ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ01ÖÜ

Ðû²¼Ê±¼ä 2020-01-06

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê12ÔÂ30ÈÕÖÁ2020Äê01ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î50¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Solr VelocityÄ£°å´úÂë×¢ÈëÎó²î; Tencent WeChatÓû§ÃûÏÂÁî×¢ÈëÎó²î£»£»ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´ÐÐÎó²î£»£»Nagios XI schedulereport.php SHELLÏÂÁî×¢ÈëÎó²î£»£»Cisco Data Center Network Manager SOAP API OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇNagios XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-20197£©£»£»ÃÀ·¨ÔºÊÚȨ΢Èí½ÓÊܳ¯ÏÊAPT37¿ØÖƵÄ50¸öÓòÃû£»£»ÎïÁªÍø¹©Ó¦ÉÌWyzeÒâÍâй¶Լ240Íò¿Í»§ÐÅÏ¢£»£»°®¶ûÀ¼Õþ¸®Ðû²¼2019-2024¹ú¼ÒÍøÂçÇå¾²Õ½ÂÔ£»£»ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬£¬£¬£¬£¬£¬¿É»á¼ûÄÚ²¿ÏµÍ³¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache Solr VelocityÄ£°å´úÂë×¢ÈëÎó²î


Apache Solr VelocityÄ£°åVelocityResponseWriter±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬Í¨¹ý½ç˵һ¸ö½«¸ÃÉèÖÃÉèÖÃΪ "true" µÄÏìӦдÈëÆ÷À´ÆôÓà "parms .resource.loader. loader¡±£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://issues.apache.org/jira/browse/SOLR-13971


2. Tencent WeChatÓû§ÃûÏÂÁî×¢ÈëÎó²î


Tencent WeChatÆÊÎöusernames±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-19-1035/


3. ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´ÐÐÎó²î


ALE Alcatel-Lucent OmnivistaʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔSYSTEMÓû§Éí·ÝÖ´ÐдúÂë¡£¡£¡£¡£¡£

https://packetstormsecurity.com/files/155595/Alcatel-Lucent-Omnivista-8770-Remote-Code-Execution.html


4. Nagios XI schedulereport.php SHELLÏÂÁî×¢ÈëÎó²î


Nagios XI schedulereport.php±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâSHELLÏÂÁî¡£¡£¡£¡£¡£

https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html


5. Cisco Data Center Network Manager SOAP API OSÏÂÁî×¢ÈëÎó²î


Cisco Data Center Network Manager SOAP API±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿É×¢Èëí§ÒâOSÏÂÁî²¢Ö´ÐС£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Nagios XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-20197£©


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¼Æ»®¡£¡£¡£¡£¡£¸Ã¼Æ»®Ö§³Ö¶ÔÓ¦Óá¢Ð§ÀÍ¡¢²Ù×÷ϵͳµÈ¾ÙÐÐ¼à¿ØºÍÔ¤¾¯¡£¡£¡£¡£¡£@Cody SixteenÔÚTwitterÐû²¼ÁËÓйØNagios XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-20197£©µÄÏà¹ØÐÅÏ¢£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËNagios XI 5.6.9°æ±¾£¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊý£¬£¬£¬£¬£¬£¬ÔÚWebЧÀÍÆ÷Óû§ÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£¡£ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534


2¡¢ÃÀ·¨ÔºÊÚȨ΢Èí½ÓÊܳ¯ÏÊAPT37¿ØÖƵÄ50¸öÓòÃû


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


΢ÈíÀֳɽÓÊÜÁËÓɳ¯ÏʺڿÍ×éÖ¯APT37¿ØÖƵÄ50¸öÓòÃû£¬£¬£¬£¬£¬£¬ÕâЩÓòÃû±»¸Ã×éÖ¯ÓÃÀ´Ìá³«ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬°üÀ¨·¢ËÍ´¹ÂÚÓʼþºÍÍйܴ¹ÂÚÒ³ÃæµÈ¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖÆäÊý×Ö·¸·¨²¿·Ö£¨DCU£©ºÍÍþвÇ鱨ÖÐÐÄ£¨MSTIC£©ÒѾ­¼àÊÓAPT37³¤´ïÊýÔµÄʱ¼ä£¬£¬£¬£¬£¬£¬²¢ÓÚ12ÔÂ18ÈÕÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¸Ã×éÖ¯ÌáÆðËßËÏ¡£¡£¡£¡£¡£¸Ã·¨ÔºÊÚÓè΢ÈíȨÏÞÒÔ½ÓÊÜAPT37ÔÚ·¸·¨»î¶¯ÖÐʹÓõÄ50¸öÓòÃû¡£¡£¡£¡£¡£Î¢Èí¸ß¹ÜÌåÏÖ¸Ã×éÖ¯µÄ´ó´ó¶¼Ä¿µÄ¶¼Î»ÓÚÃÀ¹ú¡¢ÈÕ±¾ÒÔ¼°º«¹ú¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-takes-down-50-domains-operated-by-north-korean-hackers/


