当前位置:网站首页>Atlassian Confluence 远程代码执行漏洞(CVE-2022-26134漏洞分析与防护
Atlassian Confluence 远程代码执行漏洞(CVE-2022-26134漏洞分析与防护
2022-06-25 06:41:00 【千里ZLP】
一、漏洞描述
Confluence是一款专业的企业知识管理与协同软件,常用于企业wiki的构建,支持团队成员间开展信息共享、文档协作、集体讨论和信息推送等工作,具有较为便捷的编辑和站点管理特性。该软件由Atlassian公司负责开发和维护。
2022年6月3日,国家信息安全漏洞共享平台(CNVD)收录了Confluence远程代码执行漏洞(CNVD-2022-43094,对应CVE-2022-26134)。在Atlassian Confluence Server and Data Center上存在OGNL注入漏洞,恶意攻击者可以利用该漏洞在目标Atlassian Confluence Server and Data Center服务器上注入恶意ONGL表达式,造成远程执行代码并部署WebShell。
目前已发现在野利用,如Kinsing木马团队已利用该漏洞进行攻击拓展,漏洞利用脚本已经放出,受影响单位尽快升级。
参考至:https://www.cnvd.org.cn/webinfo/show/7756
二、问题分析
所有未打补丁的版本均受到影响,请尽快升级至以下版本
- 7.4.17
边栏推荐
- Three years of continuous decline in revenue, Tiandi No. 1 is trapped in vinegar drinks
- 一“石”二“鸟”,PCA有效改善机载LiDAR林下地面点部分缺失的困局
- [Batch dos - cmd Command - Summary and Summary] - cmd extension Command, extension Function (CMD / E: on, CMD / E: off)
- Home environment monitoring system design (PC version) (mobile app version to be determined)
- Shell tips (134) simple keyboard input recorder
- useMemo模拟useCallback
- Vscode official configuration synchronization scheme
- Usememo simulation usecallback
- 神经网络与深度学习-3- 机器学习简单示例-PyTorch
- Notes: [open class] neural network and deep learning -- tensorflow2.0 actual combat [Chinese course]
猜你喜欢
One "stone" and two "birds", PCA can effectively improve the dilemma of missing some ground points under the airborne lidar forest
Sichuan Tuwei ca-if1051 can transceiver has passed aec-q100 grade 1 certification
NPM install reports an error: gyp err! configure error
Four software 2021-10-14 suitable for beginners to draw PCB
[batch dos-cmd command - summary and summary] - application startup and call, service and process operation commands (start, call, and)
STL教程4-输入输出流和对象序列化
图扑软件数字孪生 3D 风电场,智慧风电之海上风电
Manufacturing process of PCB 2021-10-11
Misunderstanding of switching triode
MySQL facet 01
随机推荐
C reads XML on the web
Kinsing双平台挖矿家族病毒分析
MySQL facet 01
Chuantu microelectronics high speed and high performance rs-485/422 transceiver series
图扑软件数字孪生 3D 风电场,智慧风电之海上风电
What is the difference between norflash and nandflash
C# 读取web上的xml
Leetcode daily question - 515 Find the maximum value in each tree row
基于激光雷达的林业调查常用术语及含义锦集
Ca-is1200u current detection isolation amplifier has been delivered in batch
Cglib dynamic proxy
WinForm implementation window is always at the top level
AttributeError: ‘Upsample‘ object has no attribute ‘recompute_scale_factor‘
Application of point cloud intelligent drawing in intelligent construction site
Chuantu microelectronics breaks through the high-end isolator analog chip market with ca-is3062w
基于地面点稀少的LiDAR点云的茂密森林蓄积量估算
One "stone" and two "birds", PCA can effectively improve the dilemma of missing some ground points under the airborne lidar forest
AttributeError: ‘Upsample‘ object has no attribute ‘recompute_ scale_ factor‘
The method of judging whether triode can amplify AC signal
如何用svn新建属于自己的分支