AtlassianÖб£´æ0dayÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-06

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15006£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Atlassian Confluence server


Îó²î¸ÅÊö


Çå¾²Ö°Ô±SwiftOnSecurityÖܶþ¸üÐÂTwitter£¬ £¬£¬£¬£¬ÎÞÒâÖÐÅû¶ÁËÒ»¸öÓ°ÏìÆóÒµÈí¼þÓªÒµAtlassianµÄÁãÈÕÎó²î£¬ £¬£¬£¬£¬¸ÃÎó²î¿ÉÄÜÔÚIBMµÄAsperaÈí¼þÖлñµÃÌåÏÖ¡£¡£¡£¡£¡£¡£¡£SwiftOnSecurity TwitterÕÊ»§ÏÔʾ£¬ £¬£¬£¬£¬AtlassianÌṩÁËÒ»¸öʹÓÃÆäConfluenceÔÆÐ§ÀÍʹÓÃͨÓÃSSLÖ¤ÊéÆÊÎöµ½ÍâµØÐ§ÀÍÆ÷µÄÓò£¬ £¬£¬£¬£¬ÒÔʹAtlassian CompanionÓ¦ÓóÌÐò¿ÉÒÔÔÚÊ×Ñ¡ÍâµØÓ¦ÓóÌÐòÖб༭Îļþ²¢½«ÎļþÉúÑÄ»ØConfluence¡£¡£¡£¡£¡£¡£¡£ÈκξßÓÐ×ã¹»ÊÖÒÕ֪ʶµÄÈ˶¼¿ÉÒÔ¸´ÖÆSSLÃÜÔ¿£¬ £¬£¬£¬£¬È»ºóʹÓÃËü¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬ £¬£¬£¬£¬Õâ¿ÉÄÜʹ¹¥»÷Õß½«Ó¦ÓóÌÐòÁ÷Á¿Öض¨Ïòµ½¶ñÒâÕ¾µã¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌûÓÐÐû²¼Îó²îÐÞ¸´³ÌÐò£¬ £¬£¬£¬£¬Çëʵʱ¹Ø×¢¸üУºhttps://confluence.atlassian.com/doc/administering-the-atlassian-companion-app-958456281.html¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.theregister.co.uk/2019/12/05/atlassian_zero_day_bug/