Confluence ·¾¶´©Ô½Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-04-18

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3398£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì²úÆ·


Confluence Server

Confluence Data Center


Ó°Ïì°æ±¾


6.6.14֮ǰµÄËùÓа汾
ËùÓÐ6.7.x-6.11.x°æ±¾
6.12.4 ֮ǰµÄËùÓÐ6.12.x°æ±¾
6.13.4 ֮ǰµÄËùÓÐ6.13.x°æ±¾
6.14.3 ֮ǰµÄËùÓÐ6.14.x°æ±¾

6.15.2 ֮ǰµÄËùÓÐ6.15.x°æ±¾


Îó²î¸ÅÊö


4 Ô 17 ÈÕ£¬£¬£¬Atlassian Confluence ¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬ÐÞ¸´Á˱£´æÓÚ Confluence ÖеÄÒ»´¦Â·¾¶´©Ô½Îó²î¡£¡£ ¡£¡£¡£
Confluence Server ºÍ Data Center ÔÚ downloadallattachments ×ÊÔ´Öб£´æÂ·¾¶´©Ô½Îó²î¡£¡£ ¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓôËÎó²î£¬£¬£¬¿ÉÒÔÔÚЧÀÍÆ÷ÉÏí§ÒâĿ¼ÉÏ´«Îļþ´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄΣº¦¡£¡£ ¡£¡£¡£
´ËÎó²îµÄʹÓÃÐèÒª¹¥»÷ÕßÓµÓÐÒÔÏÂȨÏÞÖ®Ò»£º
1. Äܹ»ÏòÒ³Ãæ»ò²©¿ÍÌí¼Ó¸½¼þ
2. Äܹ»½¨ÉèеĿռ䣨space£©

3. ¶Ôij¿Õ¼ä£¨space£©ÓÐ Admin ȨÏÞ


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£ ¡£¡£¡£


ÐÞ¸´½¨Òé


1¡¢Éý¼¶Confluence Server»òData Center°æ±¾£º
6.6.13
6.13.4
6.14.3

6.15.2


2¡¢Ö´Ðйٷ½»º½â²½·¥£º
×èÖ¹Confluence
±à¼­/conf/server.xml
ÈôÊÇÄãûÓÐΪ Confluence ÉèÖà context path£¬£¬£¬Ôò½«ÒÔÏ´úÂëÌí¼ÓÖÁ ÔªËØÖУº
path="/pages/downloadallattachments.action" docBase="" >
className="org.apache.catalina.valapps.RemoteAddrValapp" deny="*" />

ÈôÊÇÄãΪ Confluence ÉèÖÃÁË context path£¬£¬£¬ºÃ±È˵ /wiki£¬£¬£¬ÔòÐèÒª½«ÒÔÏ´úÂëÌí¼ÓÖÁ ÔªËØÖУº
path="/wiki/pages/downloadallattachments.action" docBase="" >


ÉúÑÄÎļþ£¬£¬£¬ÖØÆôConfluence
ÑéÖ¤»º½â²½·¥ÊÇ·ñÉúЧ£º
»á¼ûº¬ÓÐ2¸ö»òÒÔÉϸ½¼þµÄÒ³Ãæ/²©¿Í£¬£¬£¬µã»÷... > ¸½¼þ > ÏÂÔØËùÓÐ

Èô·µ»Ø404Ò³Ãæ£¬£¬£¬Ôò˵Ã÷»º½â²½·¥ÒÑÉúЧ¡£¡£ ¡£¡£¡£


²Î¿¼Á´½Ó


https://confluence.atlassian.com/doc/confluence-security-advisory-2019-04-17-968660855.html