ÿÖÜÉý¼¶Í¨¸æ-2022-10-25
Ðû²¼Ê±¼ä 2022-10-25ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_PropertyPathFactoryBean_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃSnakeYAMLµÄPropertyPathFactoryBean·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_DefaultBeanFactoryPointcutAdvisor_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃSnakeYAMLµÄDefaultBeanFactoryPointcutAdvisor·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_CommonsConfiguration_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃSnakeYAMLµÄCommonsConfiguration·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Grafana_8.3.0_Îļþ¶ÁÈ¡[CVE-2021-43798][CNNVD-202112-482] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃGrafana8.0.0-8.3.0°æ±¾ÖдæÔÚµÄÎļþ¶Áȡ©¶´£¬´Ó¶øÔÚδÊÚȨµÄÇé¿ö϶ÁÈ¡Ä¿±êϵͳÃô¸ÐÎļþ¡£GrafanaÊÇÒ»¸ö¿çƽ̨¡¢¿ªÔ´µÄÊý¾Ý¿ÉÊÓ»¯ÍøÂçÓ¦Ó÷¨Ê½Æ½Ì¨¡£Óû§ÅäÖÃÁ¬½ÓµÄÊý¾ÝÔ´Ö®ºó£¬Grafana¿ÉÒÔÔÚÍøÂçä¯ÀÀÆ÷ÀïÏÔʾÊý¾Ýͼ±íºÍ¾¯¸æ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_HTTP_ɨÃè |
Äþ¾²ÀàÐÍ£º | Äþ¾²É¨Ãè |
ʼþÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓöÔÄ¿µÄÖ÷»úÊÔͼͨ¹ýNMAP»ñÈ¡¶ÔÓ¦Ö÷»úhttp·þÎñÆ÷°æ±¾ºÍ¶ÔÓ¦³§É̵ÄÐÐΪ¡£Õâ¿ÉÄܻᵼÖÂϵͳй¶Ïà¹ØÐÅÏ¢¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_FortiOS_7.2.1_ȨÏÞÈƹý[CVE-2022-40684][CNNVD-202210-347] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃFortiOS7.2.1¼°ÒÔÏ°汾£¬FortiProxy7.2.0¼°ÒÔÏ°汾£¬FortiSwitchManager7.2.0¼°ÒÔÏ°汾ÖдæÔÚµÄȨÏÞÈƹý©¶´£¬ÔÚδÊÚȨµÄÇé¿öÏÂÐÞ¸ÄÓû§µÄssh¹«Ô¿£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_©¶´ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆƽâÀûÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐЩ¶´½øÐÐÀûÓÃÁ´±©Æƹ¥»÷¡£ApacheShiro£¨Â©¶´°æ±¾<=1.2.4£©ÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí |
¸üÐÂʱ¼ä£º | 20221025 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Struts2_S2-032_´úÂëÖ´ÐÐ[CVE-2016-3081] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃStruts2.3.20-StrutsStruts2.3.28(2.3.20.3ºÍ2.3.24.3³ýÍâ)ÖдæÔڵĴúÂëÖ´ÐЩ¶´£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£Struts2ÊÇÒ»¸ö¼ò½àµÄ¡¢¿ÉÀ©Õ¹µÄ¿ò¼Ü£¬¿ÉÓÃÓÚ´´½¨ÆóÒµ¼¶JavawebÓ¦Ó÷¨Ê½¡£Éè¼ÆÕâ¸ö¿ò¼ÜÊÇΪÁË´Ó¹¹½¨¡¢²¿Êð¡¢µ½Ó¦Ó÷¨Ê½Î¬»¤·½ÃæÀ´¼ò»¯Õû¸ö¿ª·¢ÖÜÆÚ¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_Weblogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2801] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃOracleWeblogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯Â©¶´£¬Ê¹ÓÃt3ÐÒé·¢ËͶñÒâµÄÐòÁл¯Êý¾Ý£