ÿÖÜÉý¼¶²¼¸æ-2023-03-21

°ä²¼¹¦·ò 2023-03-21
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_SSRF_Microsoft_Exchange_ProxyLogon_ɨÃè[CVE-2021-26855][CNNVD-202103-192][CVE-2021-26855]

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

MicrosoftExchangeÖÐÔ̺¬ÁËÊý¸ö°²È«·ì϶£¬¹¥»÷ÕßÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öÏ£¬Äܹ»Í¨¹ý½áºÏʹÓÃÊý¸ö·ì϶À´ÈƹýExchangeǰ¶ËºÍÉí·ÝÏÞ¶È£¬ÉÏ´«¶ñÒâÎļþµ½Exchange·þÎñÆ÷ÉÏ£¬¸Ã·ì϶Á´¼´±»³ÆÎªProxyLogon£¬¸ÃÊÂÎñ¼ì²â¶ÔÆäÖеÄSSRF·ì϶ɨÃèÐÐΪ£¬¹¥»÷ÕßÄܹ»Í¨¹ý¸Ã·ì϶ÌáÉýȨÏÞ²¢Ö±½Ó½Ó¼ûºó¶Ë¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ºÅÁîÖ´ÐÐ_Bitbucket-Server&Data-Center_»·¾³±äÁ¿×¢Èë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ö÷»úÔÚÊܵ½Bitbucket-Server&Data-Center»·¾³±äÁ¿×¢È룬¿Éµ¼ÖÂËÁÒâºÅÁîÖ´ÐС£¸Ã·ì϶ÊÇͨ¹ý»·¾³±äÁ¿Òý·¢µÄºÅÁî×¢Èë·ì϶£¬¿Éµ¼ÖÂÓµÓÐȨÏ޵Ĺ¥»÷Õß½ÚÔìÓû§Ãû£¬ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐдúÂë¡£×÷Ϊһʱ»º½â´ëÊ©£¬Atlassian¹«Ë¾½¨ÒéÓû§¹Ø¹Ø¡°¹«¿ª×¢²á¡±Ñ¡Ïî¡£°²È«²¼¸æÖ¸³ö£¬¡°½ûÓù«¿ª×¢²á½«Ê¹¹¥»÷ÏòÁ¿´ÓδÈÏÖ¤¹¥»÷¸ü¸ÄΪÈÏÖ¤¹¥»÷£¬´Ó¶ø½µµÍÀûÓ÷çÏÕ¡£¾­ÖÎÀíÔ±»òϵͳÖÎÀíÔ±ÈÏÖ¤µÄÓû§¿ÉÄÜÔÚ½ûÓù«¿ª×¢²áÑ¡ÏîʱÀûÓø÷ì϶¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·çÏÕ_¿ÉÒÉÐÐΪ_esi±êǩҪÇó

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

EdgeSideIncludes(ESI)ÊÇÒ»ÖÖÏóÕ÷˵»°£¬ÖØÒªÔÚ³£¼ûµÄHTTP´úÀí£¨·´Ïò´úÀí¡¢¸ºÔØÆ½ºâ¡¢»º´æ·þÎñÆ÷¡¢´úÀí·þÎñÆ÷£©ÖÐʹÓá£Í¨¹ýESI×¢Èë¼¼ÊõÄܹ»µ¼Ö·þÎñ¶ËÒªÇóαÔ죨SSRF£©£¬ÈƹýHTTPOnlycookieµÄ¿çÕ¾¾ç±¾¹¥»÷£¨XSS£©ÒÔ¼°·þÎñ¶Ë»Ø¾ø·þÎñ¹¥»÷¡£Í¨¹ý²âÊÔ£¬Óм¸Ê®ÖÖÖ§³Ö´¦ÖÃESIµÄ²úÆ·£ºVarnish£¬SquidProxy£¬IBMWebSphere£¬OracleFusion/WebLogic£¬Akamai£¬Fastly£¬F5£¬Node.jsESI£¬LiteSpeedºÍÒ»Ð©ÌØ¶¨Ëµ»°²å¼þ£¬µ«²¢²»ÊÇÕâЩ²úƷĬÈÏÆôÓÃÁËESI¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_RichFaces[CVE-2018-14667]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

