ÿÖÜÉý¼¶²¼¸æ-2022-01-11

°ä²¼¹¦·ò 2022-01-12

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º£º

TCP_´úÂëÖ´ÐÐ_Dubbo·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2021-30179]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃDubboµÄGenericFilter½Ó¿ÚµÄ·´ÐòÁл¯Ô¶³ÌºÅÁîÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£¡£ApacheDubboÊÇÒ»¸öÉ¢²¼Ê½¿ò¼Ü£¬£¬ÖÂÁ¦ÓÚÌṩ¸ß»úÄÜͨÃ÷»¯µÄRPCÔ¶³Ì·þÎñŲÓù滮£¬£¬ÒÔ¼°SOA·þÎñÖÎÀí¹æ»®¡£¡£¡£ApacheDubboÔÚÏÖʵÀûÓó¡¾°ÖÐÖØÒªÕÆ¹Ü½â¾öÉ¢²¼Ê½µÄÓйØÐèÒª¡£¡£¡£

¸üй¦·ò£º£º

20220111

 

ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_ApiSix_ËÁÒâ´úÂëÖ´ÐÐ[CVE-2021-45232][CNNVD-202112-2629]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

ÔÚ2.10.1֮ǰµÄApacheAPISIXDashboardÖУ¬£¬ManagerAPIʹÓÃÁ½¸ö¿ò¼Ü²¢ÔÚ»ù´¡ÉÏÒýÈë`droplet`ºÍ`gin`Á½¸ö¿ò¼Ü£¬£¬¿ª·¢ËùÓÐAPIºÍÈÏÖ¤ÖÐÑë¼þ»ùÓÚ¿ò¼Ü`droplet`£¬£¬µ«²¿ÃÅAPIÖ±½ÓʹÓýӿÚ`gin`¿ò¼Üδ½øÐÐdropletÈÏÖ¤£¬£¬´Ó¶øÄܹ»Î´ÊÚȨ½Ó¼û¡£¡£¡£²¢ÇÒ£¬£¬ÔÚ³ö¸ñµÄõè¾¶Ï£¬£¬´æÔÚ±»¹¥»÷ÕßÖ´ÐÐËÁÒâlua´úÂëµÄ·çÏÕ¡£¡£¡£

¸üй¦·ò£º£º

20220111


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º£º

HTTP_¿ÉÒÉÐÐΪ_Fastjson·ì϶_hex±àÂëÀûÓÃ

°²È«ÀàÐÍ£º£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º£º

FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬£¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´®£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã£¬£¬ÀûÓÃÁìÓòºÜ¹ã¡£¡£¡£¹¥»÷³É¹¦£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£fastjson¿É½ÓÊܲ¢½âÎöhex±àÂëÄÚÈÝ£¬£¬Òò¶ø¹¥»÷Õß¿ÉÀûÓÃhex±àÂëÈÆ¹ý¼ì²âÉ豸¡£¡£¡£

¸üй¦·ò£º£º

20220111