ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ21ÖÜ

Ðû²¼Ê±¼ä 2020-05-26

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê05ÔÂ18ÈÕÖÁ05ÔÂ24ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´60¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇCisco Unified Contact Center Express·´ÐòÁл¯´úÂëÖ´ÐЩ¶´; Apache Tomcat session·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»Google Chrome reader modeÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Emerson Electric OpenEnterprisÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Centreon main.get.php OSÃüÁî×¢È멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇiPhoneÓʼþÓ¦ÓÃEdison Mail´æÔÚ©¶´ £¬Ð¹Â¶Óû§ÐÅÏ¢£»°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿ÃÅÒµÎñÖжÏ£»Daimler 580¶à¸öGit´æ´¢¿â̻¶ £¬¼²³Û×é¼þOLUÔ´´úÂëй¶£»AdobeÐû²¼½ô¼±´øÍâ¸üР£¬ÐÞ¸´Ô¶³ÌÖ´ÐдúÂ멶´£»ºÚ¿Í͵ȡWishboneÖÐ4000ÍòÌõÓû§ÐÅÏ¢ £¬²¢ÔÚ°µÍø±ê¼Û³öÊÛ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Cisco Unified Contact Center Express·´ÐòÁл¯´úÂëÖ´ÐЩ¶´


Cisco Unified Contact Center Express JavaÔ¶³Ì¹ÜÀí½çÃæ´æÔÚ·´ÐòÁл¯Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔrootȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN


2. Apache Tomcat session·´ÐòÁл¯´úÂëÖ´ÐЩ¶´


Apache Tomcat´æÔÚÄþ¾²Â©¶´ £¬µ±Ê¹ÓÃtomcatʱ £¬Èç¹ûʹÓÃÁËtomcatÌṩµÄsession³Ö¾Ã»¯¹¦Ð§ £¬Èç¹û´æÔÚÎļþÉÏ´«¹¦Ð§ £¬¶ñÒâÇëÇóÕßͨ¹ýÒ»¸öÁ÷³Ì £¬½«ÄÜÌᳫһ¸ö¶ñÒâÇëÇóÔì³É·þÎñ¶ËÔ¶³ÌÃüÁîÖ´ÐС£

https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E


3. Google Chrome reader modeÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Google Chrome reader mode´æÔÚÊͷźóʹÓ鶴 £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html


4. Emerson Electric OpenEnterprisÔ¶³Ì´úÂëÖ´ÐЩ¶´


Emerson Electric OpenEnterpriseijͨÐÅ·þÎñ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.us-cert.gov/ics/advisories/icsa-20-140-02


5. Centreon main.get.php OSÃüÁî×¢È멶´


Centreon main.get.php´¦ÖÃRRDdatabase_status_path²ÎÊý´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿É×¢ÈëÈÎÒâOSÃüÁî¡£

https://github.com/centreon/centreon/pull/8467



> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢iPhoneÓʼþÓ¦ÓÃEdison Mail´æÔÚ©¶´ £¬Ð¹Â¶Óû§ÐÅÏ¢


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/iphone-email-app-bug-caused-users-messages-to-show-up-on-other-phones-530003.shtml


2¡¢°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿ÃÅÒµÎñÖжÏ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bluescope-reports-cyber-incident-affecting-australian-operations/


3¡¢Daimler 580¶à¸öGit´æ´¢¿â̻¶ £¬¼²³Û×é¼þOLUÔ´´úÂëй¶


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mercedes-benz-onboard-logic-unit-olu-source-code-leaks-online/


4¡¢AdobeÐû²¼½ô¼±´øÍâ¸üР£¬ÐÞ¸´Ô¶³ÌÖ´ÐдúÂ멶´


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-critical-out-of-band-security-update/


5¡¢ºÚ¿Í͵ȡWishboneÖÐ4000ÍòÌõÓû§ÐÅÏ¢ £¬²¢ÔÚ°µÍø±ê¼Û³öÊÛ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-selling-40-million-user-records-from-popular-wishbone-app/