn_RPC |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃHadoopYarnµÄ·ì϶½øÐÐδÊÚȨ½Ó¼û£»¶ÔÓÚ8032¶³öÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬±àдÀûÓ÷¨Ê½Å²ÓÃyarnClient.getApplications()¼´¿É²é¿´ËùÓÐÀûÓÃÐÅÏ¢£»Hadoop×÷Ϊһ¸öÉ¢²¼Ê½ÍÆËãÀûÓÿò¼Ü£¬ÖÖÀàÖ°ÄÜ·±¶à£¬¶øHadoopYarn×÷ΪÆäÖ÷Ìâ×é¼þÖ®Ò»¡£ |
¸üй¦·ò£º | 20230321 |


¾©¹«Íø°²±¸11010802024551ºÅ