Confluence±¾µØÎļþй¶·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-29

?·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3394£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


?Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÒÔϰ漼ÇÉÓòÄÚµÄ Confluence Server ºÍ Data Center Êܵ½·ì϶ӰÏ죺


6.1.0 <= version < 6.6.16

6.7.0 <= version < 6.13.7

6.14.0 <= version < 6.15.8


?·ì϶¸ÅÊö


8 Ô 28 ÈÕ£¬Atlassian Confluence¹Ù·½°ä²¼°²È«¹«¸æ£¬½¨¸´ÁË´æÔÚÓÚConfluence ÖеÄÒ»´¦±¾µØÎļþй¶·ì϶£¨CVE-2019-3394£©¡£


Atlassian Confluence ServerºÍAtlassian Data Center¶¼ÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄ²úÆ·¡£Atlassian Confluence ServerÊÇÒ»Ì×רҵµÄÆóҵ֪ʶÖÎÀíÓëЭͬÈí¼þ£¬Ò²Äܹ»ÓÃÓÚ¹¹½¨ÆóÒµWiKi¡£Atlassian Data CenterÊÇÒ»Ì×Êý¾ÝÖÐÐÄϵͳ¡£


Confluence ServerºÍ Data CenterÔÚÒ³Ãæµ¼³öÖ°ÄÜÖдæÔÚ±¾µØÎļþй¶·ì϶£º¾ßÓÓ×°Ôö³¤Ò³Ã桱¿Õ¼äȨÏÞµÄÔ¶³Ì¹¥»÷Õߣ¬¿ÉÄܶÁÈ¡<install-directory>/confluence/WEB-INF/Ŀ¼ÏµÄËÁÒâÎļþ¡£¸ÃĿ¼¿ÉÄÜÔ̺¬ÓÃÓÚÓëÆäËû·þÎñ¼¯³ÉµÄÅäÖÃÎļþ£¬¿ÉÄÜ»áй©ÈÏ֤ʹ´¦£¬ÀýÈçLDAPÈÏ֤ʹ´¦»òÆäËûÃô¸ÐÐÅÏ¢¡£


?·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


?½¨¸´½¨Òé


Éý¼¶Confluenceµ½Òѽ¨¸´·ì϶µÄ¸üа汾£º6.15.8 »ò 6.13.7 »ò 6.6.16£º

https://www.atlassian.com/software/confluence/download

https://www.atlassian.com/software/confluence/download-archives


ͬʱ²é³­<install-directory>/confluence/WEB-INFĿ¼¼°Æä×ÓĿ¼£¨ÓÈÆäÊÇ/classes/Ŀ¼£©£¬¿´ÊÇ·ñÓÐÎļþÔ̺¬LDAP»òCrowdÈÏ֤ʹ´¦£¨ºÃ±Ècrowd.propertiesºÍatlassian-user.xmlÎļþ£©£¬ÒÔ¼°ÆäËû¿ÉÄܺ¬ÓÐÃô¸ÐÐÅÏ¢µÄÎļþ¡£ÈçÈô·¢ÏÖº¬ÓÐÈÏ֤ʹ´¦µÄÃô¸ÐÎļþ£¬½¨Òé¶ÔÓйØÃÜÂë½øÐÐÅú¸Ä¡£


?²Î¿¼Á´½Ó


https://confluence.atlassian.com/doc/confluence-security-advisory-2019-08-28-976161720.html