ÿÖÜÉý¼¶Í¨¸æ-2023-03-28
Ðû²¼Ê±¼ä 2023-03-28ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÐÅϢй¶_MinIO[CVE-2023-28432] |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò£º | MinIO ÊÇÒ»¸ö»ùÓÚApache License v2.0¿ªÔ´ÐÒéµÄ¹¤¾ß´æ´¢Ð§ÀÍ¡£¡£¡£Ëü¼æÈÝÑÇÂíÑ·S3ÔÆ´æ´¢Ð§Àͽӿڣ¬£¬£¬£¬ºÜÊÇÊʺÏÓÚ´æ´¢´óÈÝÁ¿·Ç½á¹¹»¯µÄÊý¾Ý£¬£¬£¬£¬ÀýÈçͼƬ¡¢ÊÓÆµ¡¢ÈÕÖ¾Îļþ¡¢±¸·ÝÊý¾ÝºÍÈÝÆ÷/ÐéÄâ»ú¾µÏñµÈ¡£¡£¡£ MinIOÖб£´æÒ»´¦ÐÅϢй¶Îó²î£¬£¬£¬£¬ÓÉÓÚMinio¼¯Èº¾ÙÐÐÐÅÏ¢½»Á÷µÄ9000¶Ë¿Ú£¬£¬£¬£¬ÔÚδ¾ÉèÖõÄÇéÐÎÏÂͨ¹ý·¢ËÍÌØÊâHPPTÇëÇó¾ÙÐÐδÊÚȨ»á¼û£¬£¬£¬£¬½ø¶øµ¼ÖÂMinIO¹¤¾ß´æ´¢µÄÏà¹ØÇéÐαäÁ¿Ð¹Â¶£¬£¬£¬£¬È磺MINIO_SECRET_KEY ºÍ MINIO_ROOT_PASSWORD µÈËùÓÐÇéÐαäÁ¿ÐÅÏ¢¡£¡£¡£µ¼Ö¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÐÅÏ¢í§Òâ»á¼ûMinIO¼¯ÈºÖеÄËùÓÐÎļþ¡£¡£¡£Ê¹ÓùÙÍø¿ÍÕ» docs/orchestration/docker-compose Æô¶¯µÄµÍ°æ±¾¼¯ÈºÄ¬ÈÏÊܵ½¸ÃÎó²îÓ°Ïì¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ÐźôoaСÓÚ2.3.2[CVE-2023-1501][CNNVD-202303-1481] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | RockOA ÊÇÒ»Ì׿ªÔ´µÄ°ì¹«ÏµÍ³£¬£¬£¬£¬ÊÊÓÃÓÚÖÐСÐÍÆóÒµµÄͨÓÃÐÍÐͬ OA ÖÎÀíÈí¼þ£¬£¬£¬£¬ÈÚºÏÁ˺ã¾Ã´ÓÊÂÖÎÀíÈí¼þ¿ª·¢µÄ¸»ºñÂÄÀúÓëÏȽøÊÖÒÕ£¬£¬£¬£¬¸Ãϵͳ½ÓÄÉÁìÏ鵀 B/S (ä¯ÀÀÆ÷ / ЧÀÍÆ÷) ²Ù×÷·½·¨¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÌØ¶¨Â·ÓɾÙÐÐí§ÒâÎļþÉÏ´«£¬£¬£¬£¬Ôì³Égetshell¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_·´ÐòÁл¯_Fastjson_1.2.80 |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£fastjsonÔÚ1.2.83ÒÔ¼°Ö®Ç°°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¡£¡£¿£¿ª·¢ÕßÔÚʹÓÃfastjsonʱ£¬£¬£¬£¬ÈôÊDZàд²»µ±£¬£¬£¬£¬¿ÉÄܵ¼ÖÂJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬£¬£¬£¬µ±³ÌÐòÖ´ÐÐJSON·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ÊµÑé¾ÙÐжñÒâÏÂÁî»ò´úÂë×¢È룬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ÓÃÓÑGRP-U8²ÆÎñÖÎÀíÈí¼þ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ä¿½ñÖ÷»úÕýÔÚÔâÊÜÓÃÓÑGRP-U8²ÆÎñÖÎÀíÈí¼þí§ÒâÎļþÉÏ´«¹¥»÷£¬£¬£¬£¬ÓÃÓÑGRP-U8²ÆÎñÖÎÀíÈí¼þ×÷Ϊ²ÆÎñÖÎÀíÈí¼þ£¬£¬£¬£¬×÷ÓÃÓÚ²ÆÎñÖÎÀí£¬£¬£¬£¬ÊÇÏà¶ÔÃô¸ÐµÄÓªÒµ£¬£¬£¬£¬ÓÉÓÚ¶ÔÉÏ´«Îļþ¹¦Ð§Î´¾ÙÐгä·ÖÇ徲˼Á¿£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«¶ñÒâ¾ç±¾ÊµÏÖ¶ÔÖ÷»úµÄ¿ØÖÆ£¬£¬£¬£¬Î£º¦½Ï´ó¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ÓÃÓÑU8Cloud |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ö÷»úÕýÔÚÔâÊÜÓÃÓÑU8Cloud_ÎļþÉÏ´«¹¥»÷£¬£¬£¬£¬U8cloudÊÇÓÃÓÑÍÆ³öµÄÐÂÒ»´úÔÆERP£¬£¬£¬£¬ÓÉÓÚ¶ÔÉÏ´«Îļþ¹¦Ð§Î´¾ÙÐгä·ÖÇ徲˼Á¿£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÉÏ´«¶ñÒâ¾ç±¾ÊµÏÖ¶ÔÖ÷»úµÄ¿ØÖÆ£¬£¬£¬£¬Î£º¦½Ï´ó¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_δÊÚȨ»á¼û_Wavlink[CVE-2022-48165] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ö÷»úÕýÔÚÔâÊÜWavlink_δÊÚȨ»á¼û¹¥»÷£¬£¬£¬£¬WavlinkWL-WN530H4M30H4.V5030.210121µÄ/cgi-bin/ExportLogs.sh×é¼þÖб£´æ»á¼û¿ØÖÆÎÊÌ⣬£¬£¬£¬ÔÊÐíδ¾ÈÏÖ¤µÄ¹¥»÷ÕßÏÂÔØÉèÖÃÊý¾ÝºÍÈÕÖ¾Îļþ²¢»ñµÃÖÎÀíÖ¤Êé¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_δÊÚȨ»á¼û_Apache_AXIS_Services |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWebЧÀͼܹ¹¡£¡£¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAPЧÀÍÆ÷£¬£¬£¬£¬ÒÔ¼°ÖÖÖÖ¹«ÓÃЧÀͼ°API£¬£¬£¬£¬ÒÔÌìÉúºÍ°²ÅÅWebЧÀÍÓ¦Óᣡ£¡£Îó²îʵÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÉèÖùýʧ¡£¡£¡£µ±Ïà¹Ø½Ó¿Úδ¾ÙÐмøÈ¨´¦Öóͷ££¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýδÊÚȨ»á¼ûµ½servicesµÄwsdl½Ó¿Ú»òͨ¹ýĬÈÏ¿ÚÁî»á¼ûµ½servicesµÄupload½Ó¿Ú£¬£¬£¬£¬²¢Í¨¹ý»ñÈ¡Ãô¸Ð½Ó¿ÚÎĵµÐÅÏ¢»ò°²ÅŶñÒâЧÀ;ÙÐкóÐø¹¥»÷ÐÐΪ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_Îļþ¶ÁÈ¡_jetty[CVE-2021-28169] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ä¿µÄÖ÷»úÕýÔÚÔâÊÜjettyÎļþ¶ÁÈ¡[CVE-2021-28169]¹¥»÷¡£¡£¡£JettyServletsÖеÄConcatServlet¡¢WelcomeFilterÀà±£´æ¶àÖØ½âÂëÎÊÌ⣬£¬£¬£¬µ±Ó¦Óõ½ÕâÁ½¸öÀà֮һʱ£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔʹÓÃË«ÖØURL±àÂëÈÆ¹ýÏÞÖÆÀ´»á¼ûWEB-INFĿ¼ÏµÄÃô¸ÐÎļþ£¬£¬£¬£¬Ôì³ÉÃô¸ÐÐÅϢй¶¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_·ºÎ¢OA_ajax.php |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓ÷ºÎ¢OA±£´æµÄÎļþÉÏ´«Îó²î¾ÙÐÐí§ÒâÎļþÉÏ´«¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÉÏ´«¶ñÒâÎļþ£¬£¬£¬£¬»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_ÏÂÁî¿ØÖÆ_C2ͨѶ_BruteRatelC4.badger_ÐÄÌø_ÀÖ³É |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½ºÚ¿Í¹¤¾ßBruteRatelC4(ÒÔϼò³ÆBRC4)ÌìÉúµÄºóÃÅbadgerʵÑéÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBruteRatelC4.badger¡£¡£¡£BruteRatelC4£¨ÒÔϼò³ÆBRC4£©ÓÃÒÔÌæ»»ÒòʹÓÃÆÕ±é¶ø±»Çå¾²¹«Ë¾ÖصãÌá·ÀµÄCobaltStrike¿ò¼Ü¡£¡£¡£BRC4ʹÓÃÁËÖÚ¶àÓÃÓÚ¹æ±ÜºÍ¼ì²âEDRµÄÊÖÒÕ£¬£¬£¬£¬ÆäÍⲿC2½¹µãͨѶÂß¼Êǽ«ÓÐÓøºÔØÊä³öÒþ²ØÔÚÕýµ±ÍøÂçÁ÷Á¿ÖС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_À¶ÁèOA_datajson.js |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÀ¶ÁèOAÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£ÉîÛÚÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýdatajson.js£¬£¬£¬£¬ÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Weblogic_T3ÐÒé[CVE-2019-2890] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨£¬£¬£¬£¬ÓÃÓÚÔÚÍâµØºÍÔÆ¶Ë¿ª·¢¡¢°²ÅźÍÔËÐÐÆóÒµÓ¦ÓóÌÐò£¬£¬£¬£¬ÀýÈçJava¡£¡£¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