ÿÖÜÉý¼¶Í¨¸æ-2023-04-25
Ðû²¼Ê±¼ä 2023-04-25ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_·´ÐòÁл¯_Spring_Boot_Actuator_Snakeyaml_Ô¶³Ì´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.cloud.bootstrap.locationÉèÖÃΪ¶ñÒâyamlÎļþURLµØµã¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_Spring_Boot_logging.config_logback_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«logging.configÉèÖÃΪ¶ñÒâxmlÎļþµØµã¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_Îļþ°üÀ¨_spring-boot-actuator-logview[CVE-2021-21234][CNNVD-202101-261] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃspring-boot-actuator-logviewÎļþ°üÀ¨Îó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£spring-boot-actuator-logviewÊÇÒ»¸ö¼òÆÓµÄÈÕÖ¾ÎļþÉó²éÆ÷×÷ΪSpringBootÖ´ÐÐÆ÷¶Ëµã£¬£¬£¬£¬£¬£¬ÔÚ0.2.12¼°Ö®Ç°°æ±¾Öб£´æ×ÅÎļþ°üÀ¨Îó²î£¬£¬£¬£¬£¬£¬±àºÅCVE-2021-21234¡£¡£¡£¡£¡£Îó²îʵÖÊÊÇSpringBootÖ´ÐÐÆ÷ͨ¹ýÇëÇóµÄ²ÎÊýÀ´Ö¸¶¨ÎļþÃûºÍÎļþ¼Ð·¾¶£¬£¬£¬£¬£¬£¬¾ÓÉ×éºÏÆ´½ÓµÖ´ïĿ¼±éÀú£¬£¬£¬£¬£¬£¬ËäȻԴÂëÖмì²éÁËÎļþÃû£¨filename£©²ÎÊýÀ´±ÜÃâĿ¼±éÀú£¬£¬£¬£¬£¬£¬¿ÉÊÇûÓмì²éÎļþ¼Ð£¨base£©²ÎÊý£¬£¬£¬£¬£¬£¬Ôì³ÉÁ˹¥»÷Õß¿ÉÒÔ¾ÙÐÐĿ¼±éÀú¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | DNS_ľÂíºóÃÅ_AgentTesla_C2ÓòÃûÆÊÎöÇëÇó |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½ÊÔͼÇëÇóÆÊÎöAgentTeslaµÄC2ÓòÃû¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAgentTesla Keylogger¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_CommonsConfiguration_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úsnakeyaml CommonsConfiguration jndi×¢ÈëÎó²î¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | DNS_ÏÂÁî¿ØÖÆ_ľÂíºóÃÅ_SalityѬȾÐͲ¡¶¾_ÓòÃûÆÊÎöÇëÇó |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´Ö÷»úÕýÔÚʵÑéÆÊÎö SalityѬȾÐͲ¡¶¾ µÄ¶ñÒâÓòÃû£¬£¬£¬£¬£¬£¬Ô´Ö÷»ú¿ÉÄÜÒѾ±»Ö²Èë SalityѬȾÐͲ¡¶¾¡£¡£¡£¡£¡£Sality Äܹ»ÔÚWindows²Ù×÷ϵͳµÄÅÌËã»úÉϾÙÐÐ×ÔÎÒ¸´ÖƺÍÈö²¥£¬£¬£¬£¬£¬£¬Í¬Ê±»¹Äܹ»¾ÙÐÐÔ¶³Ì¿ØÖƺÍÐÅÏ¢ÇÔÈ¡¡£¡£¡£¡£¡£Sality²¡¶¾µÄÈö²¥·½·¨ºÜÊÇÎÞа£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÖÖÖÖ·½·¨¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬£¬ÀýÈçʹÓÿÉÒÆ¶¯×°±¸¡¢Í¨¹ýÎļþ¹²ÏíÈí¼þ¡¢µç×ÓÓʼþµÈ·½·¨¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_ÏÂÁîÓë¿ØÖÆ_Ô¶¿ØºóÃÅ_FiveSys_ÅþÁ¬C2ЧÀÍÆ÷ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½FiveSysľÂíºóÃÅÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£FiveSysľÂíÖ÷Òª¹¦Ð§Êǽ«Ê¹ÓÃÕßÁ÷Á¿·öÒýµ½Ìض¨¶ñÒâÊðÀíЧÀÍÆ÷£»£»£»£»FiveSysÄ¿µÄÊÇÔÚÓû§ÅþÁ¬ÏßÉÏÓÎϷʱ£¬£¬£¬£¬£¬£¬½«Óû§Á÷Á¿µ¼ÏòÊðÀíЧÀÍÆ÷ʱ£¬£¬£¬£¬£¬£¬½è´Ë×èµ²¡¢ÇÔÈ¡Óû§ÕÊÃܵÈÑéÖ¤ÐÅÏ¢¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÎļþÏÂÔØ_RuoYiºǫ́ÖÎÀíϵͳ[CVE-2023-27025][CNNVD-202304-021] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | RuoyiÔÚv4.7.6¼°ÒÔϰ汾Öб£´æí§ÒâÎļþÏÂÔØÎó²î£¬£¬£¬£¬£¬£¬¾ÓÉÉí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃ׼ʱʹÃüÏÂÔØí§ÒâÎļþ¡£¡£¡£¡£¡£ÈôÊÇϵͳδ¶Ô¶ÁÈ¡/ÏÂÔØÎļþµÄÎļþĿ¼×öÏÞÖÆ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÖ±½Ó¶ÁÈ¡webĿ¼ÏÂí§ÒâÎļþ£¬£¬£¬£¬£¬£¬ºÃ±ÈÉèÖÃÎļþ¡¢Êý¾Ý¿âÎļþµÈ£¬£¬£¬£¬£¬£¬ÉõÖÁÖ±½Ó»ñȡЧÀÍÆ÷ÉÏí§ÒâÎļþÄÚÈÝ¡£¡£¡£¡£¡£Ruoyiºǫ́ÖÎÀíϵͳÊÇ»ùÓÚSpringBootµÄȨÏÞÖÎÀíϵͳ¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JndiRefForwardingDataSource_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úsnakeyaml JndiRefForwardingDataSource jndi×¢ÈëÎó²î¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_Spring_Boot_spring.main.sources_groovy_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.main.sourcesÉèÖÃΪ¶ñÒâgroovyÎļþµØµã¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Spring_Boot_Actuator_datasource_Ô¶³Ì´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.datasource.dataÊôÐÔÉèÖÃΪ¶ñÒâsqlÎļþµÄURLµØµã¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_·´ÐòÁл¯_SnakeYaml_MarshalOutputStream_í§ÒâÎļþдÈë |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úsnakeyaml MarshalOutputStream ÎļþдÈëÎó²î¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_ÓÃÓÑNC_uapjs_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNC6.5ÖÐjsinvoke½Ó¿Ú±£´æµÄí§ÒâÒªÁìŲÓÃÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÎļþÏÂÔØ_ͨ´ïOA_video_file.php |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ʹÓÃMEDIA_DIRÓëMEDIA_NAME²ÎÊýÖµÁýÕÖ¾ÙÐз¾¶´©Ô½²¢½ÓÄÉhttpµÄÏìÓ¦Content-DispositionÍ·×Ö¶ÎʵÏÖí§ÒâÎļþµÄÏÂÔØ¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_PostgreSQL-JDBC-Driver_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-21724] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | PostgreSQLÊý¾Ý¿âµÄjdbcÇý¶¯³ÌÐòÖб£´æÒ»¸öÇå¾²Îó²î¡£¡£¡£¡£¡£µ±¹¥»÷Õß¿ØÖÆjdbcurl»òÕßÊôÐÔʱ£¬£¬£¬£¬£¬£¬Ê¹ÓÃPostgreSQLÊý¾Ý¿âµÄϵͳ½«Êܵ½¹¥»÷¡£¡£¡£¡£¡£pgjdbcƾ֤ͨ¹ýauthenticationPluginClassName¡¢sslhostnameverifier¡¢socketFactory¡¢sslfactory¡¢sslpasswordcallbackÅþÁ¬ÊôÐÔÌṩÀàÃûʵÀý»¯²å¼þʵÀý¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬Çý¶¯³ÌÐòÔÚʵÀý»¯Àà֮ǰûÓÐÑéÖ¤ÀàÊÇ·ñʵÏÖÁËÔ¤ÆÚµÄ½Ó¿Ú¡£¡£¡£¡£¡£Õâ¿ÉÄܵ¼ÖÂͨ¹ýí§ÒâÀà¼ÓÔØÔ¶³Ì´úÂëÖ´ÐлòÎļþдÈë¹¥»÷¡£¡£¡£¡£¡£Ó°Ïì°æ±¾£ºpostgresql_jdbc_driver<42.2.25£¬£¬£¬£¬£¬£¬42.3.0<=postgresql_jdbc_driver<=42.3.1 |