3¡¢ÎïÁªÍø¹©Ó¦ÉÌWyzeÒâÍâй¶Լ240Íò¿Í»§ÐÅÏ¢


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÎïÁªÍø¹©Ó¦ÉÌWyzeÈ·ÈÏÆäÒ»¸öElasticsearchЧÀÍÆ÷й¶ÁËÔ¼240ÍòÓû§µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â²¢²»ÊÇÉú²úϵͳ£¬£¬£¬£¬£¬£¬µ«´æ´¢ÁËÓÐÓõÄÓû§Êý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨ÓÃÓÚ½¨ÉèWyzeÕÊ»§µÄµç×ÓÓʼþµØµã¡¢·ÖÅɸøÆäWyzeÇå¾²ÉãÏñ»úµÄÓû§êdzơ¢WiFiÍøÂç±êʶ·ûSSIDÒÔ¼°2.4ÍòÓû§µÄAlexaÁîÅÆµÈ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ12ÔÂ4ÈÕ±»¹ýʧµØÌ»Â¶ÔÚ¹«ÍøÉÏ£¬£¬£¬£¬£¬£¬Çå¾²¹«Ë¾Twelve SecurityÓÚ12ÔÂ26ÈÕ·¢Ã÷Á˸ÃÊý¾Ý¿â²¢Í¨ÖªÁËWyze£¬£¬£¬£¬£¬£¬WyzeËæºó¶ÔÊý¾Ý¿â¾ÙÐÐÁ˱£»£»¤¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/iot-vendor-wyze-confirms-server-leak/


4¡¢°®¶ûÀ¼Õþ¸®Ðû²¼2019-2024¹ú¼ÒÍøÂçÇå¾²Õ½ÂÔ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


°®¶ûÀ¼Õþ¸®Ðû²¼ÁË¡¶2019-2024¹ú¼ÒÍøÂçÇå¾²Õ½ÂÔ¡·£¬£¬£¬£¬£¬£¬ÕâÊǸùúÓÚ2015ÄêÐû²¼µÄÊ׸öÇå¾²Õ½ÂԵĸüа汾¡£¡£¡£¡£¡£¸ÃÕ½ÂÔ±¨¸æ¸ÅÊöÁËÕþ¸®½«ÔõÑù¼ÌÐøÔö½ø¸Ã¹úÅÌËã»úÍøÂçºÍÏà¹Ø»ù´¡ÉèÊ©µÄÇå¾²¡£¡£¡£¡£¡£±¨¸æÖÐÆÊÎöÁËÕþ¸®¶ÔÇå¾²ºÍ¿É¿¿µÄÍøÂç¿Õ¼äµÄÔ¸¾°ÒÔ¼°½«½ÓÄɵÄÐж¯£¬£¬£¬£¬£¬£¬°üÀ¨¼ÌÐøÌá¸ßÒªº¦»ù´¡¼Ü¹¹ºÍ¹«¹²Ð§ÀÍÖеÄÍøÂ絯ÐÔ£»£»Ìá¸ßÆóÒµºÍ¹«Ãñ¶ÔÍøÂçÇå¾²Ö÷ÒªÐÔµÄÊìϤ£»£»Í¨¹ýÓë½ÌÓýϵͳ¡¢ÐÐÒµºÍѧÊõ½çµÄÏàÖú£¬£¬£¬£¬£¬£¬½øÒ»²½Éú³¤È«Éç»áµÄÍøÂçÇå¾²ÎÄ»¯£»£»¼ÌÐøÀο¿°®¶ûÀ¼×÷ΪÊÖÒÕºÍÐÅÏ¢Çå¾²ÖÐÐĵÄÈ«ÇòÉùÓþ£¬£¬£¬£¬£¬£¬²¢×ÊÖúÔö½ø°®¶ûÀ¼³ÉΪICTÆóÒµµÄÊ×Ñ¡ËùÔÚ¡£¡£¡£¡£¡£¸Ã±¨¸æ»¹±Þ²ß¾ÙÐÐË¢ÐÂÒÔ±£»£»¤Òªº¦»ù´¡¼Ü¹¹ÃâÊÜÖØ´óÍøÂçÍþвµÄÓ°Ï죬£¬£¬£¬£¬£¬Í¬Ê±»¹ÖÒÑÔ³ÆÍâ¹ú¿ÉÄÜ»á¸ÉÔ¤°®¶ûÀ¼µÄÑ¡¾Ù¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95825/laws-and-regulations/irish-national-cyber-security-strategy.html


5¡¢ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬£¬£¬£¬£¬£¬¿É»á¼ûÄÚ²¿ÏµÍ³


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ç徲ר¼ÒVinoth KumarÔÚÒ»¸ö¹ûÕæ¿ÉÓõÄGithub´æ´¢¿âÖз¢Ã÷ÐǰͿ˵ÄÒ»¸öAPIÃÜÔ¿ÔÚÏß̻¶£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÃÜÔ¿À´»á¼û¹«Ë¾µÄÄÚ²¿ÏµÍ³²¢¸Ä¶¯ÊÚȨÓû§ÁÐ±í¡£¡£¡£¡£¡£¸ÃÃÜÔ¿¿ÉÓÃÓÚ»á¼ûÐǰͿËJumpCloud API£¬£¬£¬£¬£¬£¬JumpCloudÊÇÒ»¸öActive DirectoryÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬£¬ÌṩÓû§ÖÎÀí¡¢WebÓ¦ÓóÌÐòµ¥µãµÇ¼£¨SSO£©»á¼û¿ØÖƺÍÇáÐÍĿ¼»á¼ûЭÒ飨LDAP£©Ð§ÀÍ¡£¡£¡£¡£¡£Kumar»¹ÌṩÁ˸ÃÎÊÌâµÄPoC´úÂ룬£¬£¬£¬£¬£¬ÑÝʾÁËÔõÑùÁгöϵͳºÍÓû§¡¢¿ØÖÆAWSÕÊ»§¡¢ÔÚϵͳÉÏÖ´ÐÐÏÂÁîÒÔ¼°Ìí¼Ó»òɾ³ýÓÐȨ»á¼ûÄÚ²¿ÏµÍ³µÄÓû§¡£¡£¡£¡£¡£ÐǰͿËÈ·ÈÏÁËÕâÒ»ÎÊÌⲢѸËÙ×÷·ÏÁ˸ÃÃÜÔ¿¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95826/security/starbucks-api-key-exposed-online.html