ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ01ÖÜ

Ðû²¼Ê±¼ä 2020-01-06

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê12ÔÂ30ÈÕÖÁ2020Äê01ÔÂ05ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Solr VelocityÄ£°å´úÂë×¢È멶´; Tencent WeChatÓû§ÃûÃüÁî×¢È멶´£»ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´ÐЩ¶´£»Nagios XI schedulereport.php SHELLÃüÁî×¢È멶´£»Cisco Data Center Network Manager SOAP API OSÃüÁî×¢È멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇNagios XIÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¨CVE-2019-20197£©£»ÃÀ·¨ÔºÊÚȨ΢Èí½Ó¹Ü³¯ÏÊAPT37¿ØÖƵÄ50¸öÓòÃû£»ÎïÁªÍø¹©Ó¦ÉÌWyzeÒâÍâй¶Լ240Íò¿Í»§ÐÅÏ¢£»°®¶ûÀ¼Õþ¸®Ðû²¼2019-2024¹ú¼ÒÍøÂçÄþ¾²Õ½ÂÔ£»ÐÇ°Í¿ËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬¿É·ÃÎÊÄÚ²¿ÏµÍ³¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Apache Solr VelocityÄ£°å´úÂë×¢È멶´


Apache Solr VelocityÄ£°åVelocityResponseWriter´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Í¨¹ý½ç˵һ¸ö½«¸ÃÅäÖÃÉèÖÃΪ "true" µÄÏìӦдÈëÆ÷À´ÆôÓà "parms .resource.loader. loader¡±£¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£

https://issues.apache.org/jira/browse/SOLR-13971


2. Tencent WeChatÓû§ÃûÃüÁî×¢È멶´


Tencent WeChat½âÎöusernames´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-19-1035/


3. ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´ÐЩ¶´


ALE Alcatel-Lucent OmnivistaʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔSYSTEMÓû§Éí·ÝÖ´ÐдúÂë¡£

https://packetstormsecurity.com/files/155595/Alcatel-Lucent-Omnivista-8770-Remote-Code-Execution.html


4. Nagios XI schedulereport.php SHELLÃüÁî×¢È멶´


Nagios XI schedulereport.php´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâSHELLÃüÁî¡£

https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html


5. Cisco Data Center Network Manager SOAP API OSÃüÁî×¢È멶´


Cisco Data Center Network Manager SOAP API´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâOSÃüÁî²¢Ö´ÐС£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject


>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Nagios XIÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¨CVE-2019-20197£©


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö·½°¸¡£¸Ã·½°¸Ö§³Ö¶ÔÓ¦ÓᢷþÎñ¡¢²Ù×÷ϵͳµÈ½øÐмà¿ØºÍÔ¤¾¯¡£@Cody SixteenÔÚTwitterÐû²¼ÁËÓйØNagios XIÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¨CVE-2019-20197£©µÄÏà¹ØÐÅÏ¢£¬¸Ã©¶´Ó°ÏìÁËNagios XI 5.6.9°æ±¾£¬¾­¹ýÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊý£¬ÔÚWeb·þÎñÆ÷Óû§ÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ²Ù×÷ϵͳÃüÁĿǰ³§ÉÌÔÝδÐû²¼ÐÞ¸´´ëÊ©¡£


Ô­ÎÄÁ´½Ó£º

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534


2¡¢ÃÀ·¨ÔºÊÚȨ΢Èí½Ó¹Ü³¯ÏÊAPT37¿ØÖƵÄ50¸öÓòÃû


×ðÁú¶¶È¦ - Ϊdu¶øÉú


΢ÈíÀֳɽӹÜÁËÓɳ¯ÏʺڿÍ×éÖ¯APT37¿ØÖƵÄ50¸öÓòÃû£¬ÕâЩÓòÃû±»¸Ã×éÖ¯ÓÃÀ´ÌᳫÍøÂç¹¥»÷£¬°üÂÞ·¢Ë͵öÓãÓʼþºÍÍйܵöÓãÒ³ÃæµÈ¡£Î¢ÈíÌåÏÖÆäÊý×Ö·¸×ﲿÃÅ£¨DCU£©ºÍÍþвÇ鱨ÖÐÐÄ£¨MSTIC£©ÒѾ­¼àÊÓAPT37³¤´ïÊýÔµÄʱ¼ä£¬²¢ÓÚ12ÔÂ18ÈÕÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¸Ã×éÖ¯ÌáÆðËßËÏ¡£¸Ã·¨ÔºÊÚÓè΢ÈíȨÏÞÒÔ½Ó¹ÜAPT37ÔÚ·¸×ï»î¶¯ÖÐʹÓõÄ50¸öÓòÃû¡£Î¢Èí¸ß¹ÜÌåÏÖ¸Ã×éÖ¯µÄ´ó¶àÊýÄ¿±ê¶¼Î»ÓÚÃÀ¹ú¡¢ÈÕ±¾ÒÔ¼°º«¹ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-takes-down-50-domains-operated-by-north-korean-hackers/


