ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ01ÖÜ

Ðû²¼Ê±¼ä 2020-01-06

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê12ÔÂ30ÈÕÖÁ2020Äê01ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î50¸ö£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇApache Solr VelocityÄ£°å´úÂë×¢ÈëÎó²î; Tencent WeChatÓû§ÃûÏÂÁî×¢ÈëÎó²î£»£»£»ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´ÐÐÎó²î£»£»£»Nagios XI schedulereport.php SHELLÏÂÁî×¢ÈëÎó²î£»£»£»Cisco Data Center Network Manager SOAP API OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇNagios XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-20197£©£»£»£»ÃÀ·¨ÔºÊÚȨ΢Èí½ÓÊܳ¯ÏÊAPT37¿ØÖƵÄ50¸öÓòÃû£»£»£»ÎïÁªÍø¹©Ó¦ÉÌWyzeÒâÍâй¶Լ240Íò¿Í»§ÐÅÏ¢£»£»£»°®¶ûÀ¼Õþ¸®Ðû²¼2019-2024¹ú¼ÒÍøÂçÇå¾²Õ½ÂÔ£»£»£»ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬£¬£¬ £¬¿É»á¼ûÄÚ²¿ÏµÍ³¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache Solr VelocityÄ£°å´úÂë×¢ÈëÎó²î


Apache Solr VelocityÄ£°åVelocityResponseWriter±£´æÇå¾²Îó²î£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬Í¨¹ý½ç˵һ¸ö½«¸ÃÉèÖÃÉèÖÃΪ "true" µÄÏìӦдÈëÆ÷À´ÆôÓà "parms .resource.loader. loader¡±£¬£¬£¬ £¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://issues.apache.org/jira/browse/SOLR-13971


2. Tencent WeChatÓû§ÃûÏÂÁî×¢ÈëÎó²î


Tencent WeChatÆÊÎöusernames±£´æÇå¾²Îó²î£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-19-1035/


3. ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´ÐÐÎó²î


ALE Alcatel-Lucent OmnivistaʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬¿ÉÒÔSYSTEMÓû§Éí·ÝÖ´ÐдúÂë¡£¡£¡£¡£¡£

https://packetstormsecurity.com/files/155595/Alcatel-Lucent-Omnivista-8770-Remote-Code-Execution.html


4. Nagios XI schedulereport.php SHELLÏÂÁî×¢ÈëÎó²î


Nagios XI schedulereport.php±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâSHELLÏÂÁî¡£¡£¡£¡£¡£

https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html


5. Cisco Data Center Network Manager SOAP API OSÏÂÁî×¢ÈëÎó²î


Cisco Data Center Network Manager SOAP API±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬ £¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬¿É×¢Èëí§ÒâOSÏÂÁî²¢Ö´ÐС£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Nagios XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-20197£©


MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø


Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¼Æ»®¡£¡£¡£¡£¡£¸Ã¼Æ»®Ö§³Ö¶ÔÓ¦Óá¢Ð§ÀÍ¡¢²Ù×÷ϵͳµÈ¾ÙÐÐ¼à¿ØºÍÔ¤¾¯¡£¡£¡£¡£¡£@Cody SixteenÔÚTwitterÐû²¼ÁËÓйØNagios XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-20197£©µÄÏà¹ØÐÅÏ¢£¬£¬£¬ £¬¸ÃÎó²îÓ°ÏìÁËNagios XI 5.6.9°æ±¾£¬£¬£¬ £¬¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊý£¬£¬£¬ £¬ÔÚWebЧÀÍÆ÷Óû§ÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£¡£ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534


