Ç徲ͨ¸æ
-
΢ÈíÐû²¼5Ô²¹¶¡ ÐÞ¸´111¸öÇå¾²ÎÊÌâ
2020-05-13
΢ÈíÓÚ±¾ÖܶþÐû²¼ÁË5ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË111¸ö´Ó¼òÆÓµÄÓÕÆ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄÇå¾²ÎÊÌ⣬²úÆ·Éæ¼° NET Core¡¢ NET Framework¡¢Active Directory¡¢Common Log File System Driver¡¢Internet Explorer¡¢Microsoft Dynamics¡¢Microsoft Edge¡¢Microsoft Graphics Component¡¢Microsoft JET Database Engine¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Microsoft Scripting Engine¡¢Microsoft Win
¸ü¶à -
AG¹«Ë¾ÍþвÇ鱨Öܱ¨£¨20200427~20200510£©
2020-05-11
Ò»¡¢Íþвͨ¸æJenkins²å¼þ¶à¸öÎó²î¡¾Ðû²¼Ê±¼ä¡¿2020-05-08 18:00:00 GMT¡¾¸ÅÊö¡¿5ÔÂ6ÈÕ£¬Jenkins¹Ù·½Ðû²¼Ç徲ͨ¸æÐÞ¸´²å¼þÖеÄ9¸öÎó²î£¬ÓÐ5¸ö²å¼þÊܵ½Ó°Ïì¡£ÆäÖÐSCM Filter Jervis²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2189£©£¬¹Ù·½¶¨¼¶Îª¸ßΣ¡£ÓÉÓÚSCM Filter Jervis²å¼þĬÈϲ»ÉèÖÃYAMLÆÊÎöÆ÷£¬µ¼ÖÂÓû§¿ÉÒÔʹÓùýÂËÆ÷ÉèÖÃÏîÄ¿£¬Ò²¿ÉÒÔ²Ù×÷SCMÒÑ´æ´¢ÉèÖùýµÄÏîÄ¿ÄÚÈÝ¡£CredentialsBinding²å¼þ±£´æÁ½¸öƾ֤й¶Îó²î£¨CVE-20
¸ü¶à -
¡¸Îó²îͨ¸æ¡¹Jenkins²å¼þ¶à¸öÎó²î
2020-05-08
Îó²î¸ÅÊö5ÔÂ6ÈÕ£¬Jenkins¹Ù·½Ðû²¼Ç徲ͨ¸æÐÞ¸´²å¼þÖеÄ9¸öÎó²î£¬ÓÐ5¸ö²å¼þÊܵ½Ó°Ïì¡£ÆäÖÐSCM Filter Jervis²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2189£©£¬¹Ù·½¶¨¼¶Îª¸ßΣ¡£ÓÉÓÚSCM Filter Jervis²å¼þĬÈϲ»ÉèÖÃYAMLÆÊÎöÆ÷£¬µ¼ÖÂÓû§¿ÉÒÔʹÓùýÂËÆ÷ÉèÖÃÏîÄ¿£¬Ò²¿ÉÒÔ²Ù×÷SCMÒÑ´æ´¢ÉèÖùýµÄÏîÄ¿ÄÚÈÝ¡£CredentialsBinding²å¼þ±£´æÁ½¸öƾ֤й¶Îó²î£¨CVE-2020-2181¡¢CVE-2020-2182£©£¬CopyArtifact²å¼þ±£´æÈ¨ÏÞУÑé²»µ±Îó²î£¨CVE-
¸ü¶à -
AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2020Äê4Ô£©
2020-05-04
Ò»¡¢Îó²îÌ¬ÊÆ2020Äê04ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼209Îó²î, ÆäÖиßΣÎó²î155¸ö£¬Î¢Èí¸ßΣÎó²î18¸ö¡£* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2020 04 29×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ¡£¶þ¡¢ÍþвÊÂÎñpolaris½©Ê¬ÍøÂç¹¥»÷È«ÇòNetlink·ÓÉÆ÷¡¾±êÇ©¡¿polaris¡¾Ê±¼ä¡¿2020-04-10¡¾¼ò½é¡¿½üÆÚAG¹«Ë¾¿Æ¼¼¸ñÎïʵÑéÊÒ·¢Ã÷Õë¶ÔNetlink GPON·ÓÉÆ÷RCEÎó²îµÄʹÓÃÐÐ
¸ü¶à -
¿ËÈÕ£¬·þÎñÆ÷»ù´¡¼Ü¹¹¼¯Öл¯ÖÎÀíÆ½Ì¨SaltStack Salt ±»Åû¶±£´æÁ½¸öÇå¾²Îó²î£¨CVE-2020-11651¡¢CVE-2020-11652£©¡£¿ªÔ´ÏîÄ¿Salt ÊÇSaltStack¹«Ë¾²úÆ·µÄ½¹µã£¬×÷ΪÖÎÀíÊý¾ÝÖÐÐĺÍÔÆÇéÐÎÖзþÎñÆ÷µÄÉèÖù¤¾ß£¬¹ãÊܽӴý¡£±£´æµÄÁ½¸öÎó²î»®·ÖÊÇÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-11651£©ºÍĿ¼±éÀúÎó²î£¨ CVE-2020-11652£©¡£Îó²îÐÎòCVE-2020-11651Îó²îÓÉClearFuncsÀàÒýÆð£¬¸ÃÀàÎÞÒâÖÐ̻¶ÁË_send_pub£¨£©ºÍ_prep_auth_info£¨£©ÒªÁì¡£
¸ü¶à -
Ò»¡¢Îó²î¸ÅÊö4ÔÂ28ÈÕ£¬Juniper¹Ù·½Ðû²¼Ç徲ͨ¸æÐÞ¸´Juniper Networks Junos OSÖÐJ-WebºÍ»ùÓÚWebµÄ£¨HTTP HTTPS£©·þÎñÖеÄÎó²î£¨CVE-2020-1631£©£¬JunosOS×°±¸µÄJ-Web·þÎñ¡¢WebÉí·ÝÑé֤ģ¿é¡¢¶¯Ì¬VPN£¨DVPN£©¡¢´øÓÐWebÖØ¶¨ÏòµÄ·À»ðǽÉí·ÝÑéÖ¤¼°Áã½Ó´¥ÉèÖã¨ZTP£©ËùʹÓõÄHTTP HTTPS·þÎñ½Ó¿Ú±£´æÍâµØÎļþ°üÀ¨£¨LFI£©ºÍ·¾¶±éÀúÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÏòhttpd logÎļþ×¢ÈëÏÂÁ¶ÁÈ¡Îļþ»ò»ñÈ¡J-Web»á»°ÁîÅÆ¡£½¨ÒéʹÓøÃϵͳ
¸ü¶à








