ÿÖÜÉý¼¶Í¨¸æ-2023-03-28

Ðû²¼Ê±¼ä 2023-03-28

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÐÅϢй¶_MinIO[CVE-2023-28432]

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

MinIO ÊÇÒ»¸ö»ùÓÚApache License v2.0¿ªÔ´Ð­ÒéµÄ¹¤¾ß´æ´¢·þÎñ¡£Ëü¼æÈÝÑÇÂíÑ·S3ÔÆ´æ´¢·þÎñ½Ó¿Ú  £¬ºÜÊÇÊʺÏÓÚ´æ´¢´óÈÝÁ¿·Ç½á¹¹»¯µÄÊý¾Ý  £¬ÀýÈçͼƬ¡¢ÊÓÆµ¡¢ÈÕÖ¾Îļþ¡¢±¸·ÝÊý¾ÝºÍÈÝÆ÷/ÐéÄâ»ú¾µÏñµÈ¡£

MinIOÖб£´æÒ»´¦ÐÅϢй¶Îó²î  £¬ÓÉÓÚMinio¼¯Èº¾ÙÐÐÐÅÏ¢½»Á÷µÄ9000¶Ë¿Ú  £¬ÔÚδ¾­ÉèÖõÄÇéÐÎÏÂͨ¹ý·¢ËÍÌØÊâHPPTÇëÇó¾ÙÐÐδÊÚȨ»á¼û  £¬½ø¶øµ¼ÖÂMinIO¹¤¾ß´æ´¢µÄÏà¹ØÇéÐαäÁ¿Ð¹Â¶  £¬È磺MINIO_SECRET_KEY ºÍ MINIO_ROOT_PASSWORD µÈËùÓÐÇéÐαäÁ¿ÐÅÏ¢¡£µ¼Ö¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÐÅÏ¢í§Òâ»á¼ûMinIO¼¯ÈºÖеÄËùÓÐÎļþ¡£Ê¹ÓùÙÍø¿ÍÕ» docs/orchestration/docker-compose Æô¶¯µÄµÍ°æ±¾¼¯ÈºÄ¬ÈÏÊܵ½¸ÃÎó²îÓ°Ïì¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ÐźôoaСÓÚ2.3.2[CVE-2023-1501][CNNVD-202303-1481]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

RockOA ÊÇÒ»Ì׿ªÔ´µÄ°ì¹«ÏµÍ³  £¬ÊÊÓÃÓÚÖÐСÐÍÆóÒµµÄͨÓÃÐÍЭͬ OA ¹ÜÀíÈí¼þ  £¬ÈÚºÏÁ˺ã¾Ã´ÓʹÜÀíÈí¼þ¿ª·¢µÄ¸»ºñÂÄÀúÓëÏȽøÊÖÒÕ  £¬¸Ãϵͳ½ÓÄÉÁìÏ鵀 B/S (ä¯ÀÀÆ÷ / ·þÎñÆ÷) ²Ù×÷·½·¨¡£¹¥»÷Õß¿Éͨ¹ýÌØ¶¨Â·ÓɾÙÐÐí§ÒâÎļþÉÏ´«  £¬Ôì³Égetshell¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_·´ÐòÁл¯_Fastjson_1.2.80

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ  £¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£fastjsonÔÚ1.2.83ÒÔ¼°Ö®Ç°°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¿ª·¢ÕßÔÚʹÓÃfastjsonʱ  £¬ÈôÊDZàд²»µ±  £¬¿ÉÄܵ¼ÖÂJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂë  £¬µ±³ÌÐòÖ´ÐÐJSON·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂë  £¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÊµÑé¾ÙÐжñÒâÏÂÁî»ò´úÂë×¢Èë  £¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ÓÃÓÑGRP-U8²ÆÎñ¹ÜÀíÈí¼þ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¿½ñÖ÷»úÕýÔÚÔâÊÜÓÃÓÑGRP-U8²ÆÎñ¹ÜÀíÈí¼þí§ÒâÎļþÉÏ´«¹¥»÷  £¬ÓÃÓÑGRP-U8²ÆÎñ¹ÜÀíÈí¼þ×÷Ϊ²ÆÎñ¹ÜÀíÈí¼þ  £¬×÷ÓÃÓÚ²ÆÎñ¹ÜÀí  £¬ÊÇÏà¶ÔÃô¸ÐµÄÓªÒµ  £¬ÓÉÓÚ¶ÔÉÏ´«Îļþ¹¦Ð§Î´¾ÙÐгä·ÖÇ徲˼Á¿  £¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«¶ñÒâ¾ç±¾ÊµÏÖ¶ÔÖ÷»úµÄ¿ØÖÆ  £¬Î£º¦½Ï´ó¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ÓÃÓÑU8Cloud

