ÿÖÜÉý¼¶²¼¸æ-2023-03-07
°ä²¼¹¦·ò 2023-03-07ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_ȨÏÞÈÆ¹ý_Apache_Shiro_v1.5.3ÒÔÏÂ[CVE-2020-11989][CNNVD-202006-1556] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ApacheShiroÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬£¬£¬ËüÄܹ»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£Ä¿Ç°³£¼û¼¯³ÉÓÚ¸÷ÀàÀûÓÃÖнøÐÐÉí·ÝÑéÖ¤£¬£¬£¬ÊÚȨµÈ¡£¶ÔÓÚApacheShiro1.5.3֮ǰµÄ°æ±¾£¬£¬£¬µ±½«ApacheShiroÓëSpring½ÚÖÆÆ÷һ·ʹÓÃʱ£¬£¬£¬¹¥»÷ÕßÌØÖÆÒªÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£ |
¸üй¦·ò£º£º | 20230307 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Apache_Log4j2_jndi×¢ÈëǶÌ×lookupÈÆ¹ý[CVE-2021-44228] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ApacheLog4j2ÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãlog4j2×é¼þÖ§³ÖµÄÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬£¬£¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬£¬£¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬£¬´ËÐÐΪӵÓнϸ߷çÏÕ£¬£¬£¬ÈÝÒ×±»¹¥»÷ÕßÀÄÓ㬣¬£¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬£¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓ㬣¬£¬´Ó¶øÖ´ÐжñÒâ´úÂë»òºÅÁî¡£log4j22.15.0-RC1Ö®ºóµÄ°æ±¾Ä¬ÈϹرÕÁËʹÓôËÊÖ·¨Å²ÓÃjndiŲÓõÄÖ°ÄÜ£¬£¬£¬²¢ÏÞ¶ÈÁ˰×Ãûµ¥£¬£¬£¬¹ÊʹÓÃδ¾Ï޶ȵÄÀϰ汾log4j2×é¼þ¿ÉÄÜ»á´æÔÚjndi×¢ÈëµÄ·çÏÕ¡£ |
¸üй¦·ò£º£º | 20230307 |
ÊÂÎñÃû³Æ£º£º | TCP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Apache_Log4j2_jndi×¢ÈëǶÌ×lookupÈÆ¹ý[CVE-2021-44228] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬£¬£¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬£¬£¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬£¬´ËÐÐΪӵÓп϶¨·çÏÕ£¬£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬£¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬£¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓᣠ|
¸üй¦·ò£º£º | 20230307 |


¾©¹«Íø°²±¸11010802024551ºÅ