ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ01ÖÜ

Ðû²¼Ê±¼ä 2020-01-06

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê12ÔÂ30ÈÕÖÁ2020Äê01ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î50¸ö£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Solr VelocityÄ£°å´úÂë×¢ÈëÎó²î; Tencent WeChatÓû§ÃûÏÂÁî×¢ÈëÎó²î£»£»£»£»ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´ÐÐÎó²î£»£»£»£»Nagios XI schedulereport.php SHELLÏÂÁî×¢ÈëÎó²î£»£»£»£»Cisco Data Center Network Manager SOAP API OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇNagios XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-20197£©£»£»£»£»ÃÀ·¨ÔºÊÚȨ΢Èí½ÓÊܳ¯ÏÊAPT37¿ØÖƵÄ50¸öÓòÃû£»£»£»£»ÎïÁªÍø¹©Ó¦ÉÌWyzeÒâÍâй¶Լ240Íò¿Í»§ÐÅÏ¢£»£»£»£»°®¶ûÀ¼Õþ¸®Ðû²¼2019-2024¹ú¼ÒÍøÂçÇå¾²Õ½ÂÔ£»£»£»£»ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬ £¬£¬£¬¿É»á¼ûÄÚ²¿ÏµÍ³¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache Solr VelocityÄ£°å´úÂë×¢ÈëÎó²î


Apache Solr VelocityÄ£°åVelocityResponseWriter±£´æÇå¾²Îó²î£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬Í¨¹ý½ç˵һ¸ö½«¸ÃÉèÖÃÉèÖÃΪ "true" µÄÏìӦдÈëÆ÷À´ÆôÓà "parms .resource.loader. loader¡±£¬ £¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://issues.apache.org/jira/browse/SOLR-13971


2. Tencent WeChatÓû§ÃûÏÂÁî×¢ÈëÎó²î


Tencent WeChatÆÊÎöusernames±£´æÇå¾²Îó²î£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-19-1035/


3. ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´ÐÐÎó²î


ALE Alcatel-Lucent OmnivistaʵÏÖ±£´æÇå¾²Îó²î£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬¿ÉÒÔSYSTEMÓû§Éí·ÝÖ´ÐдúÂë¡£¡£¡£¡£

https://packetstormsecurity.com/files/155595/Alcatel-Lucent-Omnivista-8770-Remote-Code-Execution.html


4. Nagios XI schedulereport.php SHELLÏÂÁî×¢ÈëÎó²î


Nagios XI schedulereport.php±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâSHELLÏÂÁî¡£¡£¡£¡£

https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html


5. Cisco Data Center Network Manager SOAP API OSÏÂÁî×¢ÈëÎó²î


Cisco Data Center Network Manager SOAP API±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬¿É×¢Èëí§ÒâOSÏÂÁî²¢Ö´ÐС£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Nagios XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-20197£©


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¼Æ»®¡£¡£¡£¡£¸Ã¼Æ»®Ö§³Ö¶ÔÓ¦Óá¢Ð§ÀÍ¡¢²Ù×÷ϵͳµÈ¾ÙÐÐ¼à¿ØºÍÔ¤¾¯¡£¡£¡£¡£@Cody SixteenÔÚTwitterÐû²¼ÁËÓйØNagios XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-20197£©µÄÏà¹ØÐÅÏ¢£¬ £¬£¬£¬¸ÃÎó²îÓ°ÏìÁËNagios XI 5.6.9°æ±¾£¬ £¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊý£¬ £¬£¬£¬ÔÚWebЧÀÍÆ÷Óû§ÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534