¸üÐÂʱ¼ä£º | 20230425 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ScriptEngineManager_SnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃSnakeYAMLScriptEngineManager·´ÐòÁл¯Ê¹ÓÃÁ´¾ÙÐй¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£¡£¡£SnakeYamlÊÇJavaÓÃÓÚÆÊÎöYaml£¨YetAnotherMarkupLanguage£©ÃûÌÃÊý¾ÝµÄÀà¿â£¬£¬£¬£¬£¬£¬ËüÌṩÁËdumpÒªÁì¿ÉÒÔ½«Ò»¸öJava¹¤¾ßתΪYamlÃûÌÃ×Ö·û´®,ÆäloadÒªÁìÒ²Äܹ»½«Yaml×Ö·û´®×ªÎªJava¹¤¾ß¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_H2database_console |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndiЧÀÍÆ÷µØµã¡£¡£¡£¡£¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ£¬£¬£¬£¬£¬£¬½ÓÄÉjavaÓïÑÔ±àд£¬£¬£¬£¬£¬£¬²»ÊÜÆ½Ì¨µÄÏÞÖÆ£¬£¬£¬£¬£¬£¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸öÊ®·ÖÀû±ãµÄweb¿ØÖÆÌ¨ÓÃÓÚ²Ù×÷ºÍÖÎÀíÊý¾Ý¿âÄÚÈÝ¡£¡£¡£¡£¡£H2Database»¹Ìṩ¼æÈÝģʽ£¬£¬£¬£¬£¬£¬¿ÉÒÔ¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬Òò´Ë½ÓÄÉH2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿âºÜÊÇÀû±ã¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Groovy1_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃGroovy1µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£ApacheGroovyÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄ¶¯Ì¬±à³ÌÓïÑÔ£¬£¬£¬£¬£¬£¬¿¿×ů侫Á·¡¢ÓëJavaºÜÊÇÏàËÆÒÔ¼°Ò×ÓÚѧϰµÄÓï·¨£¬£¬£¬£¬£¬£¬»ùÓÚJavaƽ̨µÄGroovy¹Ø×¢ÓÚÌá¸ß¿ª·¢ÕßµÄÉú²úÐÔ¡£¡£¡£¡£¡£Ëü¿ÉÒÔºÍÈκÎJavaÓïÑÔ¾ÙÐÐÎ޷켯³É£¬£¬£¬£¬£¬£¬Ö§³ÖDSL£¬£¬£¬£¬£¬£¬ÌṩÔËÐн׶κͱàÒë½×¶ÎÔªÊý¾Ý±à³ÌµÈǿʢµÄ¹¦Ð§¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_Îļþ¶ÁÈ¡_Grafana_8.3.0[CVE-2021-43798][CNNVD-202112-482] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃGrafana8.0.0-8.3.0°æ±¾Öб£´æµÄÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬£¬´Ó¶øÔÚδÊÚȨµÄÇéÐÎ϶ÁȡĿµÄϵͳÃô¸ÐÎļþ¡£¡£¡£¡£¡£GrafanaÊÇÒ»¸ö¿çƽ̨¡¢¿ªÔ´µÄÊý¾Ý¿ÉÊÓ»¯ÍøÂçÓ¦ÓóÌÐòƽ̨¡£¡£¡£¡£¡£Óû§ÉèÖÃÅþÁ¬µÄÊý¾ÝÔ´Ö®ºó£¬£¬£¬£¬£¬£¬Grafana¿ÉÒÔÔÚÍøÂçä¯ÀÀÆ÷ÀïÏÔʾÊý¾Ýͼ±íºÍÖÒÑÔ |
¸üÐÂʱ¼ä£º | 20230425 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_logging.config |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃActuatorµÄ/evn½Ó¿Úͨ¹ýlogging.config²ÎÊýʵÑéÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØÏµÍ³Êý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØÐí¶àÐí¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬£¬£¬£¬£¬£¬¿ÉÒÔÉó²éÓ¦ÓÃÉèÖõÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230425 |