ÿÖÜÉý¼¶²¼¸æ-2023-03-28

°ä²¼¹¦·ò 2023-03-28

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ÐÅϢй¶_MinIO[CVE-2023-28432]

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

MinIO ÊÇÒ»¸ö»ùÓÚApache License v2.0¿ªÔ´ºÍ̸µÄ¶ÔÏó´æ´¢·þÎñ¡£Ëü¼æÈÝÑÇÂíÑ·S3ÔÆ´æ´¢·þÎñ½Ó¿Ú £¬¼«¶ÈÊʺÏÓÚ´æ´¢´óÈÝÁ¿·Ç½á¹¹»¯µÄÊý¾Ý £¬ÀýÈçͼƬ¡¢ÊÓÆµ¡¢ÈÕÖ¾Îļþ¡¢±¸·ÝÊý¾ÝºÍÈÝÆ÷/Ðé¹¹»ú¾µÏñµÈ¡£

MinIOÖдæÔÚÒ»´¦ÐÅϢй¶·ì϶ £¬ÓÉÓÚMinio¼¯Èº½øÐÐÐÅÏ¢»¥»»µÄ9000¶Ë¿Ú £¬ÔÚδ¾­ÅäÖõÄÇé¿öÏÂͨ¹ý·¢ËÍÌØÊâHPPTÒªÇó½øÐÐδÊÚȨ½Ó¼û £¬½ø¶øµ¼ÖÂMinIO¶ÔÏó´æ´¢µÄÓйػ·¾³±äÁ¿Ð¹Â¶ £¬È磺MINIO_SECRET_KEY ºÍ MINIO_ROOT_PASSWORD µÈËùÓл·¾³±äÁ¿ÐÅÏ¢¡£µ¼Ö¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩÐÅÏ¢ËÁÒâ½Ó¼ûMinIO¼¯ÈºÖеÄËùÓÐÎļþ¡£Ê¹ÓùÙÍø²Ö¿â docs/orchestration/docker-compose Æô¶¯µÄµÍ°æ±¾¼¯ÈºÄ¬ÈÏÊܵ½¸Ã·ì϶ӰÏì¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ÎļþÉÏ´«_ÐźôoaÓ×ÓÚ2.3.2[CVE-2023-1501][CNNVD-202303-1481]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

RockOA ÊÇÒ»Ì׿ªÔ´µÄ°ì¹«ÏµÍ³ £¬ºÏÓÃÓÚÖÐÓ×ÐÍÆóÒµµÄͨÓÃÐÍЭͬ OA ÖÎÀíÈí¼þ £¬ÈÚºÏÁ˳־ôÓÊÂÖÎÀíÈí¼þ¿ª·¢µÄ·á˶¾­ÑéÓëÏȽø¼¼Êõ £¬¸Ãϵͳѡȡµ±Ï鵀 B/S (ä¯ÀÀÆ÷ / ·þÎñÆ÷) ²Ù×÷·½Ê½¡£¹¥»÷Õß¿Éͨ¹ýÌØ¶¨Â·ÓɽøÐÐËÁÒâÎļþÉÏ´« £¬Ôì³Égetshell¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_·´ÐòÁл¯_Fastjson_1.2.80

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ £¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£fastjsonÔÚ1.2.83ÒÔ¼°Ö®Ç°°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ°²È«·ì϶¡£¿ª·¢ÕßÔÚʹÓÃfastjsonʱ £¬ÈôÊDZàд²»µ± £¬¿ÉÄܵ¼ÖÂJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐÄ»ú¹ØµÄJSONÐòÁл¯¶ñÒâ´úÂë £¬µ±·¨Ê½Ö´ÐÐJSON·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂë £¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£³¢ÊÔ½øÐжñÒâºÅÁî»ò´úÂë×¢Èë £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ÎļþÉÏ´«_ÓÃÓÑGRP-U8²ÆÕþÖÎÀíÈí¼þ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½µ±Ç°Ö÷»úÔÚÔâ·êÓÃÓÑGRP-U8²ÆÕþÖÎÀíÈí¼þËÁÒâÎļþÉÏ´«¹¥»÷ £¬ÓÃÓÑGRP-U8²ÆÕþÖÎÀíÈí¼þ×÷Ϊ²ÆÕþÖÎÀíÈí¼þ £¬×÷ÓÃÓÚ²ÆÕþÖÎÀí £¬ÊÇÏà¶ÔÃô¸ÐµÄÒµÎñ £¬ÓÉÓÚ¶ÔÉÏ´«ÎļþÖ°ÄÜδ½øÐгä·Ö°²È«Ë¼¿¼ £¬µ¼Ö¹¥»÷Õß¿ÉÄÜͨ¹ýÉÏ´«¶ñÒâ¾ç±¾ÊµÏÖ¶ÔÖ÷»úµÄ½ÚÔì £¬·çÏսϴó¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ÎļþÉÏ´«_ÓÃÓÑU8Cloud