2¡¢ÃÀ·¨ÔºÊÚȨ΢Èí½ÓÊܳ¯ÏÊAPT37¿ØÖƵÄ50¸öÓòÃû


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


΢ÈíÀֳɽÓÊÜÁËÓɳ¯ÏʺڿÍ×éÖ¯APT37¿ØÖƵÄ50¸öÓòÃû£¬ £¬£¬£¬ÕâЩÓòÃû±»¸Ã×éÖ¯ÓÃÀ´Ìá³«ÍøÂç¹¥»÷£¬ £¬£¬£¬°üÀ¨·¢ËÍ´¹ÂÚÓʼþºÍÍйܴ¹ÂÚÒ³ÃæµÈ¡£¡£¡£¡£Î¢ÈíÌåÏÖÆäÊý×Ö·¸·¨²¿·Ö£¨DCU£©ºÍÍþвÇ鱨ÖÐÐÄ£¨MSTIC£©ÒѾ­¼àÊÓAPT37³¤´ïÊýÔµÄʱ¼ä£¬ £¬£¬£¬²¢ÓÚ12ÔÂ18ÈÕÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¸Ã×éÖ¯ÌáÆðËßËÏ¡£¡£¡£¡£¸Ã·¨ÔºÊÚÓè΢ÈíȨÏÞÒÔ½ÓÊÜAPT37ÔÚ·¸·¨»î¶¯ÖÐʹÓõÄ50¸öÓòÃû¡£¡£¡£¡£Î¢Èí¸ß¹ÜÌåÏÖ¸Ã×éÖ¯µÄ´ó´ó¶¼Ä¿µÄ¶¼Î»ÓÚÃÀ¹ú¡¢ÈÕ±¾ÒÔ¼°º«¹ú¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-takes-down-50-domains-operated-by-north-korean-hackers/


3¡¢ÎïÁªÍø¹©Ó¦ÉÌWyzeÒâÍâй¶Լ240Íò¿Í»§ÐÅÏ¢


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ÎïÁªÍø¹©Ó¦ÉÌWyzeÈ·ÈÏÆäÒ»¸öElasticsearchЧÀÍÆ÷й¶ÁËÔ¼240ÍòÓû§µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¸ÃÊý¾Ý¿â²¢²»ÊÇÉú²úϵͳ£¬ £¬£¬£¬µ«´æ´¢ÁËÓÐÓõÄÓû§Êý¾Ý£¬ £¬£¬£¬°üÀ¨ÓÃÓÚ½¨ÉèWyzeÕÊ»§µÄµç×ÓÓʼþµØµã¡¢·ÖÅɸøÆäWyzeÇå¾²ÉãÏñ»úµÄÓû§êdzơ¢WiFiÍøÂç±êʶ·ûSSIDÒÔ¼°2.4ÍòÓû§µÄAlexaÁîÅÆµÈ¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ12ÔÂ4ÈÕ±»¹ýʧµØÌ»Â¶ÔÚ¹«ÍøÉÏ£¬ £¬£¬£¬Çå¾²¹«Ë¾Twelve SecurityÓÚ12ÔÂ26ÈÕ·¢Ã÷Á˸ÃÊý¾Ý¿â²¢Í¨ÖªÁËWyze£¬ £¬£¬£¬WyzeËæºó¶ÔÊý¾Ý¿â¾ÙÐÐÁ˱£»£»£»£»¤¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/iot-vendor-wyze-confirms-server-leak/


