ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ01ÖÜ
°ä²¼¹¦·ò 2020-01-06>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê12ÔÂ30ÈÕÖÁ2020Äê01ÔÂ05ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Solr VelocityÄ£°å´úÂë×¢Èë·ì϶; Tencent WeChatÓû§ÃûºÅÁî×¢Èë·ì϶£»£»£»£»£»£»ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´Ðзì϶£»£»£»£»£»£»Nagios XI schedulereport.php SHELLºÅÁî×¢Èë·ì϶£»£»£»£»£»£»Cisco Data Center Network Manager SOAP API OSºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇNagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©£»£»£»£»£»£»ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû£»£»£»£»£»£»ÎïÁªÍø¹©¸øÉÌWyzeÒâ±íй¶Լ240Íò¿Í»§ÐÅÏ¢£»£»£»£»£»£»°®¶ûÀ¼µ±¾Ö°ä²¼2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ£»£»£»£»£»£»ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬£¬£¬£¬£¬£¬£¬¿É½Ó¼ûÄÚ²¿ÏµÍ³¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1. Apache Solr VelocityÄ£°å´úÂë×¢Èë·ì϶
Apache Solr VelocityÄ£°åVelocityResponseWriter´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Í¨¹ý½ç˵һ¸ö½«¸ÃÅäÖÃÉèÖÃΪ "true" µÄÏìӦдÈëÆ÷À´ÆôÓà "parms .resource.loader. loader¡±£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://issues.apache.org/jira/browse/SOLR-13971
2. Tencent WeChatÓû§ÃûºÅÁî×¢Èë·ì϶
Tencent WeChat½âÎöusernames´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-1035/
3. ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´Ðзì϶
ALE Alcatel-Lucent OmnivistaʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»SYSTEMÓû§Éí·ÝÖ´ÐдúÂë¡£¡£¡£¡£¡£
https://packetstormsecurity.com/files/155595/Alcatel-Lucent-Omnivista-8770-Remote-Code-Execution.html
4. Nagios XI schedulereport.php SHELLºÅÁî×¢Èë·ì϶
Nagios XI schedulereport.php´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâSHELLºÅÁî¡£¡£¡£¡£¡£
https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html
5. Cisco Data Center Network Manager SOAP API OSºÅÁî×¢Èë·ì϶
Cisco Data Center Network Manager SOAP API´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É×¢ÈëËÁÒâOSºÅÁî²¢Ö´ÐС£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Nagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©
Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¹æ»®¡£¡£¡£¡£¡£¸Ã¹æ»®Ö§³Ö¶ÔÀûÓᢷþÎñ¡¢²Ù×÷ϵͳµÈ½øÐÐ¼à¿ØºÍÔ¤¾¯¡£¡£¡£¡£¡£@Cody SixteenÔÚTwitter°ä²¼ÁËÓйØNagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©µÄÓйØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËNagios XI 5.6.9°æ±¾£¬£¬£¬£¬£¬£¬£¬¾¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»Í¨¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊý£¬£¬£¬£¬£¬£¬£¬ÔÚWeb·þÎñÆ÷Óû§ÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ²Ù×÷ϵͳºÅÁî¡£¡£¡£¡£¡£Ä¿Ç°³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534
2¡¢ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû