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£WeblogicÊÇÄ¿Ç°È«ÇòÊг¡ÉÏÓ¦ÓÃ×î¹ã·ºµÄJ2EE¹¤¾ßÖ®Ò»£¬±»³ÆΪҵ½ç×î¼ÑµÄÓ¦Ó÷¨Ê½·þÎñÆ÷£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦Ó÷¨Ê½£¬Ö§³Öй¦Ð§£¬¿É½µµÍÔËÓª³É±¾£¬Ìá¸ßÐÔÄÜ£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÎï×éºÏ¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ÓÃÓÑNC6.5_XbrlPersistenceServlet_·´ÐòÁл¯_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÔÐÐΪ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃÓÃÓÑNC6.5ÖÐXbrlPersistenceServlet½Ó¿Ú´æÔڵķ´ÐòÁл¯Â©¶´£¬Ê¹ÓÃURLDNSÀûÓÃÁ´Ì½²â¸Ã©¶´ÊÇ·ñ´æÔÚ¡£ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö·½°¸¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄ¹ÜÀíÒµÎñÀíÄî¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍŹÜÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-36189¡¢CVE-2020-36188¡¢CVE-2019-14439¡¢CVE-2019-14361] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¹¥»÷Õß¿ÉÄÜÀûÓÃjacksonµÄ¿ÉÒÉ·´ÐòÁл¯Ààlogback¹¥»÷Ä¿µÄIPÖ÷»ú¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2883] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃWebLogicServer10.3.6.0.0£¬12.1.3.0.0£¬12.2.1.3.0£¬12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯Â©¶´£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳµÄȨÏÞ¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplicationserver£¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖмä¼þ£¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍ¹ÜÀí´óÐÍÂþÑÜʽWebÓ¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦ÓõÄJavaÓ¦Ó÷þÎñÆ÷¡£½«JavaµÄ¶¯Ì¬¹¦Ð§ºÍJavaEnterprise³ß¶ÈµÄÄþ¾²ÐÔÒýÈë´óÐÍÍøÂçÓ¦ÓõĿª·¢¡¢¼¯³É¡¢²¿ÊðºÍ¹ÜÀíÖ®ÖС£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-8840][CNNVD-202002-354] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£´Ë©¶´Öй¥»÷Õß¿ÉÀûÓÃxbean-reflectµÄÀûÓÃÁ´´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ´Ó¶øµ½´ïÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Zabbix_СÓÚ4.4_δÊÚȨ·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃZabbixСÓÚ4.4°æ±¾ÖдæÔÚµÄΪδÊÚȨ·ÃÎÊ©¶´£¬´Ó¶øÔÚδ¾ÊÚȨµÄÇé¿öÏ·ÃÎÊZabbix·þÎñÆ÷ÉϵÄÊý¾Ý£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Struts2_S2-055_REST_JacksonLibrary_´úÂëÖ´ÐÐ[CVE-2017-7525] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | Tomcat·þÎñÆ÷ÊÇÒ»¸öÃâ·ÑµÄ¿ª·ÅÔ´´úÂëµÄWebÓ¦Ó÷þÎñÆ÷¡£Struts2ÊÇApacheÈí¼þ»ù½ð»áÂôÁ¦Î¬»¤µÄÒ»¿îÓÃÓÚ´´½¨ÆóÒµ¼¶JavaWebÓ¦ÓõĿªÔ´¿ò¼Ü¡£Struts2ÔÚv2.5-v2.5.14£¬¹¥»÷Õßͨ¹ýµ÷ÓÃREST²å¼þÖеĴæÔÚ·´ÐòÁл¯Â©¶´µÄJacksonLibraryÀ´´¦ÖÃJSONÊý¾Ý£¬´Ó¶ø´¥·¢·´ÐòÁл¯Â©¶´¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÐÅϢй¶_PACSOne_Server_6.6.2_DICOM_Web_Viewer_Ŀ¼±éÀú |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýPACSOneServerÖдæÔÚµÄĿ¼±éÀú©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúnocache.php½Å±¾µÄ¡®path¡¯²ÎÊýÖеġ®..