2¡¢ÃÀ·¨ÔºÊÚȨ΢Èí½ÓÊܳ¯ÏÊAPT37¿ØÖƵÄ50¸öÓòÃû


MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø


΢ÈíÀֳɽÓÊÜÁËÓɳ¯ÏʺڿÍ×éÖ¯APT37¿ØÖƵÄ50¸öÓòÃû£¬£¬£¬ £¬ÕâЩÓòÃû±»¸Ã×éÖ¯ÓÃÀ´Ìá³«ÍøÂç¹¥»÷£¬£¬£¬ £¬°üÀ¨·¢ËÍ´¹ÂÚÓʼþºÍÍйܴ¹ÂÚÒ³ÃæµÈ¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖÆäÊý×Ö·¸·¨²¿·Ö£¨DCU£©ºÍÍþвÇ鱨ÖÐÐÄ£¨MSTIC£©ÒѾ­¼àÊÓAPT37³¤´ïÊýÔµÄʱ¼ä£¬£¬£¬ £¬²¢ÓÚ12ÔÂ18ÈÕÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¸Ã×éÖ¯ÌáÆðËßËÏ¡£¡£¡£¡£¡£¸Ã·¨ÔºÊÚÓè΢ÈíȨÏÞÒÔ½ÓÊÜAPT37ÔÚ·¸·¨»î¶¯ÖÐʹÓõÄ50¸öÓòÃû¡£¡£¡£¡£¡£Î¢Èí¸ß¹ÜÌåÏÖ¸Ã×éÖ¯µÄ´ó´ó¶¼Ä¿µÄ¶¼Î»ÓÚÃÀ¹ú¡¢ÈÕ±¾ÒÔ¼°º«¹ú¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-takes-down-50-domains-operated-by-north-korean-hackers/


3¡¢ÎïÁªÍø¹©Ó¦ÉÌWyzeÒâÍâй¶Լ240Íò¿Í»§ÐÅÏ¢


MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø


ÎïÁªÍø¹©Ó¦ÉÌWyzeÈ·ÈÏÆäÒ»¸öElasticsearchЧÀÍÆ÷й¶ÁËÔ¼240ÍòÓû§µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â²¢²»ÊÇÉú²úϵͳ£¬£¬£¬ £¬µ«´æ´¢ÁËÓÐÓõÄÓû§Êý¾Ý£¬£¬£¬ £¬°üÀ¨ÓÃÓÚ½¨ÉèWyzeÕÊ»§µÄµç×ÓÓʼþµØµã¡¢·ÖÅɸøÆäWyzeÇå¾²ÉãÏñ»úµÄÓû§êdzơ¢WiFiÍøÂç±êʶ·ûSSIDÒÔ¼°2.4ÍòÓû§µÄAlexaÁîÅÆµÈ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ12ÔÂ4ÈÕ±»¹ýʧµØÌ»Â¶ÔÚ¹«ÍøÉÏ£¬£¬£¬ £¬Çå¾²¹«Ë¾Twelve SecurityÓÚ12ÔÂ26ÈÕ·¢Ã÷Á˸ÃÊý¾Ý¿â²¢Í¨ÖªÁËWyze£¬£¬£¬ £¬WyzeËæºó¶ÔÊý¾Ý¿â¾ÙÐÐÁ˱£»£»£»¤¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/iot-vendor-wyze-confirms-server-leak/


