ConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-09Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-3396£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
²úÆ·
Confluence Data Center
°æ±¾
ËùÓÐ6.0.x£¬£¬£¬£¬£¬£¬6.1.x£¬£¬£¬£¬£¬£¬6.2.x£¬£¬£¬£¬£¬£¬6.3.x£¬£¬£¬£¬£¬£¬6.4.xºÍ6.5.x°æ±¾
6.6.12֮ǰµÄËùÓÐ6.6.x°æ±¾
ËùÓÐ6.7.x£¬£¬£¬£¬£¬£¬6.8.x£¬£¬£¬£¬£¬£¬6.9.x£¬£¬£¬£¬£¬£¬6.10.xºÍ6.11.x°æ±¾
6.12.3֮ǰµÄËùÓÐ6.12.x°æ±¾
6.13.3֮ǰµÄËùÓÐ6.13.x°æ±¾
6.14.2֮ǰµÄËùÓÐ6.14.x°æ±¾
×é¼þ
widgetconnector<=3.1.3
Îó²î¸ÅÊö
ConfluenceÊÇÈ«ÇòÊ¢ÐеÄWikiϵͳ£¬£¬£¬£¬£¬£¬ÓªÒµº¸Ç100¶à¸ö¹ú¼Ò»òµØÇø¡£¡£¡£¡£¡£¡£¡£IBM¡¢SAPµÈÖ®×ÅÃûÆóÒµ¶¼Ê¹ÓÃConfluence¹¹½¨ÆóÒµWiki²¢Ïò¹«ÖÚ¿ª·Å¡£¡£¡£¡£¡£¡£¡£
CVE-2019-3395:Atlassian¹«Ë¾µÄConfluence ServerºÍData Center²úÆ·ÖеÄWebDAV¶Ëµã±£´æÐ§ÀÍÆ÷¶ËÇëÇóαÔìÎó²î¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÒÀ¸½Confluence Server»òData CenterʵÀý·¢ËÍí§ÒâHTTPºÍWebDAVÇëÇ󡣡£¡£¡£¡£¡£¡£
CVE-2019-3396:Atlassian¹«Ë¾µÄConfluence ServerºÍData Center²úÆ·ÖÐʹÓõÄwidgetconnecter×é¼þ(°æ±¾<=3.1.3)Öб£´æÐ§ÀÍÆ÷¶ËÄ£°å×¢Èë(SSTI)Îó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄHTTPÇëÇó²ÎÊý£¬£¬£¬£¬£¬£¬¶ÔÄ¿µÄϵͳʵÑ飨·¾¶±éÀú¡¢í§ÒâÎļþ¶ÁÈ¡ÒÔ¼°Ô¶³ÌÏÂÁîÖ´ÐУ©¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸ÃÀ๥»÷¿Éµ¼ÖÂÄ¿µÄϵͳÖеÄÃô¸ÐÐÅÏ¢±»Ð¹Â¶£¬£¬£¬£¬£¬£¬ÒÔ¼°Ö´Ðй¥»÷Õ߽ṹµÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
¾Ýͳ¼Æ£¬£¬£¬£¬£¬£¬È«Çò¹²ÓÐ78158¸öConfluence¿ª·ÅЧÀÍ£¬£¬£¬£¬£¬£¬ÃÀ¹ú×î¶à£¬£¬£¬£¬£¬£¬ÓÐ23002¸öЧÀÍ£¬£¬£¬£¬£¬£¬µÂ¹úµÚ¶þ£¬£¬£¬£¬£¬£¬ÓÐ14385¸ö¿ª·ÅЧÀÍ£¬£¬£¬£¬£¬£¬ÖйúµÚÈý£¬£¬£¬£¬£¬£¬ÓÐ7281¸öЧÀÍ£¬£¬£¬£¬£¬£¬°Ä´óÀûÑǵÚËÄ£¬£¬£¬£¬£¬£¬ÓÐ7959¸öЧÀÍ£¬£¬£¬£¬£¬£¬°®¶ûÀ¼µÚÎ壬£¬£¬£¬£¬£¬ÓÐ2893¸öЧÀÍ¡£¡£¡£¡£¡£¡£¡£ÌìϵĿª·ÅµÄConfluenceЧÀÍÖУ¬£¬£¬£¬£¬£¬Õã½×î¶à£¬£¬£¬£¬£¬£¬ÓÐ3040¸öЧÀÍ£¬£¬£¬£¬£¬£¬±±¾©µÚ¶þ£¬£¬£¬£¬£¬£¬ÓÐ1713¸öЧÀÍ£¬£¬£¬£¬£¬£¬ÉϺ£µÚÈý£¬£¬£¬£¬£¬£¬ÓÐ532¸öЧÀÍ£¬£¬£¬£¬£¬£¬¹ã¶«µÚËÄ£¬£¬£¬£¬£¬£¬ÓÐ525¸öЧÀÍ¡£¡£¡£¡£¡£¡£¡£
Îó²îʹÓÃ
ʹÓÃ_template²ÎÊýÁýÕÖVelocityäÖȾģ°å£¬£¬£¬£¬£¬£¬Ê¹ÓÃfile:ÐÒé¿ÉÒÔ¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡(²»ÔÙÊÜÏÞÓÚclasspath)
ͨ¹ý¸ÃÒªÁì¿ÉÒÔ¾ÙÐÐÍâµØÎļþ°üÀ¨£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://jira.atlassian.com/browse/CONFSERVER-57974¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201903-909
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201903-910
https://nvd.nist.gov/vuln/detail/CVE-2019-3396
https://nvd.nist.gov/vuln/detail/CVE-2019-3395


¾©¹«Íø°²±¸11010802024551ºÅ