£¡£¡£CVE-2019-2890Îó²î¿ÉÒÔʹÓÃPersistentContextÀàÈÆ¹ý²¹¶¡£¬£¬£¬£¬Í¨¹ý·´ÐòÁл¯´¥·¢rmiÀú³ÌÖв»Çå¾²µÄjrmpÒªÁ죬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ÐÒéÍøÂç»á¼û²¢ÆÆËðÒ×Êܹ¥»÷µÄWebLogicЧÀÍÆ÷£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂOracleWebLogicЧÀÍÆ÷±»½ÓÊÜ»òÃô¸ÐÐÅϢй¶¡£¡£¡£Ó°Ïì¹æÄ££º-Weblogic10.3.6.0.0-Weblogic12.1.3.0.0-Weblogic12.2.1.3.0 |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | TCP_Îó²îʹÓÃ_ÏÂÁîÖ´ÐÐ_Exim[CVE-2019-10149] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃEximµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¸ÃÎó²îÓ°ÏìExim4.87~4.91°æ±¾£¬£¬£¬£¬ÔÚ4.87°æ±¾Ö®Ç°ÈôÊÇÊÖ¶¯ÆôÓÃÁËEXPERIMENTAL_EVENTÑ¡Ï£¬£¬£¬Ð§ÀÍÆ÷Ò²»á±£´æÎó²î£¬£¬£¬£¬¸ÃÎó²îÔÚĬÈÏÉèÖÃÏ¿ɱ»ÍâµØ¹¥»÷ÕßÖ±½ÓʹÓ㬣¬£¬£¬Í¨¹ýµÍȨÏÞÓû§Ö´ÐÐrootȨÏÞÏÂÁ£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÐèÒªÐÞ¸ÄĬÈÏÉèÖᣡ£¡£ÎªÁËÔÚĬÈÏÉèÖÃÏÂÔ¶³ÌʹÓøÃÎó²î£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÐèÒªÓë±£´æÎó²îµÄЧÀÍÆ÷½¨Éè7ÌìµÄÅþÁ¬£¨Ã¿¸ô¼¸·ÖÖÓ·¢ËÍ1¸ö×Ö½Ú£©¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_H2database_console |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndiЧÀÍÆ÷µØµã¡£¡£¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ£¬£¬£¬£¬½ÓÄÉjavaÓïÑÔ±àд£¬£¬£¬£¬²»ÊÜÆ½Ì¨µÄÏÞÖÆ£¬£¬£¬£¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸öÊ®·ÖÀû±ãµÄweb¿ØÖÆÌ¨ÓÃÓÚ²Ù×÷ºÍÖÎÀíÊý¾Ý¿âÄÚÈÝ¡£¡£¡£H2Database»¹Ìṩ¼æÈÝģʽ£¬£¬£¬£¬¿ÉÒÔ¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â£¬£¬£¬£¬Òò´Ë½ÓÄÉH2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿âºÜÊÇÀû±ã¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Ruby_conversions.rb_Ruby[CVE-2013-0156] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄÖ÷»úÉϵÄRuby½á¹¹¶ñÒâµÄXMLÍⲿʵÌå×¢Èë´úÂë¾ÙÐй¥»÷£»£»£»RubyonRailsÊÇÒ»¸ö¿ÉÒÔʹ¿ª·¢¡¢°²ÅÅ¡¢Î¬»¤webÓ¦ÓóÌÐò±äµÃ¼òÆÓµÄ¿ò¼Ü¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Kibana[CVE-2019-7609] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | KibanaÊÇΪElasticsearchÉè¼ÆµÄ¿ªÔ´ÆÊÎöºÍ¿ÉÊÓ»¯Æ½Ì¨¡£¡£¡£¿£¿ÉÒÔʹÓÃKibanaÀ´ËÑË÷£¬£¬£¬£¬Éó²é´æ´¢ÔÚElasticsearchË÷ÒýÖеÄÊý¾Ý²¢ÓëÖ®½»»¥¡£¡£¡£¿£¿ÉÒÔºÜÈÝÒ×ʵÏָ߼¶µÄÊý¾ÝÆÊÎöºÍ¿ÉÊÓ»¯£¬£¬£¬£¬ÒÔͼ±êµÄÐÎʽչÏÖ³öÀ´¡£¡£¡£¹¥»÷ÕßʹÓÃÎó²î¿ÉÒÔͨ¹ýTimelion×é¼þÖеÄJavaScriptÔÐÍÁ´ÎÛȾ¹¥»÷£¬£¬£¬£¬ÏòKibanaÌᳫÏà¹ØÇëÇ󣬣¬£¬£¬´Ó¶ø½ÓÊÜËùÔÚЧÀÍÆ÷£¬£¬£¬£¬ÔÚЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬Îó²îÓ°Ïì¹æÄ£°üÀ¨Kibana<6.6.1¡¢Kibana<5.6.15¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230328 |


¾©¹«Íø°²±¸11010802024551ºÅ