68

Confluence 未授权 RCE (CVE-2019-3396) 漏洞分析-创宇程序员的博客

 5 years ago
source link: https://blog.51cto.com/14126565/2376426
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
作者:Badcode@知道创宇404实验室时间:2019年4月8日看到官方发布了预警,于是开始了漏洞应急。漏洞描述中指出ConfluenceServer与ConfluenceDataCenter中的WidgetConnector存在服务端模板注入漏洞,***者能利用此漏洞能够实现目录穿越与远程代码执行。确认漏洞点是WidgetConnector,下载最新版的比对补丁,发现在com\atlassian

About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK