ÿÖÜÉý¼¶²¼¸æ-2023-04-25
°ä²¼¹¦·ò 2023-04-25ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º£º | HTTP_·´ÐòÁл¯_Spring_Boot_Actuator_Snakeyaml_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.cloud.bootstrap.locationÉèÖÃΪ¶ñÒâyamlÎļþURLµØÖ·¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_Spring_Boot_logging.config_logback_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«logging.configÉèÖÃΪ¶ñÒâxmlÎļþµØÖ·¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_ÎļþÔ̺¬_spring-boot-actuator-logview[CVE-2021-21234][CNNVD-202101-261] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃspring-boot-actuator-logviewÎļþÔ̺¬·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¡£spring-boot-actuator-logviewÊÇÒ»¸öµ¥Ò»µÄÈÕÖ¾Îļþ²é¿´Æ÷×÷ΪSpringBootÖ´ÐÐÆ÷¶Ëµã£¬£¬£¬ÔÚ0.2.12¼°Ö®Ç°°æ±¾ÖдæÔÚ×ÅÎļþÔ̺¬·ì϶£¬£¬£¬±àºÅCVE-2021-21234¡£¡£·ì϶ÐÔÖÊÊÇSpringBootÖ´ÐÐÆ÷ͨ¹ýÒªÇóµÄ²ÎÊýÀ´Ö¸¶¨ÎļþÃûºÍÎļþ¼Ðõè¾¶£¬£¬£¬¾¹ý×éºÏÆ´½Ó´ïµ½Ä¿Â¼±éÀú£¬£¬£¬¹ÌȻԴÂëÖвé³ÁËÎļþÃû£¨filename£©²ÎÊýÀ´Ô¤·ÀĿ¼±éÀú£¬£¬£¬µ«ÊÇûÓвé³Îļþ¼Ð£¨base£©²ÎÊý£¬£¬£¬Ôì³ÉÁ˹¥»÷ÕßÄܹ»½øÐÐĿ¼±éÀú¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | DNS_ľÂíºóÃÅ_AgentTesla_C2ÓòÃû½âÎöÒªÇó |
°²È«ÀàÐÍ£º£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½ÊÔͼҪÇó½âÎöAgentTeslaµÄC2ÓòÃû¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAgentTesla Keylogger¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_ÌáȨ¹¥»÷_CommonsConfiguration_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÖ÷ÕÅÖ÷»úsnakeyaml CommonsConfiguration jndi×¢Èë·ì϶¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | DNS_ºÅÁî½ÚÖÆ_ľÂíºóÃÅ_SalityϰȾÐͲ¡¶¾_ÓòÃû½âÎöÒªÇó |
°²È«ÀàÐÍ£º£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´Ö÷»úÕýÔÚ³¢ÊÔ½âÎö SalityϰȾÐͲ¡¶¾ µÄ¶ñÒâÓòÃû£¬£¬£¬Ô´Ö÷»ú¿ÉÄÜÒѾ±»Ö²Èë SalityϰȾÐͲ¡¶¾¡£¡£Sality ¿ÉÄÜÔÚWindows²Ù×÷ϵͳµÄÍÆËã»úÉϽøÐÐ×ÔÎÒ¸´Öƺʹ«²¼£¬£¬£¬Í¬Ê±»¹¿ÉÄܽøÐÐÔ¶³Ì½ÚÖÆºÍÐÅÏ¢ÇÔÈ¡¡£¡£Sality²¡¶¾µÄ´«²¼·½Ê½¼«¶È½Ã½Ý£¬£¬£¬Äܹ»Í¨¹ý¸÷À෽ʽ½øÐд«²¼£¬£¬£¬ÀýÈçÀûÓÿÉÒÆ¶¯É豸¡¢¡¢Í¨¹ýÎļþ¹²ÏíÈí¼þ¡¢¡¢µç×ÓÓʼþµÈ·½Ê½¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_ºÅÁîÓë½ÚÖÆ_Ô¶¿ØºóÃÅ_FiveSys_ÏνÓC2·þÎñÆ÷ |
