2020-11-17
Ðû²¼Ê±¼ä 2020-11-18ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_JIRA_δÊÚȨSSRFÎó²î[CVE-2019-8451][CNNVD-201909-556] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | JIRAÊÇAtlassian¹«Ë¾³öÆ·µÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬±»ÆÕ±éÓ¦ÓÃÓÚȱÏݸú×Ù¡¢¿Í»§Ð§ÀÍ¡¢ÐèÇóÍøÂç¡¢Á÷³ÌÉóÅú¡¢Ê¹Ãü¸ú×Ù¡¢ÏîÄ¿¸ú×ÙºÍѸËÙÖÎÀíµÈÊÂÇéÁìÓò¡£¡£¡£¡£¡£¡£¡£JiraµÄ/plugins/servlet/gadgets/makeRequest×ÊÔ´±£´æSSRFÎó²î£¬£¬£¬£¬£¬£¬£¬£¬Ôµ¹ÊÔÓÉÔÚÓÚJiraWhitelistÕâ¸öÀàµÄÂ߼ȱÏÝ£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÒÔJiraЧÀͶ˵ÄÉí·Ý»á¼ûÄÚÍø×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Nagios_XI_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-5791][CNNVD-202010-1115] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | Nagios XIÊÇÒ»¸ö½¨ÉèÔÚNagios½¹µãÉÏµÄÆóÒµ¼¶¼à²âºÍ±¨¾¯¼Æ»®µÄ¿ªÔ´×é¼þ¡£¡£¡£¡£¡£¡£¡£¹¦Ð§°üÀ¨PHPÍøÕ¾½çÃæ¡¢×ÛºÏÌåÏÖͼ¡¢¿É¶¨ÖƵÄÒDZí°å¡¢ÍøÂç½á¹¹¡¢ÉèÖÃGUI(ͼÐÎÓû§½Ó¿Ú)¡¢Óû§ÖÎÀíµÈ¡£¡£¡£¡£¡£¡£¡£Nagios XI 5.7.3Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÒÔ¡°apache¡±Óû§Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉ.NET·´ÐòÁл¯Êý¾Ý |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ¶Ô¿ÉÄܱ£´æ.NET·´ÐòÁл¯Îó²îµÄÒ³Ãæ·¢ËÍ¿ÉÒÉ·´ÐòÁл¯Êý¾Ý¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_ÒÉËÆnodejs´úÂë×¢Èë |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÒÉËÆÕýÔÚʹÓÃnodejs´úÂë×¢Èë¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_ActiveMQ_í§ÒâÎļþÉÏ´«Îó²î[CVE-2016-3088][CNNVD-201605-596] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ActiveMQ ÊÇ Apache Èí¼þ»ù½ð»áϵÄÒ»¸ö¿ªÔ´ÐÂÎÅÇý¶¯ÖÐÐļþÈí¼þ¡£¡£¡£¡£¡£¡£¡£Jetty ÊÇÒ»¸ö¿ªÔ´µÄ servlet ÈÝÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ËüΪ»ùÓÚ Java µÄ web ÈÝÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç "font-family:ËÎÌå">ºÍ servlet ÌṩÔËÐÐÇéÐΡ£¡£¡£¡£¡£¡£¡£ActiveMQ 5.0 ¼°ÒÔºó°æ±¾Ä¬Èϼ¯³ÉÁËjetty¡£¡£¡£¡£¡£¡£¡£ActiveMQ ÖÐµÄ FileServer ЧÀÍÔÊÐíÓû§Í¨¹ý HTTP PUT ÒªÁìÉÏ´«Îļþµ½Ö¸¶¨Ä¿Â¼£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹԶ³Ì¹¥»÷ÕßÓöñÒâ´úÂëÌæ»»WebÓ¦Ó㬣¬£¬£¬£¬£¬£¬£¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_´úÂëÖ´ÐÐ_yii·´ÐòÁл¯´úÂëÖ´ÐÐ[CVE-2020-15148][CNNVD-202009-926] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPʹÓÃyii·´ÐòÁл¯Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¾ÙÐÐÏÂÁîÖ´ÐеÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£YiiÊÇÒ»¸ö¸ßÐÔÄܵÄPHP5µÄwebÓ¦ÓóÌÐò¿ª·¢¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÒ»¸ö¼òÆÓµÄÏÂÁîÐй¤¾ß yiic ¿ÉÒÔ¿ìËÙ½¨ÉèÒ»¸öwebÓ¦ÓóÌÐòµÄ´úÂë¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬¿ª·¢Õß¿ÉÒÔÔÚÌìÉúµÄ´úÂë¿ò¼Ü»ù´¡ÉÏÌí¼ÓÓªÒµÂß¼£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¿ìËÙÍê³ÉÓ¦ÓóÌÐòµÄ¿ª·¢¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_fastjson_1.2.60_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬Ö§³Ö½«Java BeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬£¬£¬£¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_MSAServices.Bitter.Rat(ÂûÁ黨)_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½ BitterľÂí ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÊÂÎñÃû³Æ£º | TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-2551] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2551£©£¬£¬£¬£¬£¬£¬£¬£¬Oracle WebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2551£©£¬£¬£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýGIOPÐÒé´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£Îó²î±£´æµÄweblogic°æ±¾:10.3.6.0.012.1.3.0.012.2.1.3.012.2.1.4.0ÈôÊDZ»¹¥»÷»úеûÓÐÉý¼¶ÏìÓ¦µÄ²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÊµÑé¾ÙÐжñÒâÏÂÁî»ò´úÂë×¢È룬£¬£¬£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃ_Ŀ¼´©Ô½Îó²î[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902] [CNNVD-201904-1243/CNNVD-202006-075/CNNVD-201912-908/CNNVD-202007-053] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈÆ¹ýWebЧÀÍÆ÷µÄ»á¼ûÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬£¬£¬£¬£¬£¬£¬£¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ÊÂÎñÃû³Æ£º | HTTP_fastjson_1.2.61_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬Ö§³Ö½«Java BeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬£¬£¬£¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20201117 |


¾©¹«Íø°²±¸11010802024551ºÅ