Ç徲ͨ¸æ
-
Ò»¡¢×ÛÊö2ÔÂ20ÈÕ£¬¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨CNVD£©Ðû²¼ÁËÒ»Ôò¹ØÓÚApache Tomcat±£´æÎļþ°üÀ¨Îó²îµÄÇ徲ͨ¸æ¡£Í¨¸æÖÐÌåÏÖ£¬±£´æÓÚApache TomcatÖеÄÎļþ°üÀ¨Îó²î£¨CNVD-2020-10487£¬¶ÔÓ¦CVE-2020-1938£©¿Éʹ¹¥»÷ÕßÔÚδÊÚȨµÄÇéÐÎÏÂÔ¶³Ì¶ÁÈ¡ÌØ¶¨Ä¿Â¼ÏµÄí§ÒâÎļþ¡£Îó²îÔ´ÓÚTomcat AJPÐÒéʵÏÖÖеÄȱÏÝ£¬Ê¹µÃÏà¹Ø²ÎÊý¿É¿Ø¡£Í¨¹ýÏòAJPÐÒé¶Ë¿Ú£¨Ä¬ÈÏ8009£©·¢ËÍÈ«ÐĽṹµÄÊý¾Ý£¬¿É¶ÁÈ¡·þÎñÆ÷webappĿ¼ÏµÄí§ÒâÎļþ£¬ºÃ±ÈÉèÖÃÎÄ
¸ü¶à -
Ò» Îó²î¸ÅÊö2ÔÂ20ÈÕ£¬¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨CNVD£©Ðû²¼ÁËApache TomcatÎļþ°üÀ¨Îó²î£¨CNVD-2020-10487 CVE-2020-1938£©¡£¸ÃÎó²îÊÇÓÉÓÚTomcat AJPÐÒé±£´æÈ±Ïݶøµ¼Ö£¬¹¥»÷ÕßʹÓøÃÎó²î¿Éͨ¹ý½á¹¹Ìض¨²ÎÊý£¬¶ÁÈ¡·þÎñÆ÷webappϵÄí§ÒâÎļþ¡£ÈôÄ¿µÄ·þÎñÆ÷ͬʱ±£´æÎļþÉÏ´«¹¦Ð§£¬¹¥»÷Õ߿ɽøÒ»²½ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£ÏÖÔÚ£¬³§ÉÌÒÑÐû²¼Ð°汾Íê³ÉÎó²îÐÞ¸´¡£TomcatÊÇApacheÈí¼þ»ù½ð»áÖеÄÒ»¸öÖ÷ÒªÏîÄ¿£¬ÐÔÄÜÎȹÌÇÒÃâ·Ñ£¬ÊÇÏÖÔÚ
¸ü¶à -
×ÛÊö¿ËÈÕ£¬jackson-databindа汾ÖÐÐÞ¸´ÁËÒ»¸öÓÉJNDI×¢Èëµ¼ÖµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2020-8840¡£ÊÜÓ°Ïì°æ±¾µÄ jackson-databind ÖÐÓÉÓÚȱÉÙijЩxbean-reflect JNDIºÚÃûµ¥À࣬Èçorg apache xbean propertyeditor JndiConverter£¬¿Éµ¼Ö¹¥»÷ÕßʹÓÃJNDI×¢ÈëµÄ·½·¨ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£²Î¿¼Á´½Ó£ºhttps: nvd nist gov vuln detail CVE-2020-8840ÊÜÓ°Ïì²úÆ·°æ±¾2 0 0 <= FasterXML jackson-databind Version <= 2 9 10 2²»ÊÜ
¸ü¶à -
Ò»¡¢ Íþвͨ¸æ? ΢Èí¸üжà¸ö²úÆ·¸ßΣÎó²î¡¾Ðû²¼Ê±¼ä¡¿2020-02-13 10:40:00 GMT¡¾¸ÅÊö¡¿±±¾©Ê±¼ä2ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼2ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË100¸öÇå¾²ÎÊÌâ£¬Éæ¼°InternetExplorer¡¢MicrosoftEdge¡¢MicrosoftExchangeServer¡¢MicrosoftOfficeµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨ÌáȨºÍÔ¶³Ì´úÂëÖ´ÐеȸßΣÎó²î¡£¡¾Á´½Ó¡¿http: blog nsfocus net microsoft-releases-multiple-announcement-for-critical-threats ? DjangoSQL×¢Èë©
¸ü¶à -
×ÛÊöÔÚÉÏÖÜÐû²¼µÄ΢ÈíÔ¶ȸüÐÂÖУ¬°üÀ¨Ò»¸ö±£´æÓÚSQL Server Reporting Services£¨SSRS£©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2020-0618¡£ÏÖÔÚÒѱ£´æÕë¶Ô¸ÃÎó²îµÄ PoC£¬ÇëÏà¹ØÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤¡£SQL Server Reporting Services (SSRS)ÊÇ΢Èí»ùÓÚ·þÎñÆ÷µÄ±¨±íÌìÉúÈí¼þ£¬ËüÊÇMicrosoft SQL Server·þÎñÌ×¼þµÄÒ»²¿·Ö£¬Í¨¹ýWeb½çÃæ¾ÙÐÐÖÎÀí£¬¿ÉÓÃÓÚ×¼±¸ºÍ½»¸¶ÖÖÖÖ½»»¥Ê½±¨¸æ¡£SSRSÓ¦ÓÃÖеĹ¦Ð§ÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÏòÊÜÓ°
¸ü¶à -
×ÛÊö¿ËÈÕ£¬ChekmarxÍŶӵÄÑо¿Ö°Ô±·¢Ã÷²¢Ðû²¼ÁËApache DubboÖб£´æµÄÒ»¸ö·´ÐòÁл¯Îó²î£¨CVE-2019-17564£©¡£Apache Dubbo ÊÇÒ»¿î¸ßÐÔÄÜJava RPC¿ò¼Ü¡£µ±ÔÚDubboÓ¦ÓÃÖÐÆôÓÃÁËHTTPÐÒé¾ÙÐÐͨѶʱ±£´æ¸ÃÎó²î£¬¹¥»÷Õß¿ÉÄÜÌá½»Ò»¸ö°üÀ¨Java¹¤¾ßµÄPOSTÇëÇóÀ´ÍêÈ«ÆÆËðApache DubboµÄÌṩÕßʵÀý¡£Dubbo HTTPʵÀý»áÈ¥·´ÐòÁл¯JavaObjectStreamÖеÄÊý¾Ý£¬ÈôÊÇÊý¾ÝÖаüÀ¨Ò»×é¶ñÒâÀ࣬ÓÉÓÚûÓÐ×öÈκÎÇå¾²¹ýÂ˺ͼì²é,ÄÇô·´ÐòÁл¯½«»áµ¼
¸ü¶à








