Atlassian CrowdÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-11580 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾
Atlassian Crowd 3.4.3
Atlassian Crowd 3.4
Atlassian Crowd 3.3.4
Atlassian Crowd 3.3.3
Atlassian Crowd 3.3.1
Atlassian Crowd 3.3
Atlassian Crowd 3.2.1 - 3.2.7
Atlassian Crowd 3.2
Atlassian Crowd 3.1.5
Atlassian Crowd 3.1
Atlassian Crowd 3.0.4
Atlassian Crowd 2.11.1
Atlassian Crowd 2.11
Atlassian Crowd 2.10.3
Atlassian Crowd 2.10.1
Atlassian Crowd 2.9.7
Atlassian Crowd 2.9.1 - 2.9.5
Atlassian Crowd 2.9
Atlassian Crowd 2.8.8
Atlassian Crowd 2.8.3
Atlassian Crowd 2.7
Atlassian Crowd 2.6.0 - 2.6.3
Atlassian Crowd 2.5.3 - 2.5.4
Atlassian Crowd 2.5.0 - 2.5.2
Atlassian Crowd 2.4.9
Atlassian Crowd 2.4.1
Atlassian Crowd 2.4
Atlassian Crowd 2.3.6 - 2.3.8
Atlassian Crowd 2.3.1 - 2.3.4
Atlassian Crowd 2.2.9
Atlassian Crowd 2.2.7
Atlassian Crowd 2.2.4
Atlassian Crowd 2.2.2
Atlassian Crowd 2.1.1 - 2.1.2

Atlassian Crowd 2.1


·ì϶¸ÅÊö


CrowdÊÇÒ»¸öµ¥Ò»Ò×Óõĵ¥Ò»µÇ¼ºÍÓû§ÖÎÀíÈí¼þ £¬ÎªÓû§Ìṩһ×éÓû§ÃûºÍÃÜÂëÀ´µÇ¼±ØÒª½Ó¼ûµÄËùÓÐÀûÓá£Î޷켯³É Jira¡¢Confluence ºÍ Bitbucket µÈËùÓÐ Atlassian ²úÆ· £¬ÎªÓû§Ìṩµ¥Ò»µÇ¼ (SSO) ÂÄÀú¡£¼¯Öжà¸öĿ¼ £¬½«ËÁÒâĿ¼×éºÏÓ³Éäµ½µ¥¸öÀûÓà £¬¶øºóÔÚͳһµØÎ»ÖÎÀíÉí·ÝÑé֤ȨÏÞ¡£ºÏÓÃÓÚ AD¡¢LDAP¡¢Microsoft Azure AD¡¢Novell eDirectory µÈµÄÏÎ½ÓÆ÷¡£


Atlassian Crowd´æÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶ £¬´Ë·ì϶ÓÉÓÚAtlassian CrowdµÄcom.atlassian.pdkinstall.PdkInstallFilterÔÊÐí¹¥»÷ÕßÔÚ/admin/uploadplugin.actionõè¾¶ÏÂʹÓÃMultipartÌåʽÉÏ´«Îļþ £¬¹¥»÷ÕßÄܹ»ÀûÓô˷½Ê½Ïò·þÎñÆ÷ÉÏ´«¶ñÒâÎļþ,»ñÈ¡·þÎñÆ÷ȨÏÞ,ʵÏÖÔ¶³ÌºÅÁîÖ´Ðзì϶µÄÀûÓá£


Ŀǰ¾Ýͳ¼Æ,ÔÚÈ«ÇòÁìÓòÄÚ¶Ô»¥ÁªÍøÊ¢¿ªAtlassian CrowdµÄ×ʲúÊýÁ¿¶à´ï14,225̨ £¬Öйú610̨ £¬É¢²¼ÈçÏ£º 

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


·ì϶ÑéÖ¤


´î½¨ Atlassian Crowd 3.2.3»·¾³¡£ÔÚ/crowd/admin/uploadplugin.actionõè¾¶Ï»ú¹ØMultipartÀàÐÍÒªÇó°ü £¬ÔÚfile_cdl²ÎÊýÖд«ÈëÒªÉÏ´«µÄÎļþ £¬×îÖÕ³ÉЧÈçÏÂͼËùʾ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


½¨¸´½¨Òé


ĿǰÒѰ䲼а汾 £¬Éý¼¶µ½Crowd¶ÔÓ¦µÄ×îа汾3.4.4 £¬3.3.5 £¬3.2.8 £¬3.1.6 £¬ 3.0.5¡£ÏÂÔØÁ´½Ó£ºhttps://www.atlassian.com/software/crowd/download¡£


²Î¿¼Á´½Ó


https://confluence.atlassian.com/crowd/crowd-security-advisory-2019-05-22-970260700.html