¡¯×Ö·ûÀûÓø鶴¶ÁÈ¡ÈÎÒâÎļþ¡£¹¥»÷Õß¿ÉÀûÓø鶴»ñÈ¡Ãô¸ÐÐÅÏ¢ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_ͨ´ïOA_print.php_Îļþɾ³ý |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃͨ´ïOAµÄV11.6¼°ÒÔÇ°µÄ°æ±¾´æÔÚµÄÎļþɾ³ý©¶´½øÐй¥»÷¡£Í¨´ïOAÊÇOfficeAnywhereµÄ¼ò³Æ£¬¸Ãϵͳ½ÓÄÉÁìÏȵÄB/S(ä¯ÀÀÆ÷/·þÎñÆ÷)²Ù×÷·½Ê½£¬Ê¹µÃÍøÂç°ì¹«²»ÊܵØÓòÏÞ¡£OfficeAnywhere½ÓÄÉ»ùÓÚWEBµÄÆóÒµ¼ÆË㣬Ö÷HTTP·þÎñÆ÷½ÓÄÉÁËÊÀ½çÉÏ×îÏȽøµÄApache·þÎñÆ÷£¬ÐÔÄÜÎȶ¨¿É¿¿¡£Êý¾Ý´æÈ¡¼¯ÖпØÖÆ£¬ÖÆÖ¹ÁËÊý¾Ýй©µÄ¿ÉÄÜ¡£ÌṩÊý¾Ý±¸·Ý¹¤¾ß£¬±£»¤ÏµÍ³Êý¾ÝÄþ¾²¡£¶à¼¶µÄȨÏÞ¿ØÖÆ£¬ÍêÉƵÄÃÜÂëÑéÖ¤ÓëµÇ¼ÑéÖ¤»úÖÆÔ½·¢Ç¿ÁËϵͳÄþ¾²ÐÔ¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14645][CVE-2020-14625][CVE-2020-14644][CVE-2020-14687] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃOracleWebLogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯Â©¶´£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÆäËü¿ÉÒÉÐÐΪ_PHPαÐÒé |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃPHPµÄһЩ·â×°ÐÒ飬Èçphp://input,php://filterµÈÌá½»Ò»¾ä»°Ä¾Âí£¬»òÔ¶³ÌÖ´ÐÐÃüÁîÀ´¹¥»÷Êܺ¦Õß·þÎñÆ÷£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-1000353] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃJenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾ÖдæÔڵķ´ÐòÁл¯Â©¶´½øÐй¥»÷£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£JenkinsÊÇÒ»¸ö¿ÉÀ©Õ¹µÄ¿ªÔ´Á¬Ðø¼¯³É·þÎñÆ÷£¬ÔںܶàÆóÒµµÄÄÚÍøÖж¼²¿ÊðÁËÕâ¸öϵͳ¡£Jenkins2.56¼°Ö®Ç°µÄ°æ±¾ºÍ2.46.1LTS¼°Ö®Ç°µÄ°æ±¾ÖдæÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòJenkinsCLIͨ±¨ÐòÁл¯µÄJava¡®SignedObject¡¯¹¤¾ßÀûÓø鶴Èƹý»ùÓÚºÚÃûµ¥µÄ±£»¤»úÖÆ¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jenkins·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2015-8103] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃJenkins1.637¼°Ö®Ç°°æ±¾¡¢JenkinsLTS1.625.1¼°Ö®Ç°°æ±¾´æÔڵķ´ÐòÁл¯Â©¶´½øÐдúÂëÖ´Ðй¥»÷£¬´Ó¶ø»ñÈ¡Ä¿±êÖ÷»úȨÏÞ¡£JenkinsÊÇÒ»¸ö¿ÉÀ©Õ¹µÄ¿ªÔ´Á¬Ðø¼¯³É·þÎñÆ÷¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JBossMQ_JMS·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-7504][CNNVD-201705-937] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | RedHatJBossApplicationServerÊÇÒ»¿î»ùÓÚJavaEEµÄ¿ªÔ´Ó¦Ó÷þÎñÆ÷¡£JBossAS4.x¼°Ö®Ç°°æ±¾ÖУ¬JbossMQʵÏÖ¹ý³ÌµÄJMSoverHTTPInvocationLayerµÄHTTPServerILServlet.javaÎļþ´æÔÚ·´ÐòÁл¯Â©¶´£¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖƵÄÐòÁл¯Êý¾ÝÀûÓø鶴ִÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JACKSON-databind_2670_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-11113][CNNVD-202003-1735] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´ÏòÄ¿µÄip½øÐз´ÐòÁл¯¹¥»÷£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_InfluxDB_δÊÚȨ·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | influxdbÊÇÒ»¿îÖøÃûµÄʱÐòÊý¾Ý¿â£¬ÆäʹÓÃjwt×÷Ϊ¼øȨ·½Ê½¡£ÔÚÓû§¿ªÆôÁËÈÏÖ¤£¬µ«Î´ÉèÖòÎÊýshared-secretµÄÇé¿öÏ£¬jwtµÄÈÏÖ¤ÃÜԿΪ¿Õ×Ö·û´®£¬´Ëʱ¹¥»÷Õß¿ÉÒÔαÔìÈÎÒâÓû§Éí·ÝÔÚinfluxdbÖÐÖ´ÐÐSQLÓï¾ä¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_IncomCMS_2.0_ÎļþÉÏ´«[CVE-2020-29597][CNNVD-202012-431] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | IncomCMS2.0ÒÔ¼°Ö®Ç°µÄ°æ±¾´æÔÚÎļþÉÏ´«Â©¶´£¬¹¥»÷Õß¿ÉÒÔÉÏ´«webshell»ñÈ¡Ä¿±êϵͳȨÏÞ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Docker_Remote_API_δÊÚȨ·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃDockerRemoteAPIÅäÖò»Í×ʱµ¼ÖµÄδÊÚȨ·ÃÎÊ©¶´dockerclient»òÕßhttpÖ±½ÓÇëÇó·ÃÎÊÕâ¸öAPI£¬´Ó¶øÖ±½Ó·ÃÎÊËÞÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢£¬»ò¶ÔÃô¸ÐÎļþ½øÐÐÐ޸ģ¬×îÖÕÍêÈ«¿ØÖÆ·þÎñÆ÷¡£DockerRemoteAPIÊÇÒ»¸öÈ¡´úÔ¶³ÌÃüÁîÐнçÃ棨rcli£©µÄRESTAPI¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ShiroAttack¹¤¾ßʹÓÃ_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐЩ¶´½øÐй¥»÷¡£ApacheShiro£¨Â©¶´°æ±¾<=1.2.4£©ÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÃüÁî×¢Èë |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÃüÁî×¢È멶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬exportovpn½Ó¿Ú´æÔÚÃüÁî×¢È룬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_©¶´ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ_ÄÚ´æÂí×¢Èë_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐЩ¶´½øÐÐÀûÓ㬲¢ÔÚÇëÇóÌ崦עÈëÄÚ´æÂí¡£ApacheShiro£¨Â©¶´°æ±¾<=1.2.4£©ÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí |
¸üÐÂʱ¼ä£º | 20221025 |
ʼþÃû³Æ£º | TCP_©¶´ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆƽâÀûÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö: | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃShiroAttack¹¤¾ß¶ÔÄ¿µÄÖ÷»úÉϵÄApachShiroµÄRememberme´¦Ô¶³Ì´úÂëÖ´ÐЩ¶´½øÐÐÀûÓÃÁ´±©Æƹ¥»÷¡£ApacheShiro£¨Â©¶´°æ±¾<=1.2.4£©ÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí |
¸üÐÂʱ¼ä£º | 20221025 |