ÿÖÜÉý¼¶Í¨¸æ-2022-03-01

Ðû²¼Ê±¼ä 2022-03-01

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

UDP_Çå¾²Îó²î_Realtek_sdk_udp·þÎñÔ¶³ÌÏÂÁîÖ´ÐÐ[CVE-2021-35394]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃRealtekSdkʹÓÃudp·þÎñ½á¹¹¶ñÒâÏÂÁî¹¥»÷Ä¿µÄIP×°±¸¡£Ì¨ÍåоƬÉè¼ÆÉÌRealtekÖÒÑÔÆäWiFiÄ£¿é¸½´øµÄÈý¸öÈí¼þ¿ª·¢¹¤¾ß°ü(SDK)Öб£´æËĸöÇå¾²Îó²î£¬ÕâЩÈí¼þ¿ª·¢¹¤¾ß°üÓÃÓÚÖÁÉÙ65¼Ò¹©Ó¦ÉÌÉú²úµÄ½ü200¿îÎïÁªÍø×°±¸¡£RealtekJungleSDK°æ±¾v2.xÖÁv3.4.14BÌṩÁËÒ»¸öHTTPWeb·þÎñÆ÷£¬¹ûÕæÁËÒ»¸öÖÎÀí½Ó¿Ú£¬¿ÉÓÃÓÚÉèÖýÓÈëµã¡£Õâ¸öÖÎÀí½çÃæÓÐÁ½¸ö°æ±¾£ºÒ»¸ö»ùÓÚÃûΪwebsµÄGo-Ahead£¬ÁíÒ»¸ö»ùÓÚÃûΪboaµÄBoa¡£ËüÃǶ¼Êܵ½ÕâЩÎó²îµÄÓ°Ïì¡£

¸üÐÂʱ¼ä£º

20220301

 

ÊÂÎñÃû³Æ£º

TCP_Éó¼ÆÊÂÎñ_JAVA_RMIÇëÇóŲÓÃ

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐRMIÇëÇó¡£RMI¼´Ô¶³ÌÒªÁìŲÓÃ(RemoteMethodInvocation)£¬Ò»ÖÖÓÃÓÚʵÏÖÔ¶³ÌÀú³ÌŲÓõÄJavaAPI¡£ÈôÔ´IPÖ÷»ú±£´æJAVA·´ÐòÁл¯Îó²î£¬¹¥»÷Õß¿ÉʹÓÃJNDIÀ´Å²ÓÃRMI£¬¿ÉÄܱ£´æÔ¶³Ì»á¼û¶ñÒ⹤¾ßµÄΣº¦¡£

¸üÐÂʱ¼ä£º

20220301

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP_RoonServer_ÏÂÁî×¢Èë[CVE-2021-28811]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÍþÁªÍ¨¿Æ¼¼£¬¼ò³ÆÍþÁªÍ¨£¬Ó¢ÓïÒëÃûôßÆ·ÅÆÃû³ÆΪQNAP£¬ÊÇ×ܲ¿Î»ÓÚÖйų́ÍåµÄ¿Æ¼¼¹«Ë¾¡£Æä²úÆ·°üÀ¨ÍøÂ總¼Ó´æ´¢×°±¸¡¢ÊÓƵ¼à¿Ø¼Ïñ×°±¸¡¢ÍøÂç½»Á÷»ú¡¢ÎÞÏß·ÓÉÆ÷¡¢ÎÞÏß/ÓÐÏßÍø¿¨ºÍÊÓƵ¾Û»á×°±¸µÈ¡£ÍþÁªÍ¨£¨QNAP£©²úÆ·µÄRoonServerÓ¦ÓÃÖУ¬±£´æȨÏÞÈÏÖ¤Îó²îÓëÏÂÁî×¢ÈëÎó²î£¬¹¥»÷Õß¿ÉÒÔ½«Õâ2¸öÎó²î×éºÏÆðÀ´Ê¹Óã¬ÒÔµÖ´ïδÊÚȨԶ³ÌÖ´ÐÐí§ÒâÏÂÁîµÄÄ¿µÄ¡£

¸üÐÂʱ¼ä£º

20220301

 

ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_BADNEWS_PatchWorkAPT_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÐÎò£º

¼ì²âµ½patchworkºóÃÅBADNEWSľÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBADNEWSľÂí¡£BADNEWSľÂíÊÇÒ»¸ö¹¦Ð§ºÜÊÇÇ¿Ê¢µÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20220301

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Gerapy_clone_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2021-32849][CNNVD-202201-2495]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

GerapyÊÇÒ»¿î»ùÓÚScrapy¡¢Scrapyd¡¢DjangoºÍVue.jsµÄÂþÑÜʽÅÀ³æÖÎÀí¿ò¼Ü¡£Gerapy0.9.6ºÍ֮ǰµÄ°æ±¾Öб£´æ×¢ÈëÎó²î£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷÕûÀíͨ¹ýproject_clone¶Ëµãת´ï¸øPopenµÄÊäÈ룬µ¼Ö¹¥»÷Õß¿ÉʹÓøÃÎó²îÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220301

 

ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_HigaisaRat(ºÚ¸ñɯ)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½HigaisaRatÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿ØHigaisaRat¡£HigaisaRatÊÇÒ»¸ö»ùÓÚgh0st¿ªÔ´Ô¶¿Ø¿ò¼ÜÐ޸ĶøÀ´Ô¶³Ì¿ØÖÆľÂí£¬ÔÊÐí¹¥»÷Õß¿ØÖƱ»Ö²Èë»úе¡£¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»¿Ø¶ËÖ÷»ú×öÖݪֲÙ×÷¡£

¸üÐÂʱ¼ä£º

20220301

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ͨ´ïOA_í§ÒâÎļþÉÏ´«/Îļþ°üÀ¨Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ͨ´ïOAÊÇÒ»Ìװ칫ϵͳ¡£ÓÉÓÚͨ´ïOAÖб£´æµÄÁ½Ã¶Îó²î(ÎļþÉÏ´«Îó²î£¬Îļþ°üÀ¨Îó²î)£¬¹¥»÷Õß¿Éͨ¹ýÕâÁ½Ã¶Îó²îʵÏÖÔ¶³ÌÏÂÁîÖ´ÐС£/ispirit/im/upload.php±£´æÈƹýµÇ¼(í§ÒâÎļþÉÏ´«Îó²î)£¬ÍŽágateway.php´¦±£´æµÄÎļþ°üÀ¨Îó²î£¬×îÖÕµ¼ÖÂgetshell¡£

¸üÐÂʱ¼ä£º

20220301

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_APISIX_batch-requests_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃApacheAPISIXµÄbatch-requests²å¼þŲÓÃAPI²¢Ö´ÐжñÒâ´úÂë¡£ApacheAPISIXÊÇÒ»¸ö¶¯Ì¬¡¢ÊµÊ±¡¢¸ßÐÔÄܵÄAPIÍø¹Ø¡£APISIXÌṩÁ˸»ºñµÄÁ÷Á¿ÖÎÀíÌØÕ÷£¬ÀýÈ縺ÔØƽºâ¡¢¶¯Ì¬ÉÏÓΡ¢½ð˿ȸÐû²¼¡¢È۶ϡ¢ÈÏÖ¤¡¢¿ÉÊÓ²ìÐԵȡ£

¸üÐÂʱ¼ä£º

20220301