΢Èí³É¹¦ÊÕÊÜÁËÓɳ¯ÏʺڿÍ×éÖ¯APT37½ÚÔìµÄ50¸öÓòÃû£¬£¬£¬£¬£¬£¬£¬ÕâЩÓòÃû±»¸Ã×éÖ¯ÓÃÀ´ÌáÒéÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô̺¬·¢ËÍ´¹µöÓʼþºÍÍйܴ¹µöÒ³ÃæµÈ¡£¡£¡£¡£¡£Î¢Èí°µÊ¾ÆäÊý×Ö·¸×ﲿÃÅ£¨DCU£©ºÍÍþвµý±¨ÖÐÐÄ£¨MSTIC£©ÒѾ¼à¶½APT37³¤´ïÊýԵŦ·ò£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ12ÔÂ18ÈÕÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¸Ã×éÖ¯Ìá¸æ×´ËÏ¡£¡£¡£¡£¡£¸Ã·¨ÔºÊÚÓè΢ÈíȨÏÞÒÔÊÕÊÜAPT37ÔÚ·¸×ï»î¶¯ÖÐʹÓõÄ50¸öÓòÃû¡£¡£¡£¡£¡£Î¢Èí¸ß¹Ü°µÊ¾¸Ã×éÖ¯µÄ´óÎÞÊýÖ¸±ê¶¼Î»ÓÚÃÀ¹ú¡¢ÈÕ±¾ÒÔ¼°º«¹ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-takes-down-50-domains-operated-by-north-korean-hackers/
3¡¢ÎïÁªÍø¹©¸øÉÌWyzeÒâ±íй¶Լ240Íò¿Í»§ÐÅÏ¢
ÎïÁªÍø¹©¸øÉÌWyzeÈ·ÈÏÆäÒ»¸öElasticsearch·þÎñÆ÷й¶ÁËÔ¼240ÍòÓû§µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â²¢²»Êdzö²úϵͳ£¬£¬£¬£¬£¬£¬£¬µ«´æ´¢ÁËÓÐЧµÄÓû§Êý¾Ý£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÓÃÓÚ´´½¨WyzeÕÊ»§µÄµç×ÓÓʼþµØÖ·¡¢·ÖÅ䏸ÆäWyze°²È«ÉãÏñ»úµÄÓû§êdzơ¢WiFiÍøÂç±êʶ·ûSSIDÒÔ¼°2.4ÍòÓû§µÄAlexaÁîÅÆµÈ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ12ÔÂ4ÈÕ±»ÃýÎóµØÂ¶³öÔÚ¹«ÍøÉÏ£¬£¬£¬£¬£¬£¬£¬°²È«¹«Ë¾Twelve SecurityÓÚ12ÔÂ26ÈÕ·¢ÏÖÁ˸ÃÊý¾Ý¿â²¢Í¨ÖªÁËWyze£¬£¬£¬£¬£¬£¬£¬WyzeËæºó¶ÔÊý¾Ý¿â½øÐÐÁ˱£»£»£»£»£»£»¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/iot-vendor-wyze-confirms-server-leak/
4¡¢°®¶ûÀ¼µ±¾Ö°ä²¼2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ
°®¶ûÀ¼µ±¾Ö°ä²¼ÁË¡¶2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ¡·£¬£¬£¬£¬£¬£¬£¬ÕâÊǸùúÓÚ2015Äê°ä²¼µÄÊ׸ö°²È«Õ½ÊõµÄ¸üа汾¡£¡£¡£¡£¡£¸ÃÕ½Êõ»ã±¨¸ÅÊöÁ˵±¾Ö½«ÈôºÎ³ÖÐøÍÆ½ø¸Ã¹úÍÆËã»úÍøÂçºÍÓйػù´¡ÉèÊ©µÄ°²È«¡£¡£¡£¡£¡£»ã±¨ÖвûÁËÈ»µ±¾Ö¶Ô°²È«ºÍ¿¿µÃסµÄÍøÂç¿Õ¼äµÄÔ¸¾°ÒÔ¼°½«²ÉÈ¡µÄÐж¯£¬£¬£¬£¬£¬£¬£¬Ô̺¬³ÖÐøÌá¸ß¹Ø¼ü»ù´¡¼Ü¹¹ºÍ¹«¹²·þÎñÖеÄÍøÂ絯ÐÔ£»£»£»£»£»£»Ìá¸ßÆóÒµºÍ¹«Ãñ¶ÔÍøÂ簲ȫ³ÁÒªÐÔµÄÒâʶ£»£»£»£»£»£»Í¨¹ýÓë½ÌÓýϵͳ¡¢ÐÐÒµºÍѧÊõ½çµÄºÏ×÷£¬£¬£¬£¬£¬£¬£¬½øÒ»²½·¢Õ¹È«Éç»áµÄÍøÂ簲ȫÎÄ»¯£»£»£»£»£»£»³ÖÐø¼áÈͰ®¶ûÀ¼×÷Ϊ¼¼ÊõºÍÐÅÏ¢°²È«ÖÐÐĵÄÈ«ÇòÃûÓþ£¬£¬£¬£¬£¬£¬£¬²¢Ô®ÊÖÍÆ½ø°®¶ûÀ¼³ÉΪICTÆóÒµµÄÊ×Ñ¡µØÖ·¡£¡£¡£¡£¡£¸Ã»ã±¨»¹¶½ÍƽøÐж¦ÐÂÒÔ±£»£»£»£»£»£»¤¹Ø¼ü»ù´¡¼Ü¹¹ÃâÊܳÁ´óÍøÂçÍþвµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹ÖÒ¸æ³Æ±í¹ú¿ÉÄÜ»á¹ýÎʰ®¶ûÀ¼µÄÑ¡¾Ù¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95825/laws-and-regulations/irish-national-cyber-security-strategy.html
5¡¢ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬£¬£¬£¬£¬£¬£¬¿É½Ó¼ûÄÚ²¿ÏµÍ³
°²È«×¨¼ÒVinoth KumarÔÚÒ»¸ö¹«¿ª¿ÉÓõÄGithub´æ´¢¿âÖз¢ÏÖÐǰͿ˵ÄÒ»¸öAPIÃÜÔ¿ÔÚÏß¶³ö£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓøÃÃÜÔ¿À´½Ó¼û¹«Ë¾µÄÄÚ²¿ÏµÍ³²¢´Û¸ÄÊÚȨÓû§ÁÐ±í¡£¡£¡£¡£¡£¸ÃÃÜÔ¿¿ÉÓÃÓÚ½Ó¼ûÐǰͿËJumpCloud API£¬£¬£¬£¬£¬£¬£¬JumpCloudÊÇÒ»¸öActive DirectoryÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬£¬£¬ÌṩÓû§ÖÎÀí¡¢WebÀûÓ÷¨Ê½µ¥µãµÇ¼£¨SSO£©½Ó¼û½ÚÔìºÍÇáÐÍĿ¼½Ó¼ûºÍ̸£¨LDAP£©·þÎñ¡£¡£¡£¡£¡£Kumar»¹ÌṩÁ˸ÃÎÊÌâµÄPoC´úÂ룬£¬£¬£¬£¬£¬£¬ÑÝʾÁËÈôºÎÁгöϵͳºÍÓû§¡¢½ÚÔìAWSÕÊ»§¡¢ÔÚϵͳÉÏÖ´ÐкÅÁîÒÔ¼°Ôö³¤»òɾ³ýÓÐȨ½Ó¼ûÄÚ²¿ÏµÍ³µÄÓû§¡£¡£¡£¡£¡£ÐǰͿËÈ·ÈÏÁËÕâÒ»ÎÊÌⲢѸËÙ³·ÏúÁ˸ÃÃÜÔ¿¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95826/security/starbucks-api-key-exposed-online.html


¾©¹«Íø°²±¸11010802024551ºÅ