ÿÖÜÉý¼¶Í¨¸æ-2022-04-19

Ðû²¼Ê±¼ä 2022-04-19
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_·ÉËþSSL-VPNÎļþ¶ÁÈ¡Îó²î[CVE-2018-13379][CNNVD-201905-1026]

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

·¢Ã÷Ä¿µÄÕýÔÚÔâÊÜ·ÉËþSSL-VP.NÎļþ¶ÁÈ¡Îó²î[CVE-2018-13379]¹¥»÷

¸üÐÂʱ¼ä£º

20220419


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache-Tapestry-HMAC_ÐÅϢй¶

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

ApacheTapestryÊÇÒ»ÖÖÓÃJava±àдµÄÃæÏò×é¼þµÄWebÓ¦ÓóÌÐò¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£Tapestry¿ÉÒÔÔÚÈκÎÓ¦ÓóÌÐòЧÀÍÆ÷ÏÂÊÂÇ飬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔÇáËɼ¯³ÉËùÓкó¶Ë£¬£¬£¬£¬£¬ÈçSpring£¬£¬£¬£¬£¬HibernateµÈ¡£¡£¡£¡£¡£¡£¡£http://localhost:8080/assets/something/services/AppModule.class/ÔÚºÚÃûµ¥¼ì²éºó£¬£¬£¬£¬£¬Ð±Ïß±»°þÀ룬£¬£¬£¬£¬AppModule.classÎļþ±»¼ÓÔØµ½ÏìÓ¦ÖС£¡£¡£¡£¡£¡£¡£Õâ¸öÀàͨ³£°üÀ¨ÓÃÓÚ¶ÔÐòÁл¯µÄJava¹¤¾ß¾ÙÐÐÊðÃûµÄHMACÃØÔ¿£¬£¬£¬£¬£¬ÔÚÖªµÀ¸ÃÃÜÔ¿µÄÇéÐÎÏ£¬£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔÇ©ÊðJavaС¹¤¾ßÁ´£¨ÀýÈçysoserialµÄCommonsBeanUtils1£©£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2021-27850£©¡£¡£¡£¡£¡£¡£¡£CVE-2021-27850Ó°Ïì¹æÄ£:ApacheTapestry5.4.5ApacheTapestry5.5.0ApacheTapestry5.6.2ApacheTapestry5.7.0

¸üÐÂʱ¼ä£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_Kylin_δÊÚȨÉèÖÃй¶Îó²î[CVE-2020-13937][CNNVD-202010-896]

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

ApacheKylinÊÇÒ»¸ö¿ªÔ´µÄÂþÑÜʽÆÊÎöÒýÇæ£¬£¬£¬£¬£¬Ëü×î³õÓÉeBay¿ª·¢£¬£¬£¬£¬£¬ÏÖÔÚÊÇApacheSoftwareFoundationµÄÏîÄ¿¡£¡£¡£¡£¡£¡£¡£ApacheKylin½¨ÉèÔÚApacheHadoop£¬£¬£¬£¬£¬ApacheHive£¬£¬£¬£¬£¬ApacheHBase£¬£¬£¬£¬£¬ApacheParquet£¬£¬£¬£¬£¬ApacheCalcite£¬£¬£¬£¬£¬ApacheSparkºÍÆäËûÊÖÒÕÖ®ÉÏ¡£¡£¡£¡£¡£¡£¡£ÕâЩÊÖÒÕʹKylin¿ÉÒÔÇáËÉÀ©Õ¹ÒÔÖ§³Öº£Á¿Êý¾Ý¸ºÔØ¡£¡£¡£¡£¡£¡£¡£ApacheKylinÓÐÒ»¸örestfulapi»áÔÚûÓÐÈÏ¿ÉÈÏÖ¤µÄÇéÐÎÏÂ̻¶ÉèÖÃÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñȡϵͳÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jira_δ¾­Éí·ÝÑéÖ¤Óû§Ãûö¾ÙÎó²î[CVE-2020-14181][CNNVD-202009-1072]

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

AtlassianJiraÊÇÆóÒµÆÕ±éʹÓõÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß£¬£¬£¬£¬£¬±»ÆÕ±éÓ¦ÓÃÓÚȱÏݸú×Ù¡¢¿Í»§Ð§ÀÍ¡¢ÐèÇóÍøÂç¡¢Á÷³ÌÉóÅú¡¢Ê¹Ãü¸ú×Ù¡¢ÏîÄ¿¸ú×ÙºÍѸËÙÖÎÀíµÈÊÂÇéÁìÓò¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÓÃÓÚö¾ÙÓû§Õ˺Å¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_Apache_Druid_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2021-26919][CNNVD-202101-2542]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheDruidʹÓÃJDBC´ÓÆäËüÊý¾Ý¿â¶ÁÈ¡Êý¾Ý£¬£¬£¬£¬£¬´Ë¹¦Ð§ÊÇΪÁËÈÃÊÜÐÅÈεÄÓû§Í¨¹ýÊʵ±µÄȨÏÞÀ´ÉèÖòéÕÒ»òÌá½»ÌáȡʹÃü¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚApacheDruidĬÈÏÇéÐÎÏÂȱ·¦ÊÚȨÈÏÖ¤£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬´Ó¶ø¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_IOTÎó²î_Trend_Micro_InterScan_WebSecurity_Virtual_Appliance_ÏÂÁî×¢ÈëÎó²î[CVE-2020-8466][CNNVD-202012-1205]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

TrendMicroInterScanWebSecurityVirtualAppliance6.5SP2±£´æÒ»¸öÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚ¶ÔHTTPÇëÇóÖÐÓû§ÌṩµÄÊý¾ÝµÄÑéÖ¤²»µ±Ôì³ÉµÄ¡£¡£¡£¡£¡£¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄЧÀÍÆ÷·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²î¿ÉÄÜÔÊÐíÔÚiscanÕÊ»§µÄÇå¾²ÉÏÏÂÎÄÖÐÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Nexus_EL±í´ïʽעÈëÎó²î[CVE-2018-16341]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

NuxeoPlatformÊÇÒ»¿î¿çƽ̨¿ªÔ´µÄÆóÒµ¼¶ÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚnuxeo-jsf-ui×é¼þ´¦Öóͷ£faceletÄ£°å²»µ±£¬£¬£¬£¬£¬µ±»á¼ûµÄfaceletÄ£°å²»±£´æÊ±£¬£¬£¬£¬£¬Ïà¹ØµÄÎļþÃû»áÊä³öµ½¹ýÊ§Ò³ÃæÉÏ£¬£¬£¬£¬£¬¶ø¹ýÊ§Ò³Ãæ»áµ±³ÉÄ£°å±»ÆÊÎö£¬£¬£¬£¬£¬ÎļþÃû°üÀ¨±í´ïʽ»á±»Êä³öͬʱ±»ÆÊÎöÖ´ÐУ¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Zoho_ManageEngine_Applications_Manager_upload.php_í§ÒâÎļþÉÏ´«Îó²î[CVE-2020-14008][CNNVD-202009-296]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ZohoManageEngineApplicationsManager14710¼°Ö®Ç°°æ±¾ÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÖÎÀíÔ±Óû§ÔÚÌØ¶¨Î»ÖÃÉÏ´«í§ÒâjarÎļþ£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419

 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Fodcha_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½½©Ê¬ÍøÂçFodchaÊÔͼÅþÁ¬C&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFodcha¡£¡£¡£¡£¡£¡£¡£FodchaÖ÷Ҫͨ¹ýNDayÎó²îºÍTelnet/SSHÈõ¿ÚÁîÈö²¥£¬£¬£¬£¬£¬°üÀ¨CVE-2021-22205¡¢CVE-2021-35394¡¢AndroidADBDebugServerRCE¡¢LILINDVRRCEµÈÎó²î¡£¡£¡£¡£¡£¡£¡£ÖðÈÕÉÏÏß¾³ÄÚÈ⼦ÊýÒÔIPÊýÅÌËãÒÑÁè¼Ý1Íò£¬£¬£¬£¬£¬ÇÒÖðÈÕ»áÕë¶ÔÁè¼Ý100¸ö¹¥»÷Ä¿µÄÌᳫDDoS¹¥»÷£¬£¬£¬£¬£¬¹¥»÷·Ç³£»£»£»£»îÔ¾¡£¡£¡£¡£¡£¡£¡£FodchaʹÓÃChaCha20¼ÓÃܺÍC&CµÄͨѶÊý¾Ý¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419

  

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ExifTool_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-22204]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ExifToolÊÇÒ»¸ö×ÔÁ¦ÓÚÆ½Ì¨µÄPerl¿â£¬£¬£¬£¬£¬Ò²ÓÐÒ»¸öÏÂÁîÐÐÓ¦ÓóÌÐò£¬£¬£¬£¬£¬ÓÃÓÚ¶ÁÈ¡£¬£¬£¬£¬£¬Ð´ÈëºÍ±à¼­ÖÖÖÖÎļþÖеÄÔªÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚExifTool°æ±¾7.44°æ±¾Öб£´æ¶ÔDjVuÎļþÃûÌõÄÊý¾Ý´¦Öóͷ£²»µ±¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚº¬ÓÐÎó²î°æ±¾µÄExifTool¿âµÄÓ¦ÓÃЧÀÍÆ÷»òÕßÓ¦ÓóÌÐòÏ£¬£¬£¬£¬£¬½á¹¹¶ñÒâDjVuÎļþ£¬£¬£¬£¬£¬Ð§ÀÍÆ÷»òÕßÓ¦ÓóÌÐòÔ¶³ÌÍâµØÆÊÎö´ËÎļþ£¬£¬£¬£¬£¬µ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬×îÖÕ»ñȡЧÀÍÆ÷×î¸ßȨÏÞ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_IBM_QRada_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-1418][CNNVD-201804-1475]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

IBMQRadarÊÇÒ»¿îÆóÒµÇå¾²ÐÅÏ¢ºÍÊÂÎñÖÎÀí²úÆ·£¬£¬£¬£¬£¬ÓÃÓÚ×ÊÖúÇå¾²ÆÊÎöʦʶ±ðÆäÍøÂçÖеÄÖØ´óÍþв²¢¸ÄÉÆÊÂÎñÐÞ²¹²½·¥¡£¡£¡£¡£¡£¡£¡£IBMSecurityQRadarSIEM7.2ºÍ7.3±£´æÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔÊÐíÓû§ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_FatalRat_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºóÃÅFatalRatÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFatalRat¡£¡£¡£¡£¡£¡£¡£FatalRatÊÇÒ»ÖÖÖØ´óµÄC++RAT£¬£¬£¬£¬£¬¿ÉΪ¹¥»÷ÕßʵÏÖÆÕ±éµÄÔ¶¿Ø¹¦Ð§¡£¡£¡£¡£¡£¡£¡£×ϺüľÂíPurpleFox×Ô2018ÄêÒÔÀ´¾ÍÒ»Ö±×îÏÈ»îÔ¾¡£¡£¡£¡£¡£¡£¡£×î½üPurpleFoxͨ¹ýË¢ÐÂÆäÎäÆ÷¿â£¬£¬£¬£¬£¬ÓÖ×îÏÈÁËÐÂÒ»²¨µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÆäÎäÆ÷¿â¾Í°üÀ¨Á˺óÃÅFatalRat¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-061Ô¶³ÌÏÂÁîÖ´Ðй¥»÷[CVE-2020-17530][CNNVD-202012-449][CVE-2020-17530/CVE-2021-31805][CNNVD-202012-449/CNNVD-202204-3223]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄÇëÇ󣬣¬£¬£¬£¬Òý·¢OGNL±í´ïʽÆÊÎö£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220419