4¡¢°®¶ûÀ¼Õþ¸®Ðû²¼2019-2024¹ú¼ÒÍøÂçÇå¾²Õ½ÂÔ


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


°®¶ûÀ¼Õþ¸®Ðû²¼ÁË¡¶2019-2024¹ú¼ÒÍøÂçÇå¾²Õ½ÂÔ¡·£¬ £¬£¬£¬ÕâÊǸùúÓÚ2015ÄêÐû²¼µÄÊ׸öÇå¾²Õ½ÂԵĸüа汾¡£¡£¡£¡£¸ÃÕ½ÂÔ±¨¸æ¸ÅÊöÁËÕþ¸®½«ÔõÑù¼ÌÐøÔö½ø¸Ã¹úÅÌËã»úÍøÂçºÍÏà¹Ø»ù´¡ÉèÊ©µÄÇå¾²¡£¡£¡£¡£±¨¸æÖÐÆÊÎöÁËÕþ¸®¶ÔÇå¾²ºÍ¿É¿¿µÄÍøÂç¿Õ¼äµÄÔ¸¾°ÒÔ¼°½«½ÓÄɵÄÐж¯£¬ £¬£¬£¬°üÀ¨¼ÌÐøÌá¸ßÒªº¦»ù´¡¼Ü¹¹ºÍ¹«¹²Ð§ÀÍÖеÄÍøÂ絯ÐÔ£»£»£»£»Ìá¸ßÆóÒµºÍ¹«Ãñ¶ÔÍøÂçÇå¾²Ö÷ÒªÐÔµÄÊìϤ£»£»£»£»Í¨¹ýÓë½ÌÓýϵͳ¡¢ÐÐÒµºÍѧÊõ½çµÄÏàÖú£¬ £¬£¬£¬½øÒ»²½Éú³¤È«Éç»áµÄÍøÂçÇå¾²ÎÄ»¯£»£»£»£»¼ÌÐøÀο¿°®¶ûÀ¼×÷ΪÊÖÒÕºÍÐÅÏ¢Çå¾²ÖÐÐĵÄÈ«ÇòÉùÓþ£¬ £¬£¬£¬²¢×ÊÖúÔö½ø°®¶ûÀ¼³ÉΪICTÆóÒµµÄÊ×Ñ¡ËùÔÚ¡£¡£¡£¡£¸Ã±¨¸æ»¹±Þ²ß¾ÙÐÐË¢ÐÂÒÔ±£»£»£»£»¤Òªº¦»ù´¡¼Ü¹¹ÃâÊÜÖØ´óÍøÂçÍþвµÄÓ°Ï죬 £¬£¬£¬Í¬Ê±»¹ÖÒÑÔ³ÆÍâ¹ú¿ÉÄÜ»á¸ÉÔ¤°®¶ûÀ¼µÄÑ¡¾Ù¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95825/laws-and-regulations/irish-national-cyber-security-strategy.html


5¡¢ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬ £¬£¬£¬¿É»á¼ûÄÚ²¿ÏµÍ³


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


Ç徲ר¼ÒVinoth KumarÔÚÒ»¸ö¹ûÕæ¿ÉÓõÄGithub´æ´¢¿âÖз¢Ã÷ÐǰͿ˵ÄÒ»¸öAPIÃÜÔ¿ÔÚÏß̻¶£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÃÜÔ¿À´»á¼û¹«Ë¾µÄÄÚ²¿ÏµÍ³²¢¸Ä¶¯ÊÚȨÓû§Áбí¡£¡£¡£¡£¸ÃÃÜÔ¿¿ÉÓÃÓÚ»á¼ûÐǰͿËJumpCloud API£¬ £¬£¬£¬JumpCloudÊÇÒ»¸öActive DirectoryÖÎÀíÆ½Ì¨£¬ £¬£¬£¬ÌṩÓû§ÖÎÀí¡¢WebÓ¦ÓóÌÐòµ¥µãµÇ¼£¨SSO£©»á¼û¿ØÖƺÍÇáÐÍĿ¼»á¼ûЭÒ飨LDAP£©Ð§ÀÍ¡£¡£¡£¡£Kumar»¹ÌṩÁ˸ÃÎÊÌâµÄPoC´úÂ룬 £¬£¬£¬ÑÝʾÁËÔõÑùÁгöϵͳºÍÓû§¡¢¿ØÖÆAWSÕÊ»§¡¢ÔÚϵͳÉÏÖ´ÐÐÏÂÁîÒÔ¼°Ìí¼Ó»òɾ³ýÓÐȨ»á¼ûÄÚ²¿ÏµÍ³µÄÓû§¡£¡£¡£¡£ÐǰͿËÈ·ÈÏÁËÕâÒ»ÎÊÌⲢѸËÙ×÷·ÏÁ˸ÃÃÜÔ¿¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95826/security/starbucks-api-key-exposed-online.html