ConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-04-09

Îó²î±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-3395 £¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2019-3396 £¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º9.8



Ó°Ïì°æ±¾


²úÆ·


Confluence Server

Confluence Data Center


°æ±¾


ËùÓÐ1.xx £¬£¬£¬£¬ £¬£¬2.xx £¬£¬£¬£¬ £¬£¬3.xx £¬£¬£¬£¬ £¬£¬4.xxºÍ5.xx°æ±¾
ËùÓÐ6.0.x £¬£¬£¬£¬ £¬£¬6.1.x £¬£¬£¬£¬ £¬£¬6.2.x £¬£¬£¬£¬ £¬£¬6.3.x £¬£¬£¬£¬ £¬£¬6.4.xºÍ6.5.x°æ±¾
6.6.12֮ǰµÄËùÓÐ6.6.x°æ±¾
ËùÓÐ6.7.x £¬£¬£¬£¬ £¬£¬6.8.x £¬£¬£¬£¬ £¬£¬6.9.x £¬£¬£¬£¬ £¬£¬6.10.xºÍ6.11.x°æ±¾
6.12.3֮ǰµÄËùÓÐ6.12.x°æ±¾
6.13.3֮ǰµÄËùÓÐ6.13.x°æ±¾

6.14.2֮ǰµÄËùÓÐ6.14.x°æ±¾


×é¼þ


widgetconnector<=3.1.3



Îó²î¸ÅÊö



ConfluenceÊÇÈ«ÇòÊ¢ÐеÄWikiϵͳ £¬£¬£¬£¬ £¬£¬ÓªÒµº­¸Ç100¶à¸ö¹ú¼Ò»òµØÇø¡£¡£¡£¡£¡£¡£¡£IBM¡¢SAPµÈÖ®×ÅÃûÆóÒµ¶¼Ê¹ÓÃConfluence¹¹½¨ÆóÒµWiki²¢Ïò¹«ÖÚ¿ª·Å¡£¡£¡£¡£¡£¡£¡£


CVE-2019-3395:Atlassian¹«Ë¾µÄConfluence ServerºÍData Center²úÆ·ÖеÄWebDAV¶Ëµã±£´æÐ§ÀÍÆ÷¶ËÇëÇóαÔìÎó²î¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÒÀ¸½Confluence Server»òData CenterʵÀý·¢ËÍí§ÒâHTTPºÍWebDAVÇëÇ󡣡£¡£¡£¡£¡£¡£


CVE-2019-3396:Atlassian¹«Ë¾µÄConfluence ServerºÍData Center²úÆ·ÖÐʹÓõÄwidgetconnecter×é¼þ(°æ±¾<=3.1.3)Öб£´æÐ§ÀÍÆ÷¶ËÄ£°å×¢Èë(SSTI)Îó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄHTTPÇëÇó²ÎÊý £¬£¬£¬£¬ £¬£¬¶ÔÄ¿µÄϵͳʵÑ飨·¾¶±éÀú¡¢í§ÒâÎļþ¶ÁÈ¡ÒÔ¼°Ô¶³ÌÏÂÁîÖ´ÐУ©¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸ÃÀ๥»÷¿Éµ¼ÖÂÄ¿µÄϵͳÖеÄÃô¸ÐÐÅÏ¢±»Ð¹Â¶ £¬£¬£¬£¬ £¬£¬ÒÔ¼°Ö´Ðй¥»÷Õ߽ṹµÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£


¾Ýͳ¼Æ £¬£¬£¬£¬ £¬£¬È«Çò¹²ÓÐ78158¸öConfluence¿ª·ÅЧÀÍ £¬£¬£¬£¬ £¬£¬ÃÀ¹ú×î¶à £¬£¬£¬£¬ £¬£¬ÓÐ23002¸öЧÀÍ £¬£¬£¬£¬ £¬£¬µÂ¹úµÚ¶þ £¬£¬£¬£¬ £¬£¬ÓÐ14385¸ö¿ª·ÅЧÀÍ £¬£¬£¬£¬ £¬£¬ÖйúµÚÈý £¬£¬£¬£¬ £¬£¬ÓÐ7281¸öЧÀÍ £¬£¬£¬£¬ £¬£¬°Ä´óÀûÑǵÚËÄ £¬£¬£¬£¬ £¬£¬ÓÐ7959¸öЧÀÍ £¬£¬£¬£¬ £¬£¬°®¶ûÀ¼µÚÎå £¬£¬£¬£¬ £¬£¬ÓÐ2893¸öЧÀÍ¡£¡£¡£¡£¡£¡£¡£ÌìϵĿª·ÅµÄConfluenceЧÀÍÖÐ £¬£¬£¬£¬ £¬£¬Õã½­×î¶à £¬£¬£¬£¬ £¬£¬ÓÐ3040¸öЧÀÍ £¬£¬£¬£¬ £¬£¬±±¾©µÚ¶þ £¬£¬£¬£¬ £¬£¬ÓÐ1713¸öЧÀÍ £¬£¬£¬£¬ £¬£¬ÉϺ£µÚÈý £¬£¬£¬£¬ £¬£¬ÓÐ532¸öЧÀÍ £¬£¬£¬£¬ £¬£¬¹ã¶«µÚËÄ £¬£¬£¬£¬ £¬£¬ÓÐ525¸öЧÀÍ¡£¡£¡£¡£¡£¡£¡£



Îó²îʹÓÃ



ʹÓÃ_template²ÎÊýÁýÕÖVelocityäÖȾģ°å £¬£¬£¬£¬ £¬£¬Ê¹ÓÃfile:ЭÒé¿ÉÒÔ¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡(²»ÔÙÊÜÏÞÓÚclasspath)


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ͨ¹ý¸ÃÒªÁì¿ÉÒÔ¾ÙÐÐÍâµØÎļþ°üÀ¨ £¬£¬£¬£¬ £¬£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£


 ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾




ÐÞ¸´½¨Òé



ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î £¬£¬£¬£¬ £¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://jira.atlassian.com/browse/CONFSERVER-57974¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó



https://mp.weixin.qq.com/s/7PBKDJ7bjRJHtXUau-swNw
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201903-909
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201903-910
https://nvd.nist.gov/vuln/detail/CVE-2019-3396
https://nvd.nist.gov/vuln/detail/CVE-2019-3395