RichFacesÊÇÒ»¸ö»ùÓÚLGPLºÍ̸ʢ¿ªÔ´´úÂëµÄJSF£¨JavaServerFaces£©×é¼þ¿â£¬Ëü¿ÉÄÜʹÀûÓÿª·¢·½±ãµØ¼¯³ÉAJAX¡£´Ë¿ÌµÄRichFaces¿âÊÇÓÉAjax4jsfºÍRichFacesÁ½²¿ÃÅ×é³É¡£JavaRichFaces¿ò¼ÜÖÐÔ̺¬Ò»¸öRCE·ì϶,¹¥»÷Õ߿ɻú¹ØÔ̺¬org.ajax4jsf.resource.UserResource$UriDataÐòÁл¯¶ÔÏóµÄÌØ¶¨UserResourceÒªÇó£¬RichFaces»áÏÈ·´ÐòÁл¯¸ÃUriData¶ÔÏ󣬶øºóʹÓÃEL±í°×ʽ½âÎö²¢»ñÈ¡resourceµÄmodified¡¢expiresµÈÖµµ¼ÖÂÁËËÁÒâEL±í°×ʽִÐУ¬Í¨¹ý»ú¹ØÌØÊâµÄEL±í°×ʽ¿ÉʵÏÖÔ¶³ÌËÁÒâ´úÂëÖ´ÐС£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Õã½­ÓîÊӿƼ¼ÍøÂçÊÓÆµÂ¼Ïñ»ú_LogReport.php

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÔÚÀûÓÃÕã½­ÓîÊӿƼ¼ÍøÂçÊÓÆµÂ¼Ïñ»úµÄ·ì϶½øÐдúÂëÖ´Ðй¥»÷£»

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ÐÅϢй¶_Ametys_auto-completion_plugin[CVE-2022-26159]

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÔÚÀûÓÃAmetys_CMSµÄauto-completion²å¼þ´æÔÚµÄÐÅϢй¶·ì϶£¬ÇÔÈ¡Ö÷ÕÅÖ÷»úIPµÄÐÅÏ¢¡£AmetysCmsÊÇÓÃÓÚÔÚͳһ̨·þÎñÆ÷ÉÏÔËÐдóÐÍÆóÒµÍøÕ¾£¬²©¿Í£¬IntranetºÍExtranet¡££¨Ametys£©ÉçÇøµÄCmsÒ»¸öÓÃJava±àдµÄÃâ·Ñ¿ªÔ´ÄÚÈÝÖÎÀíϵͳ¡£

¸üй¦·ò£º

20230321

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Confluence[CVE-2021-26084][CNNVD-202108-2421]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

AtlassianConfluenceÊÇAtlassian¹«Ë¾³öÆ·µÄרҵµÄÆóҵ֪ʶÖÎÀíÓëЭͬÈí¼þ£¬¿ÉÓÃÓÚ¹¹½¨ÆóÒµÎÄ¿âµÈ¡£ConfluenceServerºÍConfluenceDataCenter(<6.13.23¡¢<7.11.6¡¢<7.12.5¡¢<7.4.11°æ±¾)ÉÏ´æÔÚÒ»¸öOGNL×¢Èë·ì϶£¬ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤»òÔÚijЩÇé¿öÏÂδÊÚȨµÄ¹¥»÷Õߣ¬ÔÚConfluenceServer»òConfluenceDataCenterÊ·ýÉÏÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Apache_AXIS[CVE-2019-0227]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·Ô̺¬ÁËJavaºÍC++˵»°ÊµÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°¸÷À๫Ó÷þÎñ¼°API£¬ÒÔÌìÉúºÍ²¿ÊðWeb·þÎñÀûÓ᣷ì϶ÐÔÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÅäÖÃÃýÎó¡£µ±enableRemoteAdminÊôÐÔÉèÖÃΪtrueʱ£¬¹¥»÷ÕßÄܹ»»ú¹ØWebServiceŲÓÃfreemarker×é¼þÖеÄtemplate.utility.ExecuteÀ࣬Զ³ÌÀûÓÃAdminService½Ó¿Ú½øÐÐWebService°ä²¼£¬ÔٴνӼûÌìÉúµÄWebService½Ó¿Ú£¬´«ÈëÒªÖ´ÐеĺÅÁ¾ÍÄܹ»½øÐÐÔ¶³ÌºÅÁîÖ´Ðзì϶µÄÀûÓá£

¸üй¦·ò£º

20230321

 

ÊÂÎñÃû³Æ£º

TCP_·ì϶ÀûÓÃ_δÊÚȨ½Ó¼û_Hadoop_Yarn_RPC

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃHadoopYarnµÄ·ì϶½øÐÐδÊÚȨ½Ó¼û£»¶ÔÓÚ8032¶³öÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬±àдÀûÓ÷¨Ê½Å²ÓÃyarnClient.getApplications()¼´¿É²é¿´ËùÓÐÀûÓÃÐÅÏ¢£»Hadoop×÷Ϊһ¸öÉ¢²¼Ê½ÍÆËãÀûÓÿò¼Ü£¬ÖÖÀàÖ°ÄÜ·±¶à£¬¶øHadoopYarn×÷ΪÆäÖ÷Ìâ×é¼þÖ®Ò»¡£

¸üй¦·ò£º

20230321