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ö÷»úÕýÔÚÔâÊÜÓÃÓÑU8Cloud_ÎļþÉÏ´«¹¥»÷  £¬U8cloudÊÇÓÃÓÑÍÆ³öµÄÐÂÒ»´úÔÆERP  £¬ÓÉÓÚ¶ÔÉÏ´«Îļþ¹¦Ð§Î´¾ÙÐгä·ÖÇ徲˼Á¿  £¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«¶ñÒâ¾ç±¾ÊµÏÖ¶ÔÖ÷»úµÄ¿ØÖÆ  £¬Î£º¦½Ï´ó¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_δÊÚȨ»á¼û_Wavlink[CVE-2022-48165]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ö÷»úÕýÔÚÔâÊÜWavlink_δÊÚȨ»á¼û¹¥»÷  £¬WavlinkWL-WN530H4M30H4.V5030.210121µÄ/cgi-bin/ExportLogs.sh×é¼þÖб£´æ»á¼û¿ØÖÆÎÊÌâ  £¬ÔÊÐíδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÏÂÔØÉèÖÃÊý¾ÝºÍÈÕÖ¾Îļþ²¢»ñµÃ¹ÜÀíÖ¤Êé¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_δÊÚȨ»á¼û_Apache_AXIS_Services

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAP·þÎñÆ÷  £¬ÒÔ¼°ÖÖÖÖ¹«Ó÷þÎñ¼°API  £¬ÒÔÌìÉúºÍ°²ÅÅWeb·þÎñÓ¦Óá£Îó²îʵÖÊÊǹÜÀíÔ±¶ÔAdminServiceµÄÉèÖùýʧ¡£µ±Ïà¹Ø½Ó¿Úδ¾ÙÐмøÈ¨´¦Öóͷ£  £¬¹¥»÷Õß¿Éͨ¹ýδÊÚȨ»á¼ûµ½servicesµÄwsdl½Ó¿Ú»òͨ¹ýĬÈÏ¿ÚÁî»á¼ûµ½servicesµÄupload½Ó¿Ú  £¬²¢Í¨¹ý»ñÈ¡Ãô¸Ð½Ó¿ÚÎĵµÐÅÏ¢»ò°²ÅŶñÒâ·þÎñ¾ÙÐкóÐø¹¥»÷ÐÐΪ¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_Îļþ¶ÁÈ¡_jetty[CVE-2021-28169]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¿µÄÖ÷»úÕýÔÚÔâÊÜjettyÎļþ¶ÁÈ¡[CVE-2021-28169]¹¥»÷¡£JettyServletsÖеÄConcatServlet¡¢WelcomeFilterÀà±£´æ¶àÖØ½âÂëÎÊÌâ  £¬µ±Ó¦Óõ½ÕâÁ½¸öÀà֮һʱ  £¬¹¥»÷Õ߾ͿÉÒÔʹÓÃË«ÖØURL±àÂëÈÆ¹ýÏÞÖÆÀ´»á¼ûWEB-INFĿ¼ÏµÄÃô¸ÐÎļþ  £¬Ôì³ÉÃô¸ÐÐÅϢй¶¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_·ºÎ¢OA_ajax.php

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓ÷ºÎ¢OA±£´æµÄÎļþÉÏ´«Îó²î¾ÙÐÐí§ÒâÎļþÉÏ´«¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÉÏ´«¶ñÒâÎļþ  £¬»ñȡĿµÄϵͳȨÏÞ¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_ÏÂÁî¿ØÖÆ_C2ͨѶ_BruteRatelC4.badger_ÐÄÌø_ÀÖ³É

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºÚ¿Í¹¤¾ßBruteRatelC4(ÒÔϼò³ÆBRC4)ÌìÉúµÄºóÃÅbadgerʵÑéÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBruteRatelC4.badger¡£BruteRatelC4£¨ÒÔϼò³ÆBRC4£©ÓÃÒÔÌæ»»ÒòʹÓÃÆÕ±é¶ø±»Çå¾²¹«Ë¾ÖصãÌá·ÀµÄCobaltStrike¿ò¼Ü¡£BRC4ʹÓÃÁËÖÚ¶àÓÃÓÚ¹æ±ÜºÍ¼ì²âEDRµÄÊÖÒÕ  £¬ÆäÍⲿC2½¹µãͨѶÂß¼­Êǽ«ÓÐÓøºÔØÊä³öÒþ²ØÔÚÕýµ±ÍøÂçÁ÷Á¿ÖС£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_À¶ÁèOA_datajson.js

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÀ¶ÁèOAÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£ÉîÛÚÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿Éͨ¹ýdatajson.js  £¬ÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20230328

