ÿÖÜÉý¼¶Í¨¸æ-2023-03-07

Ðû²¼Ê±¼ä 2023-03-07

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ȨÏÞÈÆ¹ý_Apache_Shiro_v1.5.3ÒÔÏÂ[CVE-2020-11989][CNNVD-202006-1556]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí ¡£¡£¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬ÊÚȨµÈ ¡£¡£¡£¹ØÓÚApacheShiro1.5.3֮ǰµÄ°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý ¡£¡£¡£

¸üÐÂʱ¼ä£º

20230307

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Apache_Log4j2_jndi×¢ÈëǶÌ×lookupÈÆ¹ý[CVE-2021-44228]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheLog4j2ÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕ־ЧÀÍÆ÷ ¡£¡£¡£´ËÊÂÎñ´ú±í·¢Ã÷ÁËÔ´IPÖ÷»ú·¢ËÍÁËÖª×ãlog4j2×é¼þÖ§³ÖµÄÄÚÖÃlookupÃûÌõÄ×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬µ±Ä¿µÄIPÖ÷»úºó¶ËÎüÊÕµ½´ËÃûÌõÄ×Ö·û´®Ê±£¬£¬£¬£¬£¬£¬£¬£¬»á×Ô¶¯Å²ÓÃlookup¹¦Ð§ ¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬£¬£¬£¬£¬£¬£¬´ËÐÐΪ¾ßÓнϸßΣº¦£¬£¬£¬£¬£¬£¬£¬£¬ÈÝÒ×±»¹¥»÷ÕßÀÄÓ㬣¬£¬£¬£¬£¬£¬£¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬£¬£¬£¬£¬£¬£¬²¢¾ÙÐзÇÔ¤ÆÚµÄjndiŲÓ㬣¬£¬£¬£¬£¬£¬£¬´Ó¶øÖ´ÐжñÒâ´úÂë»òÏÂÁî ¡£¡£¡£log4j22.15.0-RC1Ö®ºóµÄ°æ±¾Ä¬ÈϹرÕÁËʹÓôËÊÖ·¨Å²ÓÃjndiŲÓõĹ¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬²¢ÏÞÖÆÁ˰×Ãûµ¥£¬£¬£¬£¬£¬£¬£¬£¬¹ÊʹÓÃδ¾­ÏÞÖÆµÄÀϰ汾log4j2×é¼þ¿ÉÄܻᱣ´æjndi×¢ÈëµÄΣº¦ ¡£¡£¡£

¸üÐÂʱ¼ä£º

20230307

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Apache_Log4j2_jndi×¢ÈëǶÌ×lookupÈÆ¹ý[CVE-2021-44228]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕ־ЧÀÍÆ÷ ¡£¡£¡£´ËÊÂÎñ´ú±í·¢Ã÷ÁËÔ´IPÖ÷»ú·¢ËÍÁËÖª×ãÄÚÖÃlookupÃûÌõÄ×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬µ±Ä¿µÄIPÖ÷»úºó¶ËÎüÊÕµ½´ËÃûÌõÄ×Ö·û´®Ê±£¬£¬£¬£¬£¬£¬£¬£¬»á×Ô¶¯Å²ÓÃlookup¹¦Ð§ ¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬£¬£¬£¬£¬£¬£¬´ËÐÐΪ¾ßÓÐÒ»¶¨Î£º¦£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬£¬£¬£¬£¬£¬£¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬£¬£¬£¬£¬£¬£¬²¢¾ÙÐзÇÔ¤ÆÚµÄjndiŲÓà ¡£¡£¡£

¸üÐÂʱ¼ä£º

20230307