当前位置:网站首页>Atlassian Confluence 远程代码执行漏洞(CVE-2022-26134漏洞分析与防护
Atlassian Confluence 远程代码执行漏洞(CVE-2022-26134漏洞分析与防护
2022-06-25 06:41:00 【千里ZLP】
一、漏洞描述
Confluence是一款专业的企业知识管理与协同软件,常用于企业wiki的构建,支持团队成员间开展信息共享、文档协作、集体讨论和信息推送等工作,具有较为便捷的编辑和站点管理特性。该软件由Atlassian公司负责开发和维护。
2022年6月3日,国家信息安全漏洞共享平台(CNVD)收录了Confluence远程代码执行漏洞(CNVD-2022-43094,对应CVE-2022-26134)。在Atlassian Confluence Server and Data Center上存在OGNL注入漏洞,恶意攻击者可以利用该漏洞在目标Atlassian Confluence Server and Data Center服务器上注入恶意ONGL表达式,造成远程执行代码并部署WebShell。
目前已发现在野利用,如Kinsing木马团队已利用该漏洞进行攻击拓展,漏洞利用脚本已经放出,受影响单位尽快升级。
参考至:https://www.cnvd.org.cn/webinfo/show/7756
二、问题分析
所有未打补丁的版本均受到影响,请尽快升级至以下版本
- 7.4.17
边栏推荐
- OpenMP入门
- Ns32f103c8t6 can perfectly replace stm32f103c8t6
- IAR compiler flashback
- 【批處理DOS-CMD命令-匯總和小結】-cmd擴展命令、擴展功能(cmd /e:on、cmd /e:off)
- Home environment monitoring system design (PC version) (mobile app version to be determined)
- 权限、认证系统相关名词概念
- Chuantu microelectronics high speed and high performance rs-485/422 transceiver series
- 基于地面点稀少的LiDAR点云的茂密森林蓄积量估算
- OAuth 2.0一键登录那些事
- 栅格地图(occupancy grid map)构建
猜你喜欢

PI Ziheng embedded: This paper introduces the multi-channel link mode of i.mxrt timer pit and its application in coremark Test Engineering

Research on 3D model retrieval method based on two channel attention residual network - Zhou Jie - paper notes

搞清信息化是什么,让企业转型升级走上正确的道路
![[batch dos-cmd command - summary and summary] - commands related to Internet access and network communication (Ping, Telnet, NSLOOKUP, ARP, tracert, ipconfig)](/img/9b/283d99adf10262c356d1a87ce01bc0.png)
[batch dos-cmd command - summary and summary] - commands related to Internet access and network communication (Ping, Telnet, NSLOOKUP, ARP, tracert, ipconfig)

“空间转换”显著提升陡崖点云的地面点提取质量

OpenCV每日函数 结构分析和形状描述符(8) fitLine函数 拟合直线

基于地面点稀少的LiDAR点云的茂密森林蓄积量估算

Application of point cloud intelligent drawing in intelligent construction site

shell小技巧(一百三十四)简单的键盘输入记录器

Debian introduction
随机推荐
Bicubic difference
realsense d455 semantic_slam实现语义八叉树建图
Construction of occupancy grid map
Application of point cloud intelligent drawing in intelligent construction site
[batch dos-cmd command - summary and summary] - commands related to Internet access and network communication (Ping, Telnet, NSLOOKUP, ARP, tracert, ipconfig)
Modular programming of wireless transmission module nRF905 controlled by single chip microcomputer
The method of judging whether triode can amplify AC signal
Accès à la boîte aux lettres du nom de domaine Lead à l'étranger
(tool class) use SecureCRT as the communication medium
JDBC-DAO层实现
Elk + filebeat log parsing, log warehousing optimization, logstash filter configuration attribute
VectorDraw Developer Framework 10.10
Sichuan earth microelectronics 8-channel isolated digital input receiver
Estimation of dense forest volume based on LIDAR point cloud with few ground points
Manufacturing process of PCB 2021-10-11
2265. 统计值等于子树平均值的节点数
China Mobile MCU product information
WinForm实现窗口始终在顶层
数据可视化没有重点怎么办?
ts环境搭建