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Weblogic_T3ЭÒé[CVE-2019-2890]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨  £¬ÓÃÓÚÔÚÍâµØºÍÔÆ¶Ë¿ª·¢¡¢°²ÅźÍÔËÐÐÆóÒµÓ¦ÓóÌÐò  £¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£CVE-2019-2890Îó²î¿ÉÒÔʹÓÃPersistentContextÀàÈÆ¹ý²¹¶¡  £¬Í¨¹ý·´ÐòÁл¯´¥·¢rmiÀú³ÌÖв»Çå¾²µÄjrmpÒªÁì  £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ЭÒéÍøÂç»á¼û²¢ÆÆËðÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷  £¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½ÓÊÜ»òÃô¸ÐÐÅϢй¶¡£Ó°Ïì¹æÄ££º-Weblogic10.3.6.0.0-Weblogic12.1.3.0.0-Weblogic12.2.1.3.0

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_ÏÂÁîÖ´ÐÐ_Exim[CVE-2019-10149]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃEximµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¸ÃÎó²îÓ°ÏìExim4.87~4.91°æ±¾  £¬ÔÚ4.87°æ±¾Ö®Ç°ÈôÊÇÊÖ¶¯ÆôÓÃÁËEXPERIMENTAL_EVENTÑ¡Ïî  £¬·þÎñÆ÷Ò²»á±£´æÎó²î  £¬¸ÃÎó²îÔÚĬÈÏÉèÖÃÏ¿ɱ»ÍâµØ¹¥»÷ÕßÖ±½ÓʹÓà  £¬Í¨¹ýµÍȨÏÞÓû§Ö´ÐÐrootȨÏÞÏÂÁî  £¬Ô¶³Ì¹¥»÷ÕßÐèÒªÐÞ¸ÄĬÈÏÉèÖá£ÎªÁËÔÚĬÈÏÉèÖÃÏÂÔ¶³ÌʹÓøÃÎó²î  £¬Ô¶³Ì¹¥»÷ÕßÐèÒªÓë±£´æÎó²îµÄ·þÎñÆ÷½¨Éè7ÌìµÄÅþÁ¬£¨Ã¿¸ô¼¸·ÖÖÓ·¢ËÍ1¸ö×Ö½Ú£©¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_H2database_console

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndi·þÎñÆ÷µØÖ·¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ  £¬½ÓÄÉjavaÓïÑÔ±àд  £¬²»ÊÜÆ½Ì¨µÄÏÞÖÆ  £¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸öÊ®·ÖÀû±ãµÄweb¿ØÖÆÌ¨ÓÃÓÚ²Ù×÷ºÍ¹ÜÀíÊý¾Ý¿âÄÚÈÝ¡£H2Database»¹Ìṩ¼æÈÝģʽ  £¬¿ÉÒÔ¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â  £¬Òò´Ë½ÓÄÉH2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿âºÜÊÇÀû±ã¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Ruby_conversions.rb_Ruby[CVE-2013-0156]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄÖ÷»úÉϵÄRuby½á¹¹¶ñÒâµÄXMLÍⲿʵÌå×¢Èë´úÂë¾ÙÐй¥»÷ £»RubyonRailsÊÇÒ»¸ö¿ÉÒÔʹ¿ª·¢¡¢°²ÅÅ¡¢Î¬»¤webÓ¦ÓóÌÐò±äµÃ¼òÆÓµÄ¿ò¼Ü¡£

¸üÐÂʱ¼ä£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Kibana[CVE-2019-7609]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

KibanaÊÇΪElasticsearchÉè¼ÆµÄ¿ªÔ´ÆÊÎöºÍ¿ÉÊÓ»¯Æ½Ì¨¡£¿ÉÒÔʹÓÃKibanaÀ´ËÑË÷  £¬Éó²é´æ´¢ÔÚElasticsearchË÷ÒýÖеÄÊý¾Ý²¢ÓëÖ®½»»¥¡£¿ÉÒÔºÜÈÝÒ×ʵÏָ߼¶µÄÊý¾ÝÆÊÎöºÍ¿ÉÊÓ»¯  £¬ÒÔͼ±êµÄÐÎʽչÏÖ³öÀ´¡£¹¥»÷ÕßʹÓÃÎó²î¿ÉÒÔͨ¹ýTimelion×é¼þÖеÄJavaScriptÔ­ÐÍÁ´ÎÛȾ¹¥»÷  £¬ÏòKibanaÌᳫÏà¹ØÇëÇó  £¬´Ó¶ø½ÓÊÜËùÔÚ·þÎñÆ÷  £¬ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî  £¬Îó²îÓ°Ïì¹æÄ£°üÀ¨Kibana<6.6.1¡¢Kibana<5.6.15¡£

¸üÐÂʱ¼ä£º

20230328