AtlassianÖб£´æ0dayÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-06Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-15006£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Atlassian Confluence server
Îó²î¸ÅÊö
Çå¾²Ö°Ô±SwiftOnSecurityÖܶþ¸üÐÂTwitter£¬£¬ÎÞÒâÖÐÅû¶ÁËÒ»¸öÓ°ÏìÆóÒµÈí¼þÓªÒµAtlassianµÄÁãÈÕÎó²î£¬£¬¸ÃÎó²î¿ÉÄÜÔÚIBMµÄAsperaÈí¼þÖлñµÃÌåÏÖ¡£¡£¡£¡£¡£¡£SwiftOnSecurity TwitterÕÊ»§ÏÔʾ£¬£¬AtlassianÌṩÁËÒ»¸öʹÓÃÆäConfluenceÔÆÐ§ÀÍʹÓÃͨÓÃSSLÖ¤ÊéÆÊÎöµ½ÍâµØÐ§ÀÍÆ÷µÄÓò£¬£¬ÒÔʹAtlassian CompanionÓ¦ÓóÌÐò¿ÉÒÔÔÚÊ×Ñ¡ÍâµØÓ¦ÓóÌÐòÖбà¼Îļþ²¢½«ÎļþÉúÑÄ»ØConfluence¡£¡£¡£¡£¡£¡£ÈκξßÓÐ×ã¹»ÊÖÒÕ֪ʶµÄÈ˶¼¿ÉÒÔ¸´ÖÆSSLÃÜÔ¿£¬£¬È»ºóʹÓÃËü¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬£¬Õâ¿ÉÄÜʹ¹¥»÷Õß½«Ó¦ÓóÌÐòÁ÷Á¿Öض¨Ïòµ½¶ñÒâÕ¾µã¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌûÓÐÐû²¼Îó²îÐÞ¸´³ÌÐò£¬£¬Çëʵʱ¹Ø×¢¸üУºhttps://confluence.atlassian.com/doc/administering-the-atlassian-companion-app-958456281.html¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.theregister.co.uk/2019/12/05/atlassian_zero_day_bug/


¾©¹«Íø°²±¸11010802024551ºÅ