ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ21ÖÜ

Ðû²¼Ê±¼ä 2020-05-26

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê05ÔÂ18ÈÕÖÁ05ÔÂ24ÈÕ¹²ÊÕ¼Çå¾²Îó²î60¸ö£¬£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Unified Contact Center Express·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î; Apache Tomcat session·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Google Chrome reader modeÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Emerson Electric OpenEnterprisÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Centreon main.get.php OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇiPhoneÓʼþÓ¦ÓÃEdison Mail±£´æÎó²î£¬£¬ £¬£¬£¬£¬Ð¹Â¶Óû§ÐÅÏ¢£»£»£»£»£»£»£»°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿·ÖÓªÒµÖÐÖ¹£»£»£»£»£»£»£»Daimler 580¶à¸öGit´æ´¢¿â̻¶£¬£¬ £¬£¬£¬£¬¼²³Û×é¼þOLUÔ´´úÂëй¶£»£»£»£»£»£»£»AdobeÐû²¼½ôÆÈ´øÍâ¸üУ¬£¬ £¬£¬£¬£¬ÐÞ¸´Ô¶³ÌÖ´ÐдúÂëÎó²î£»£»£»£»£»£»£»ºÚ¿Í͵ȡWishboneÖÐ4000ÍòÌõÓû§ÐÅÏ¢£¬£¬ £¬£¬£¬£¬²¢ÔÚ°µÍø±ê¼Û³öÊÛ¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Cisco Unified Contact Center Express·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î


Cisco Unified Contact Center Express JavaÔ¶³ÌÖÎÀí½çÃæ±£´æ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬¿ÉÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN


2. Apache Tomcat session·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î


Apache Tomcat±£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬µ±Ê¹ÓÃtomcatʱ£¬£¬ £¬£¬£¬£¬ÈôÊÇʹÓÃÁËtomcatÌṩµÄsession³¤ÆÚ»¯¹¦Ð§£¬£¬ £¬£¬£¬£¬ÈôÊDZ£´æÎļþÉÏ´«¹¦Ð§£¬£¬ £¬£¬£¬£¬¶ñÒâÇëÇóÕßͨ¹ýÒ»¸öÁ÷³Ì£¬£¬ £¬£¬£¬£¬½«ÄÜÌᳫһ¸ö¶ñÒâÇëÇóÔì³ÉЧÀͶËÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£

https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E


3. Google Chrome reader modeÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Google Chrome reader mode±£´æÊͷźóʹÓÃÎó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬ £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html


4. Emerson Electric OpenEnterprisÔ¶³Ì´úÂëÖ´ÐÐÎó²î


Emerson Electric OpenEnterpriseijͨѶЧÀͱ£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.us-cert.gov/ics/advisories/icsa-20-140-02


5. Centreon main.get.php OSÏÂÁî×¢ÈëÎó²î


Centreon main.get.php´¦Öóͷ£RRDdatabase_status_path²ÎÊý±£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬¿É×¢Èëí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£¡£

https://github.com/centreon/centreon/pull/8467



> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢iPhoneÓʼþÓ¦ÓÃEdison Mail±£´æÎó²î£¬£¬ £¬£¬£¬£¬Ð¹Â¶Óû§ÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/iphone-email-app-bug-caused-users-messages-to-show-up-on-other-phones-530003.shtml


2¡¢°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿·ÖÓªÒµÖÐÖ¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bluescope-reports-cyber-incident-affecting-australian-operations/


3¡¢Daimler 580¶à¸öGit´æ´¢¿â̻¶£¬£¬ £¬£¬£¬£¬¼²³Û×é¼þOLUÔ´´úÂëй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mercedes-benz-onboard-logic-unit-olu-source-code-leaks-online/


4¡¢AdobeÐû²¼½ôÆÈ´øÍâ¸üУ¬£¬ £¬£¬£¬£¬ÐÞ¸´Ô¶³ÌÖ´ÐдúÂëÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-critical-out-of-band-security-update/


5¡¢ºÚ¿Í͵ȡWishboneÖÐ4000ÍòÌõÓû§ÐÅÏ¢£¬£¬ £¬£¬£¬£¬²¢ÔÚ°µÍø±ê¼Û³öÊÛ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-selling-40-million-user-records-from-popular-wishbone-app/