ÿÖÜÉý¼¶Í¨¸æ-2023-03-07
Ðû²¼Ê±¼ä 2023-03-07ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ȨÏÞÈÆ¹ý_Apache_Shiro_v1.5.3ÒÔÏÂ[CVE-2020-11989][CNNVD-202006-1556] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬ÊÚȨµÈ¡£¡£¹ØÓÚApacheShiro1.5.3֮ǰµÄ°æ±¾£¬£¬£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬£¬£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£ |
¸üÐÂʱ¼ä£º | 20230307 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Apache_Log4j2_jndi×¢ÈëǶÌ×lookupÈÆ¹ý[CVE-2021-44228] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ApacheLog4j2ÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕ־ЧÀÍÆ÷¡£¡£´ËÊÂÎñ´ú±í·¢Ã÷ÁËÔ´IPÖ÷»ú·¢ËÍÁËÖª×ãlog4j2×é¼þÖ§³ÖµÄÄÚÖÃlookupÃûÌõÄ×Ö·û´®£¬£¬£¬µ±Ä¿µÄIPÖ÷»úºó¶ËÎüÊÕµ½´ËÃûÌõÄ×Ö·û´®Ê±£¬£¬£¬»á×Ô¶¯Å²ÓÃlookup¹¦Ð§¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬£¬´ËÐÐΪ¾ßÓнϸßΣº¦£¬£¬£¬ÈÝÒ×±»¹¥»÷ÕßÀÄÓ㬣¬£¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬£¬²¢¾ÙÐзÇÔ¤ÆÚµÄjndiŲÓ㬣¬£¬´Ó¶øÖ´ÐжñÒâ´úÂë»òÏÂÁî¡£¡£log4j22.15.0-RC1Ö®ºóµÄ°æ±¾Ä¬ÈϹرÕÁËʹÓôËÊÖ·¨Å²ÓÃjndiŲÓõĹ¦Ð§£¬£¬£¬²¢ÏÞÖÆÁ˰×Ãûµ¥£¬£¬£¬¹ÊʹÓÃδ¾ÏÞÖÆµÄÀϰ汾log4j2×é¼þ¿ÉÄܻᱣ´æjndi×¢ÈëµÄΣº¦¡£¡£ |
¸üÐÂʱ¼ä£º | 20230307 |
ÊÂÎñÃû³Æ£º | TCP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Apache_Log4j2_jndi×¢ÈëǶÌ×lookupÈÆ¹ý[CVE-2021-44228] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕ־ЧÀÍÆ÷¡£¡£´ËÊÂÎñ´ú±í·¢Ã÷ÁËÔ´IPÖ÷»ú·¢ËÍÁËÖª×ãÄÚÖÃlookupÃûÌõÄ×Ö·û´®£¬£¬£¬µ±Ä¿µÄIPÖ÷»úºó¶ËÎüÊÕµ½´ËÃûÌõÄ×Ö·û´®Ê±£¬£¬£¬»á×Ô¶¯Å²ÓÃlookup¹¦Ð§¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬£¬´ËÐÐΪ¾ßÓÐÒ»¶¨Î£º¦£¬£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬£¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬£¬²¢¾ÙÐзÇÔ¤ÆÚµÄjndiŲÓᣡ£ |
¸üÐÂʱ¼ä£º | 20230307 |


¾©¹«Íø°²±¸11010802024551ºÅ