2020-11-17

°ä²¼¹¦·ò 2020-11-18

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º£º£º

HTTP_°²È«·ì϶_JIRA_δÊÚȨSSRF·ì϶[CVE-2019-8451][CNNVD-201909-556]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

JIRAÊÇAtlassian¹«Ë¾³öÆ·µÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß£¬±»¿í·ºÀûÓÃÓÚȱµã¸ú×Ù¡¢¡¢¡¢¿Í»§·þÎñ¡¢¡¢¡¢ÐèÒªÍøÂç¡¢¡¢¡¢Á÷³ÌÉóÅú¡¢¡¢¡¢¹¤×÷¸ú×Ù¡¢¡¢¡¢ÏîÄ¿¸ú×ٺͻðËÙÖÎÀíµÈ¹¤×÷ÁìÓò¡£¡£¡£¡£JiraµÄ/plugins/servlet/gadgets/makeRequest×ÊÔ´´æÔÚSSRF·ì϶£¬Ô­ÒòÔÚÓÚJiraWhitelistÕâ¸öÀàµÄÂß¼­È±µã£¬³É¹¦ÀûÓô˷ì϶µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÒÔJira·þÎñ¶ËµÄÉí·Ý½Ó¼ûÄÚÍø×ÊÔ´¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


ÊÂÎñÃû³Æ£º£º£º

HTTP_°²È«·ì϶_Nagios_XI_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-5791][CNNVD-202010-1115]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

Nagios XIÊÇÒ»¸ö³ÉÁ¢ÔÚNagiosÖ÷ÌâÉÏµÄÆóÒµ¼¶¼à²âºÍ±¨¾¯¹æ»®µÄ¿ªÔ´×é¼þ¡£¡£¡£¡£Ö°ÄÜÔ̺¬PHPÍøÕ¾½çÃæ¡¢¡¢¡¢×ۺϲû·¢Í¼¡¢¡¢¡¢¿É¶¨ÖƵÄÒDZí°å¡¢¡¢¡¢ÍøÂç½á¹¹¡¢¡¢¡¢ÅäÖÃGUI(ͼÐÎÓû§½Ó¿Ú)¡¢¡¢¡¢Óû§ÖÎÀíµÈ¡£¡£¡£¡£Nagios XI 5.7.3ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðа²È«·ì϶£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÒÔ¡°apache¡±Óû§Ö´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


ÊÂÎñÃû³Æ£º£º£º

HTTP_¿ÉÒÉ.NET·´ÐòÁл¯Êý¾Ý

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ¶Ô¿ÉÄÜ´æÔÚ.NET·´ÐòÁл¯·ì϶µÄÒ³Ãæ·¢ËÍ¿ÉÒÉ·´ÐòÁл¯Êý¾Ý¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÒÉËÆnodejs´úÂë×¢Èë

°²È«ÀàÐÍ£º£º£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÖ÷»úÒÉËÆÕýÔÚÀûÓÃnodejs´úÂë×¢Èë¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


ÊÂÎñÃû³Æ£º£º£º

HTTP_°²È«·ì϶_ActiveMQ_ËÁÒâÎļþÉÏ´«·ì϶[CVE-2016-3088][CNNVD-201605-596]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

ActiveMQ ÊÇ Apache Èí¼þ»ù½ð»áϵÄÒ»¸ö¿ªÔ´ÐÂÎÅÇý¶¯ÖÐÑë¼þÈí¼þ¡£¡£¡£¡£Jetty ÊÇÒ»¸ö¿ªÔ´µÄ servlet ÈÝÆ÷£¬ËüΪ»ùÓÚ Java µÄ web ÈÝÆ÷£¬ÀýÈç "font-family:ËÎÌå">ºÍ servlet ÌṩÔËÐл·¾³¡£¡£¡£¡£ActiveMQ 5.0 ¼°ÒÔÀ´°æ±¾Ä¬Èϼ¯³ÉÁËjetty¡£¡£¡£¡£ActiveMQ ÖÐµÄ FileServer ·þÎñÔÊÐíÓû§Í¨¹ý HTTP PUT ²½ÖèÉÏ´«Îļþµ½Ö¸¶¨Ä¿Â¼£¬¿ÉʹԶ³Ì¹¥»÷ÕßÓöñÒâ´úÂë´úÌæWebÀûÓã¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


ÊÂÎñÃû³Æ£º£º£º

HTTP_´úÂëÖ´ÐÐ_yii·´ÐòÁл¯´úÂëÖ´ÐÐ[CVE-2020-15148][CNNVD-202009-926]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÀûÓÃyii·´ÐòÁл¯Ô¶³ÌºÅÁîÖ´Ðзì϶½øÐкÅÁîÖ´ÐеÄÐÐΪ¡£¡£¡£¡£YiiÊÇÒ»¸ö¸ß»úÄܵÄPHP5µÄwebÀûÓ÷¨Ê½¿ª·¢¿ò¼Ü¡£¡£¡£¡£Í¨¹ýÒ»¸öµ¥Ò»µÄºÅÁîÐй¤¾ß yiic Äܹ»¼±¾ç´´½¨Ò»¸öwebÀûÓ÷¨Ê½µÄ´úÂë¿ò¼Ü£¬¿ª·¢ÕßÄܹ»ÔÚÌìÉúµÄ´úÂë¿ò¼Ü»ù´¡ÉÏÔö³¤ÒµÎñÂß¼­£¬ÒÔ¼±¾çʵÏÖÀûÓ÷¨Ê½µÄ¿ª·¢¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º£º£º

HTTP_fastjson_1.2.60_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£¡£¡£¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´®£¬Ö§³Ö½«Java BeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã£¬ÀûÓÃÁìÓòºÜ¹ã¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


ÊÂÎñÃû³Æ£º£º£º

TCP_ºóÃÅ_MSAServices.Bitter.Rat(ÂûÁ黨)_ÏνÓ

°²È«ÀàÐÍ£º£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½ BitterľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


ÊÂÎñÃû³Æ£º£º£º

TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-2551]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-2551£©£¬Oracle WebLogicÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-2551£©£¬ÊÔͼͨ¹ýGIOPºÍ̸´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£¡£¡£¡£·ì϶´æÔÚµÄweblogic°æ±¾:10.3.6.0.012.1.3.0.012.2.1.3.012.2.1.4.0ÈôÊDZ»¹¥»÷»úеûÓÐÉý¼¶ÏàÓ¦µÄ²¹¶¡£¡£¡£¡£¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£¡£¡£¡£³¢ÊÔ½øÐжñÒâºÅÁî»ò´úÂë×¢È룬Զ³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


ÊÂÎñÃû³Æ£º£º£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½·ì϶[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

[CNNVD-201904-1243/CNNVD-202006-075/CNNVD-201912-908/CNNVD-202007-053]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ³¢ÊÔ¶ÔÖ÷ÕÅIPÖ÷»ú½øÐÐĿ¼´©Ô½·ì϶¹¥»÷³¢ÊÔµÄÐÐΪ¡£¡£¡£¡£Ä¿Â¼´©Ô½·ì϶ÄÜʹ¹¥»÷ÕßÈÆ¹ýWeb·þÎñÆ÷µÄ½Ó¼ûÏÞ¶È£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬ËÁÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117


ÊÂÎñÃû³Æ£º£º£º

HTTP_fastjson_1.2.61_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅIPÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£¡£¡£¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´®£¬Ö§³Ö½«Java BeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã£¬ÀûÓÃÁìÓòºÜ¹ã¡£¡£¡£¡£

¸üй¦·ò£º£º£º

20201117