°²È«ÀàÐÍ£º£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½FiveSysľÂíºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£FiveSysľÂíÖØÒªÖ°ÄÜÊǽ«Ê¹ÓÃÕßÁ÷Á¿µ¼Òýµ½Ìض¨¶ñÒâ´úÀí·þÎñÆ÷£»£»£»FiveSysÖ÷ÕÅÊÇÔÚÓû§ÏνÓÏßÉÏÓÎϷʱ£¬£¬£¬½«Óû§Á÷Á¿µ¼Ïò´úÀí·þÎñÆ÷ʱ£¬£¬£¬½è´ËÀ¹½Ø¡¢¡¢ÇÔÈ¡Óû§ÕÊÃܵÈÑéÖ¤ÐÅÏ¢¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_ÎļþÏÂÔØ_RuoYiºó¶ÜÖÎÀíϵͳ[CVE-2023-27025][CNNVD-202304-021] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | RuoyiÔÚv4.7.6¼°ÒÔϰ汾ÖдæÔÚËÁÒâÎļþÏÂÔØ·ì϶£¬£¬£¬¾¹ýÉí·ÝÈÏÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓð´Ê±¹¤×÷ÏÂÔØËÁÒâÎļþ¡£¡£ÈôÊÇϵͳδ¶Ô¶ÁÈ¡/ÏÂÔØÎļþµÄÎļþĿ¼×öÏÞ¶È£¬£¬£¬¹¥»÷ÕßÀûÓô˷ì϶¿ÉÖ±½Ó¶ÁÈ¡webĿ¼ÏÂËÁÒâÎļþ£¬£¬£¬ºÃ±ÈÅäÖÃÎļþ¡¢¡¢Êý¾Ý¿âÎļþµÈ£¬£¬£¬ÉõÖÁÖ±½Ó»ñÈ¡·þÎñÆ÷ÉÏËÁÒâÎļþÄÚÈÝ¡£¡£Ruoyiºó¶ÜÖÎÀíϵͳÊÇ»ùÓÚSpringBootµÄȨÏÞÖÎÀíϵͳ¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_ÌáȨ¹¥»÷_JndiRefForwardingDataSource_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÖ÷ÕÅÖ÷»úsnakeyaml JndiRefForwardingDataSource jndi×¢Èë·ì϶¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_Spring_Boot_spring.main.sources_groovy_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.main.sourcesÉèÖÃΪ¶ñÒâgroovyÎļþµØÖ·¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_Spring_Boot_Actuator_datasource_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.datasource.dataÊôÐÔÉèÖÃΪ¶ñÒâsqlÎļþµÄURLµØÖ·¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_·´ÐòÁл¯_SnakeYaml_MarshalOutputStream_ËÁÒâÎļþдÈë |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÖ÷ÕÅÖ÷»úsnakeyaml MarshalOutputStream ÎļþдÈë·ì϶¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_ÓÃÓÑNC_uapjs_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃÓÃÓÑNC6.5ÖÐjsinvoke½Ó¿Ú´æÔÚµÄËÁÒâ²½ÖèŲÓ÷ì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_ÎļþÏÂÔØ_ÁéͨOA_video_file.php |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ÀûÓÃMEDIA_DIRÓëMEDIA_NAME²ÎÊýÖµ¸²¸Ç½øÐÐõè¾¶´©Ô½²¢Ñ¡È¡httpµÄÏìÓ¦Content-DispositionÍ·×Ö¶ÎʵÏÖËÁÒâÎļþµÄÏÂÔØ¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_ÌáȨ¹¥»÷_PostgreSQL-JDBC-Driver_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-21724] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | PostgreSQLÊý¾Ý¿âµÄjdbcÇý¶¯·¨Ê½ÖдæÔÚÒ»¸ö°²È«·ì϶¡£¡£µ±¹¥»÷Õß½ÚÖÆjdbcurl»òÕßÊôÐÔʱ£¬£¬£¬Ê¹ÓÃPostgreSQLÊý¾Ý¿âµÄϵͳ½«Êܵ½¹¥»÷¡£¡£pgjdbcƾ¾Ýͨ¹ýauthenticationPluginClassName¡¢¡¢sslhostnameverifier¡¢¡¢socketFactory¡¢¡¢sslfactory¡¢¡¢sslpasswordcallbackÏνÓÊôÐÔÌṩÀàÃûʵÀý»¯²å¼þʵÀý¡£¡£µ«ÊÇ£¬£¬£¬Çý¶¯·¨Ê½ÔÚʵÀý»¯Àà֮ǰûÓÐÑéÖ¤ÀàÊÇ·ñʵÏÖÁËÔ¤ÆÚµÄ½Ó¿Ú¡£¡£Õâ¿ÉÄܵ¼ÖÂͨ¹ýËÁÒâÀà¼ÓÔØÔ¶³Ì´úÂëÖ´ÐлòÎļþдÈë¹¥»÷¡£¡£Ó°Ïì°æ±¾£º£ºpostgresql_jdbc_driver<42.2.25£¬£¬£¬42.3.0<=postgresql_jdbc_driver<=42.3.1 |
