ÿÖÜÉý¼¶Í¨¸æ-2021-10-12

Ðû²¼Ê±¼ä 2021-10-13

ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_À¶º£×¿Ô½¼Æ·Ñ¹ÜÀíϵͳ_debug.php_ÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

À¶º£×¿Ô½¼Æ·Ñ¹ÜÀíϵͳ/debug.php´æÔÚδÊÚȨ·ÃÎÊ£¬¸ÃÎļþÌṩһ¸öÃüÁîÖ´ÐеĽӿÚ£¬¹¥»÷¿Éͨ¹ýµ÷ÓøýӿÚʵÏÖÔ¶³ÌÃüÁîÖ´ÐС£

¸üÐÂʱ¼ä£º

20211012



ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Confluence/JIRA_ÈÎÒâÎļþ¶Áȡ©¶´[CVE-2021-26085/CVE-2021-26086][CNNVD-202108-1398]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

AtlassianConfluenceÊÇAtlassian¹«Ë¾³öÆ·µÄרҵµÄÆóҵ֪ʶ¹ÜÀíÓëЭͬÈí¼þ£¬¿ÉÓÃÓÚ¹¹½¨ÆóÒµÎÄ¿âµÈ¡£ConfluenceСÓÚ7.4.10£¬7.5.0~7.12.3°æ±¾£¬JiraСÓÚ8.5.14£¬8.6.0~8.13.6£¬8.14.0~8.16.1°æ±¾£¬¶¼´æÔÚÈÎÒâÎļþ¶Áȡ©¶´¡£¸Ã©¶´ÊÇÓÉÓÚ¶ÔÓû§µÄÊäÈëûÓнøÐÐÑϸñµÄ¹ýÂ˵¼Ö£¬¹¥»÷Õß¿ÉÀûÓø鶴ÔÚδÊÚȨµÄÇé¿öÏ£¬½á¹¹¶ñÒâÊý¾ÝÖ´ÐÐÎļþ¶ÁÈ¡¹¥»÷£¬×îÖÕÔì³É·þÎñÆ÷²¿ÃÅÎļþÐÅϢй¶¡£

¸üÐÂʱ¼ä£º

20211012


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½Â©¶´[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú½øÐÐĿ¼´©Ô½Â©¶´¹¥»÷ʵÑéµÄÐÐΪ¡£Ä¿Â¼´©Ô½Â©¶´ÄÜʹ¹¥»÷ÕßÈƹýWeb·þÎñÆ÷µÄ·ÃÎÊÏÞÖÆ£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬ÈÎÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬ÆäËû©¶´£¨ÉõÖÁһЩ0day©¶´£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´Ëʼþ±¨¾¯¡£ÓÉÓÚÕý³£ÒµÎñÖÐÒ»°ã²»»á·¢Éú´ËʼþÌØÕ÷µÄÁ÷Á¿£¬ËùÒÔÐèÒªÖصã¹Ø×¢¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß·ÃÎÊÃô¸ÐÎļþ¡£

¸üÐÂʱ¼ä£º

20211012