4¡¢°®¶ûÀ¼Õþ¸®Ðû²¼2019-2024¹ú¼ÒÍøÂçÇå¾²Õ½ÂÔ


MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø


°®¶ûÀ¼Õþ¸®Ðû²¼ÁË¡¶2019-2024¹ú¼ÒÍøÂçÇå¾²Õ½ÂÔ¡·£¬£¬£¬ £¬ÕâÊǸùúÓÚ2015ÄêÐû²¼µÄÊ׸öÇå¾²Õ½ÂԵĸüа汾¡£¡£¡£¡£¡£¸ÃÕ½ÂÔ±¨¸æ¸ÅÊöÁËÕþ¸®½«ÔõÑù¼ÌÐøÔö½ø¸Ã¹úÅÌËã»úÍøÂçºÍÏà¹Ø»ù´¡ÉèÊ©µÄÇå¾²¡£¡£¡£¡£¡£±¨¸æÖÐÆÊÎöÁËÕþ¸®¶ÔÇå¾²ºÍ¿É¿¿µÄÍøÂç¿Õ¼äµÄÔ¸¾°ÒÔ¼°½«½ÓÄɵÄÐж¯£¬£¬£¬ £¬°üÀ¨¼ÌÐøÌá¸ßÒªº¦»ù´¡¼Ü¹¹ºÍ¹«¹²Ð§ÀÍÖеÄÍøÂ絯ÐÔ£»£»£»Ìá¸ßÆóÒµºÍ¹«Ãñ¶ÔÍøÂçÇå¾²Ö÷ÒªÐÔµÄÊìϤ£»£»£»Í¨¹ýÓë½ÌÓýϵͳ¡¢ÐÐÒµºÍѧÊõ½çµÄÏàÖú£¬£¬£¬ £¬½øÒ»²½Éú³¤È«Éç»áµÄÍøÂçÇå¾²ÎÄ»¯£»£»£»¼ÌÐøÀο¿°®¶ûÀ¼×÷ΪÊÖÒÕºÍÐÅÏ¢Çå¾²ÖÐÐĵÄÈ«ÇòÉùÓþ£¬£¬£¬ £¬²¢×ÊÖúÔö½ø°®¶ûÀ¼³ÉΪICTÆóÒµµÄÊ×Ñ¡ËùÔÚ¡£¡£¡£¡£¡£¸Ã±¨¸æ»¹±Þ²ß¾ÙÐÐË¢ÐÂÒÔ±£»£»£»¤Òªº¦»ù´¡¼Ü¹¹ÃâÊÜÖØ´óÍøÂçÍþвµÄÓ°Ï죬£¬£¬ £¬Í¬Ê±»¹ÖÒÑÔ³ÆÍâ¹ú¿ÉÄÜ»á¸ÉÔ¤°®¶ûÀ¼µÄÑ¡¾Ù¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95825/laws-and-regulations/irish-national-cyber-security-strategy.html


5¡¢ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬£¬£¬ £¬¿É»á¼ûÄÚ²¿ÏµÍ³


MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø


Ç徲ר¼ÒVinoth KumarÔÚÒ»¸ö¹ûÕæ¿ÉÓõÄGithub´æ´¢¿âÖз¢Ã÷ÐǰͿ˵ÄÒ»¸öAPIÃÜÔ¿ÔÚÏß̻¶£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔʹÓøÃÃÜÔ¿À´»á¼û¹«Ë¾µÄÄÚ²¿ÏµÍ³²¢¸Ä¶¯ÊÚȨÓû§ÁÐ±í¡£¡£¡£¡£¡£¸ÃÃÜÔ¿¿ÉÓÃÓÚ»á¼ûÐǰͿËJumpCloud API£¬£¬£¬ £¬JumpCloudÊÇÒ»¸öActive DirectoryÖÎÀíÆ½Ì¨£¬£¬£¬ £¬ÌṩÓû§ÖÎÀí¡¢WebÓ¦ÓóÌÐòµ¥µãµÇ¼£¨SSO£©»á¼û¿ØÖƺÍÇáÐÍĿ¼»á¼ûЭÒ飨LDAP£©Ð§ÀÍ¡£¡£¡£¡£¡£Kumar»¹ÌṩÁ˸ÃÎÊÌâµÄPoC´úÂ룬£¬£¬ £¬ÑÝʾÁËÔõÑùÁгöϵͳºÍÓû§¡¢¿ØÖÆAWSÕÊ»§¡¢ÔÚϵͳÉÏÖ´ÐÐÏÂÁîÒÔ¼°Ìí¼Ó»òɾ³ýÓÐȨ»á¼ûÄÚ²¿ÏµÍ³µÄÓû§¡£¡£¡£¡£¡£ÐǰͿËÈ·ÈÏÁËÕâÒ»ÎÊÌⲢѸËÙ×÷·ÏÁ˸ÃÃÜÔ¿¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95826/security/starbucks-api-key-exposed-online.html