ConfluenceÍâµØÎļþй¶Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-08-29?Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-3394£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
?Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ÒÔϰ汾¹æÄ£ÄÚµÄ Confluence Server ºÍ Data Center Êܵ½Îó²îÓ°Ï죺
6.1.0 <= version < 6.6.16
6.7.0 <= version < 6.13.7
6.14.0 <= version < 6.15.8
?Îó²î¸ÅÊö
8 Ô 28 ÈÕ£¬£¬£¬£¬£¬Atlassian Confluence¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´Á˱£´æÓÚConfluence ÖеÄÒ»´¦ÍâµØÎļþй¶Îó²î£¨CVE-2019-3394£©¡£¡£¡£¡£¡£¡£¡£
Atlassian Confluence ServerºÍAtlassian Data Center¶¼ÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£¡£¡£Atlassian Confluence ServerÊÇÒ»Ì×רҵµÄÆóҵ֪ʶÖÎÀíÓëÐͬÈí¼þ£¬£¬£¬£¬£¬Ò²¿ÉÒÔÓÃÓÚ¹¹½¨ÆóÒµWiKi¡£¡£¡£¡£¡£¡£¡£Atlassian Data CenterÊÇÒ»Ì×Êý¾ÝÖÐÐÄϵͳ¡£¡£¡£¡£¡£¡£¡£
Confluence ServerºÍ Data CenterÔÚÒ³Ãæµ¼³ö¹¦Ð§Öб£´æÍâµØÎļþй¶Îó²î£º¾ßÓС°Ìí¼ÓÒ³Ãæ¡±¿Õ¼äȨÏÞµÄÔ¶³Ì¹¥»÷Õߣ¬£¬£¬£¬£¬Äܹ»¶ÁÈ¡<install-directory>/confluence/WEB-INF/Ŀ¼ÏµÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£¡£¸ÃĿ¼¿ÉÄܰüÀ¨ÓÃÓÚÓëÆäËûЧÀͼ¯³ÉµÄÉèÖÃÎļþ£¬£¬£¬£¬£¬¿ÉÄÜ»á×ß©ÈÏ֤ƾ֤£¬£¬£¬£¬£¬ÀýÈçLDAPÈÏ֤ƾ֤»òÆäËûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
?Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
?ÐÞ¸´½¨Òé
Éý¼¶Confluenceµ½ÒÑÐÞ¸´Îó²îµÄ¸üа汾£º6.15.8 »ò 6.13.7 »ò 6.6.16£º
https://www.atlassian.com/software/confluence/download
https://www.atlassian.com/software/confluence/download-archives
ͬʱ¼ì²é<install-directory>/confluence/WEB-INFĿ¼¼°Æä×ÓĿ¼£¨ÓÈÆäÊÇ/classes/Ŀ¼£©£¬£¬£¬£¬£¬¿´ÊÇ·ñÓÐÎļþ°üÀ¨LDAP»òCrowdÈÏ֤ƾ֤£¨ºÃ±Ècrowd.propertiesºÍatlassian-user.xmlÎļþ£©£¬£¬£¬£¬£¬ÒÔ¼°ÆäËû¿ÉÄܺ¬ÓÐÃô¸ÐÐÅÏ¢µÄÎļþ¡£¡£¡£¡£¡£¡£¡£ÈçÈô·¢Ã÷º¬ÓÐÈÏ֤ƾ֤µÄÃô¸ÐÎļþ£¬£¬£¬£¬£¬½¨Òé¶ÔÏà¹ØÃÜÂë¾ÙÐÐÐ޸ġ£¡£¡£¡£¡£¡£¡£
?²Î¿¼Á´½Ó
https://confluence.atlassian.com/doc/confluence-security-advisory-2019-08-28-976161720.html