3¡¢ÎïÁªÍø¹©Ó¦ÉÌWyzeÒâÍâй¶Լ240Íò¿Í»§ÐÅÏ¢


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ÎïÁªÍø¹©Ó¦ÉÌWyzeÈ·ÈÏÆäÒ»¸öElasticsearch·þÎñÆ÷й¶ÁËÔ¼240ÍòÓû§µÄÏêϸÐÅÏ¢¡£¸ÃÊý¾Ý¿â²¢²»ÊÇÉú²úϵͳ£¬µ«´æ´¢ÁËÓÐЧµÄÓû§Êý¾Ý£¬°üÂÞÓÃÓÚ´´½¨WyzeÕÊ»§µÄµç×ÓÓʼþµØÖ·¡¢·ÖÅä¸øÆäWyzeÄþ¾²ÉãÏñ»úµÄÓû§êdzơ¢WiFiÍøÂç±êʶ·ûSSIDÒÔ¼°2.4ÍòÓû§µÄAlexaÁîÅƵÈ¡£¸ÃÊý¾Ý¿âÓÚ12ÔÂ4ÈÕ±»´íÎóµØ̻¶ÔÚ¹«ÍøÉÏ£¬Äþ¾²¹«Ë¾Twelve SecurityÓÚ12ÔÂ26ÈÕ·¢ÏÖÁ˸ÃÊý¾Ý¿â²¢Í¨ÖªÁËWyze£¬WyzeËæºó¶ÔÊý¾Ý¿â½øÐÐÁ˱£»¤¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/iot-vendor-wyze-confirms-server-leak/


4¡¢°®¶ûÀ¼Õþ¸®Ðû²¼2019-2024¹ú¼ÒÍøÂçÄþ¾²Õ½ÂÔ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


°®¶ûÀ¼Õþ¸®Ðû²¼ÁË¡¶2019-2024¹ú¼ÒÍøÂçÄþ¾²Õ½ÂÔ¡·£¬ÕâÊǸùúÓÚ2015ÄêÐû²¼µÄÊ׸öÄþ¾²Õ½ÂԵĸüа汾¡£¸ÃÕ½ÂÔ³ÂË߸ÅÊöÁËÕþ¸®½«ÈçºÎ¼ÌÐø´Ù½ø¸Ã¹ú¼ÆËã»úÍøÂçºÍÏà¹Ø»ù´¡ÉèÊ©µÄÄþ¾²¡£³ÂËßÖзÖÎöÁËÕþ¸®¶ÔÄþ¾²ºÍ¿É¿¿µÄÍøÂç¿Õ¼äµÄÔ¸¾°ÒÔ¼°½«½ÓÄɵÄÐж¯£¬°üÂÞ¼ÌÐøÌá¸ßÒªº¦»ù´¡¼Ü¹¹ºÍ¹«¹²·þÎñÖеÄÍøÂ絯ÐÔ£»Ìá¸ßÆóÒµºÍ¹«Ãñ¶ÔÍøÂçÄþ¾²ÖØÒªÐÔµÄÈÏʶ£»Í¨¹ýÓë½ÌÓýϵͳ¡¢ÐÐÒµºÍѧÊõ½çµÄºÏ×÷£¬½øÒ»²½Éú³¤È«Éç»áµÄÍøÂçÄþ¾²ÎÄ»¯£»¼ÌÐøÀι̰®¶ûÀ¼×÷Ϊ¼¼ÊõºÍÐÅÏ¢Äþ¾²ÖÐÐĵÄÈ«ÇòÉùÓþ£¬²¢×ÊÖú´Ù½ø°®¶ûÀ¼³ÉΪICTÆóÒµµÄÊ×Ñ¡ËùÔÚ¡£¸Ã³ÂËß»¹¶Ø´Ù½øÐиïÐÂÒÔ±£»¤Òªº¦»ù´¡¼Ü¹¹ÃâÊÜÖØ´óÍøÂçÍþвµÄÓ°Ï죬ͬʱ»¹¾¯¸æ³ÆÍâ¹ú¿ÉÄÜ»á¸ÉÔ¤°®¶ûÀ¼µÄÑ¡¾Ù¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95825/laws-and-regulations/irish-national-cyber-security-strategy.html


5¡¢ÐÇ°Í¿ËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬¿É·ÃÎÊÄÚ²¿ÏµÍ³


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Äþ¾²×¨¼ÒVinoth KumarÔÚÒ»¸ö¹ûÈ»¿ÉÓõÄGithub´æ´¢¿âÖз¢ÏÖÐǰͿ˵ÄÒ»¸öAPIÃÜÔ¿ÔÚÏß̻¶£¬¹¥»÷Õß¿ÉÒÔÀûÓøÃÃÜÔ¿À´·ÃÎʹ«Ë¾µÄÄÚ²¿ÏµÍ³²¢¸Ä¶¯ÊÚȨÓû§Áбí¡£¸ÃÃÜÔ¿¿ÉÓÃÓÚ·ÃÎÊÐÇ°Í¿ËJumpCloud API£¬JumpCloudÊÇÒ»¸öActive Directory¹ÜÀíƽ̨£¬ÌṩÓû§¹ÜÀí¡¢WebÓ¦Ó÷¨Ê½µ¥µãµÇ¼£¨SSO£©·ÃÎÊ¿ØÖƺÍÇáÐÍĿ¼·ÃÎÊЭÒ飨LDAP£©·þÎñ¡£Kumar»¹ÌṩÁ˸ÃÎÊÌâµÄPoC´úÂ룬ÑÝʾÁËÈçºÎÁгöϵͳºÍÓû§¡¢¿ØÖÆAWSÕÊ»§¡¢ÔÚϵͳÉÏÖ´ÐÐÃüÁîÒÔ¼°Ìí¼Ó»òɾ³ýÓÐȨ·ÃÎÊÄÚ²¿ÏµÍ³µÄÓû§¡£ÐÇ°Í¿ËÈ·ÈÏÁËÕâÒ»ÎÊÌⲢѸËÙÈ¡ÏûÁ˸ÃÃÜÔ¿¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95826/security/starbucks-api-key-exposed-online.html