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ö÷»úÔÚÔâ·êÓÃÓÑU8Cloud_ÎļþÉÏ´«¹¥»÷ £¬U8cloudÊÇÓÃÓÑÍÆ³öµÄÐÂÒ»´úÔÆERP £¬ÓÉÓÚ¶ÔÉÏ´«ÎļþÖ°ÄÜδ½øÐгä·Ö°²È«Ë¼¿¼ £¬µ¼Ö¹¥»÷Õß¿ÉÄÜͨ¹ýÉÏ´«¶ñÒâ¾ç±¾ÊµÏÖ¶ÔÖ÷»úµÄ½ÚÔì £¬·çÏսϴó¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_δÊÚȨ½Ó¼û_Wavlink[CVE-2022-48165]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ö÷»úÔÚÔâ·êWavlink_δÊÚȨ½Ó¼û¹¥»÷ £¬WavlinkWL-WN530H4M30H4.V5030.210121µÄ/cgi-bin/ExportLogs.sh×é¼þÖдæÔÚ½Ó¼û½ÚÔìÎÊÌâ £¬ÔÊÐíδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÏÂÔØÅäÖÃÊý¾ÝºÍÈÕÖ¾Îļþ²¢»ñµÃÖÎÀíÖ¤Êé¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_δÊÚȨ½Ó¼û_Apache_AXIS_Services

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·Ô̺¬ÁËJavaºÍC++˵»°ÊµÏÖµÄSOAP·þÎñÆ÷ £¬ÒÔ¼°¸÷À๫Ó÷þÎñ¼°API £¬ÒÔÌìÉúºÍ²¿ÊðWeb·þÎñÀûÓ᣷ì϶ÐÔÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÅäÖÃÃýÎó¡£µ±ÓйؽӿÚδ½øÐмøÈ¨´¦Öà £¬¹¥»÷Õß¿Éͨ¹ýδÊÚȨ½Ó¼ûµ½servicesµÄwsdl½Ó¿Ú»òͨ¹ýĬÈÏ¿ÚÁî½Ó¼ûµ½servicesµÄupload½Ó¿Ú £¬²¢Í¨¹ý»ñÈ¡Ãô¸Ð½Ó¿ÚÎĵµÐÅÏ¢»ò²¿Êð¶ñÒâ·þÎñ½øÐкóÐø¹¥»÷ÐÐΪ¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_Îļþ¶ÁÈ¡_jetty[CVE-2021-28169]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ö¸±êÖ÷»úÔÚÔâ·êjettyÎļþ¶ÁÈ¡[CVE-2021-28169]¹¥»÷¡£JettyServletsÖеÄConcatServlet¡¢WelcomeFilterÀà´æÔÚ¶à³Á½âÂëÎÊÌâ £¬µ±ÀûÓõ½ÕâÁ½¸öÀà֮һʱ £¬¹¥»÷Õß¾ÍÄܹ»ÀûÓÃË«³ÁURL±àÂëÈÆ¹ýÏÞ¶ÈÀ´½Ó¼ûWEB-INFĿ¼ÏµÄÃô¸ÐÎļþ £¬Ôì³ÉÃô¸ÐÐÅϢй¶¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ÎļþÉÏ´«_·ºÎ¢OA_ajax.php

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓ÷ºÎ¢OA´æÔÚµÄÎļþÉÏ´«·ì϶½øÐÐËÁÒâÎļþÉÏ´«¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÉÏ´«¶ñÒâÎļþ £¬»ñȡָ±êϵͳȨÏÞ¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_ºÅÁî½ÚÔì_C2ͨѶ_BruteRatelC4.badger_ÐÄÌø_³É¹¦

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºÚ¿Í¹¤¾ßBruteRatelC4(ÒÔϼò³ÆBRC4)ÌìÉúµÄºóÃÅbadger³¢ÊÔÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBruteRatelC4.badger¡£BruteRatelC4£¨ÒÔϼò³ÆBRC4£©ÓÃÒÔ´úÌæÒòʹÓÃ¿í·º¶ø±»°²È«¹«Ë¾³Áµã·À±¸µÄCobaltStrike¿ò¼Ü¡£BRC4ʹÓÃÁ˶à¶àÓÃÓÚ¶ã±ÜºÍ¼ì²âEDRµÄ¼¼Êõ £¬Æä±í²¿C2Ö÷ÌâͨѶÂß¼­Êǽ«ÓÐЧ¸ºÔØÊä³ö°µ²ØÔںϷ¨ÍøÂçÁ÷Á¿ÖС£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_À¶ÁèOA_datajson.js

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃÀ¶ÁèOAÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£Àö½­ÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿Éͨ¹ýdatajson.js £¬ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20230328

