ÿÖÜÉý¼¶Í¨¸æ-2022-01-11

Ðû²¼Ê±¼ä 2022-01-12

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_´úÂëÖ´ÐÐ_Dubbo·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-30179]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃDubboµÄGenericFilter½Ó¿ÚµÄ·´ÐòÁл¯Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³ÌЧÀÍŲÓüƻ®£¬£¬£¬£¬£¬£¬ÒÔ¼°SOAЧÀÍÖÎÀí¼Æ»®¡£¡£¡£ApacheDubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇ󡣡£¡£

¸üÐÂʱ¼ä£º

20220111

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ApiSix_í§Òâ´úÂëÖ´ÐÐ[CVE-2021-45232][CNNVD-202112-2629]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÔÚ2.10.1֮ǰµÄApacheAPISIXDashboardÖУ¬£¬£¬£¬£¬£¬ManagerAPIʹÓÃÁ½¸ö¿ò¼Ü²¢ÔÚ»ù´¡ÉÏÒýÈë`droplet`ºÍ`gin`Á½¸ö¿ò¼Ü£¬£¬£¬£¬£¬£¬¿ª·¢ËùÓÐAPIºÍÈÏÖ¤ÖÐÐļþ»ùÓÚ¿ò¼Ü`droplet`£¬£¬£¬£¬£¬£¬µ«²¿·ÖAPIÖ±½ÓʹÓýӿÚ`gin`¿ò¼Üδ¾ÙÐÐdropletÈÏÖ¤£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÒÔδÊÚȨ»á¼û¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬£¬£¬ÔÚÌØ±ðµÄ·¾¶Ï£¬£¬£¬£¬£¬£¬±£´æ±»¹¥»÷ÕßÖ´ÐÐí§Òâlua´úÂëµÄΣº¦¡£¡£¡£

¸üÐÂʱ¼ä£º

20220111


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_FastjsonÎó²î_hex±àÂëʹÓÃ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬£¬£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬£¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬£¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£fastjson¿É½ÓÊܲ¢ÆÊÎöhex±àÂëÄÚÈÝ£¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉʹÓÃhex±àÂëÈÆ¹ý¼ì²â×°±¸¡£¡£¡£

¸üÐÂʱ¼ä£º

20220111