¸üй¦·ò£º£º | 20230425 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º£º | HTTP_ÌáȨ¹¥»÷_ScriptEngineManager_SnakeYAML·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃSnakeYAMLScriptEngineManager·´ÐòÁл¯ÀûÓÃÁ´½øÐй¥»÷£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£SnakeYamlÊÇJavaÓÃÓÚ½âÎöYaml£¨YetAnotherMarkupLanguage£©ÌåʽÊý¾ÝµÄÀà¿â£¬£¬£¬ËüÌṩÁËdump²½ÖèÄܹ»½«Ò»¸öJava¶ÔÏóתΪYamlÌåʽ×Ö·û´®,Æäload²½ÖèÒ²¿ÉÄܽ«Yaml×Ö·û´®×ªÎªJava¶ÔÏ󡣡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_H2database_console |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndi·þÎñÆ÷µØÖ·¡£¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ£¬£¬£¬Ñ¡È¡java˵»°±àд£¬£¬£¬²»ÊÜÆ½Ì¨µÄÏÞ¶È£¬£¬£¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸ö¼«¶È·½±ãµÄweb½ÚÖÆÌ¨ÓÃÓÚ²Ù×÷ºÍÖÎÀíÊý¾Ý¿âÄÚÈÝ¡£¡£H2Database»¹Ìṩ¼æÈÝģʽ£¬£¬£¬Äܹ»¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â£¬£¬£¬Òò¶øÑ¡È¡H2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿â¼«¶È·½±ã¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | TCP_ÌáȨ¹¥»÷_Groovy1_Java·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃGroovy1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£ApacheGroovyÊÇÒ»¸öÖ°ÄÜ׳´óµÄ¶¯Ì¬±à³Ì˵»°£¬£¬£¬¿¿×ÅÆä¼ò½à¡¢¡¢ÓëJava¼«¶ÈÀàËÆÒÔ¼°Ò×ÓÚѧϰµÄÓï·¨£¬£¬£¬»ùÓÚJavaƽ̨µÄGroovy¹Ø×¢ÓÚÌá¸ß¿ª·¢Õߵijö²úÐÔ¡£¡£ËüÄܹ»ºÍÈκÎJava˵»°½øÐÐÎ޷켯³É£¬£¬£¬Ö§³ÖDSL£¬£¬£¬ÌṩÔËÐн׶κͱàÒë½×¶ÎÔªÊý¾Ý±à³ÌµÈ׳´óµÄÖ°ÄÜ¡£¡£ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_Îļþ¶ÁÈ¡_Grafana_8.3.0[CVE-2021-43798][CNNVD-202112-482] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃGrafana8.0.0-8.3.0°æ±¾ÖдæÔÚµÄÎļþ¶ÁÈ¡·ì϶£¬£¬£¬´Ó¶øÔÚδÊÚȨµÄÇé¿ö϶Áȡָ±êϵͳÃô¸ÐÎļþ¡£¡£GrafanaÊÇÒ»¸ö¿çƽ̨¡¢¡¢¿ªÔ´µÄÊý¾Ý¿ÉÊÓ»¯ÍøÂçÀûÓ÷¨Ê½Æ½Ì¨¡£¡£Óû§ÅäÖÃÏνӵÄÊý¾ÝÔ´Ö®ºó£¬£¬£¬GrafanaÄܹ»ÔÚÍøÂçä¯ÀÀÆ÷ÀïÏÔʾÊý¾Ýͼ±íºÍÖÒ¸æ |
¸üй¦·ò£º£º | 20230425 |
ÊÂÎñÃû³Æ£º£º | HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_logging.config |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/evn½Ó¿Úͨ¹ýlogging.config²ÎÊý³¢ÊÔÔ¶³Ì´úÂëÖ´ÐС£¡£SpringBootActuatorÊÇÒ»¿îÄܹ»Ô®ÊÖÄã¼à¿ØÏµÍ³Êý¾ÝµÄ¿ò¼Ü,ÆäÄܹ»¼à¿ØºÃ¶àºÃ¶àµÄϵͳÊý¾Ý,ËüÓжÔÀûÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯³É¹¦ÄÜ£¬£¬£¬Äܹ»²é¿´ÀûÓÃÅäÖõľßÌåÐÅÏ¢¡£¡£ |
¸üй¦·ò£º£º | 20230425 |


¾©¹«Íø°²±¸11010802024551ºÅ