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Weblogic_T3ºÍ̸[CVE-2019-2890]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©´óƽ̨ £¬ÓÃÓÚÔÚ±¾µØºÍÔÆ¶Ë¿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÀûÓ÷¨Ê½ £¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿¿µÃס¡¢³ÉÊìºÍ¿ÉÀ©´óµÄʵÏÖ¡£CVE-2019-2890·ì϶Äܹ»Ê¹ÓÃPersistentContextÀàÈÆ¹ý²¹¶¡ £¬Í¨¹ý·´ÐòÁл¯´¥·¢rmi¹ý³ÌÖв»°²È«µÄjrmp²½Öè £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ºÍÌ¸ÍøÂç½Ó¼û²¢·ÛËéÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷ £¬³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»ÊÕÊÜ»òÃô¸ÐÐÅϢй¶¡£Ó°ÏìÁìÓò£º-Weblogic10.3.6.0.0-Weblogic12.1.3.0.0-Weblogic12.2.1.3.0

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

TCP_·ì϶ÀûÓÃ_ºÅÁîÖ´ÐÐ_Exim[CVE-2019-10149]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃEximµÄÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¸Ã·ì϶ӰÏìExim4.87~4.91°æ±¾ £¬ÔÚ4.87°æ±¾Ö®Ç°ÈôÊÇÊÖ¶¯ÆôÓÃÁËEXPERIMENTAL_EVENTÑ¡Ïî £¬·þÎñÆ÷Ò²»á´æÔÚ·ì϶ £¬¸Ã·ì϶ÔÚĬÈÏÅäÖÃÏ¿ɱ»±¾µØ¹¥»÷ÕßÖ±½ÓÀûÓà £¬Í¨¹ýµÍȨÏÞÓû§Ö´ÐÐrootȨÏÞºÅÁî £¬Ô¶³Ì¹¥»÷Õß±ØÒªÅú¸ÄĬÈÏÅäÖá£ÎªÁËÔÚĬÈÏÅäÖÃÏÂÔ¶³ÌÀûÓø÷ì϶ £¬Ô¶³Ì¹¥»÷Õß±ØÒªÓë´æÔÚ·ì϶µÄ·þÎñÆ÷³ÉÁ¢7ÌìµÄÏνӣ¨Ã¿¸ô¼¸·ÖÖÓ·¢ËÍ1¸ö×Ö½Ú£©¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_H2database_console

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪ±í²¿¶ñÒâjndi·þÎñÆ÷µØÖ·¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ £¬Ñ¡È¡java˵»°±àд £¬²»ÊÜÆ½Ì¨µÄÏÞ¶È £¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸ö¼«¶È·½±ãµÄweb½ÚÔį̀ÓÃÓÚ²Ù×÷ºÍÖÎÀíÊý¾Ý¿âÄÚÈÝ¡£H2Database»¹Ìṩ¼æÈÝģʽ £¬Äܹ»¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â £¬Òò¶øÑ¡È¡H2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿â¼«¶È·½±ã¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Ruby_conversions.rb_Ruby[CVE-2013-0156]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÏòÖ÷ÕÅÖ÷»úÉϵÄRuby»ú¹Ø¶ñÒâµÄXML±í²¿ÊµÌå×¢Èë´úÂë½øÐй¥»÷£»RubyonRailsÊÇÒ»¸öÄܹ»Ê¹¿ª·¢¡¢²¿Êð¡¢ÊØ»¤webÀûÓ÷¨Ê½±äµÃµ¥Ò»µÄ¿ò¼Ü¡£

¸üй¦·ò£º

20230328

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Kibana[CVE-2019-7609]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

KibanaÊÇΪElasticsearchÉè¼ÆµÄ¿ªÔ´·ÖÎöºÍ¿ÉÊÓ»¯Æ½Ì¨¡£Äܹ»Ê¹ÓÃKibanaÀ´ËÑË÷ £¬²é¿´´æ´¢ÔÚElasticsearchË÷ÒýÖеÄÊý¾Ý²¢ÓëÖ®½»»¥¡£Äܹ»ºÜÈÝÒ×ʵÏָ߼¶µÄÊý¾Ý·ÖÎöºÍ¿ÉÊÓ»¯ £¬ÒÔͼ±êµÄ´ó¾Öչʾ³öÀ´¡£¹¥»÷ÕßÀûÓ÷ì϶Äܹ»Í¨¹ýTimelion×é¼þÖеÄJavaScriptÔ­ÐÍÁ´´«È¾¹¥»÷ £¬ÏòKibanaÌáÒéÓйØÒªÇó £¬´Ó¶øÊÕÊܵصã·þÎñÆ÷ £¬ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî £¬·ì϶ӰÏìÁìÓòÔ̺¬Kibana<6.6.1¡¢Kibana<5.6.15¡£

¸üй¦·ò£º

20230328