ConfluenceÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-04-09·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-3396£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
²úÆ·
Confluence Data Center
°æ±¾
ËùÓÐ6.0.x£¬£¬£¬£¬£¬£¬£¬6.1.x£¬£¬£¬£¬£¬£¬£¬6.2.x£¬£¬£¬£¬£¬£¬£¬6.3.x£¬£¬£¬£¬£¬£¬£¬6.4.xºÍ6.5.x°æ±¾
6.6.12֮ǰµÄËùÓÐ6.6.x°æ±¾
ËùÓÐ6.7.x£¬£¬£¬£¬£¬£¬£¬6.8.x£¬£¬£¬£¬£¬£¬£¬6.9.x£¬£¬£¬£¬£¬£¬£¬6.10.xºÍ6.11.x°æ±¾
6.12.3֮ǰµÄËùÓÐ6.12.x°æ±¾
6.13.3֮ǰµÄËùÓÐ6.13.x°æ±¾
6.14.2֮ǰµÄËùÓÐ6.14.x°æ±¾
×é¼þ
widgetconnector<=3.1.3
·ì϶¸ÅÊö
ConfluenceÊÇÈ«ÇòÊ¢ÐеÄWikiϵͳ£¬£¬£¬£¬£¬£¬£¬ÒµÎñº¸Ç100¶à¸ö¹ú¶È»òµØÓò¡£¡£¡£¡£¡£IBM¡¢SAPµÈÖ®³ÛÃûÆóÒµ¶¼Ê¹ÓÃConfluence¹¹½¨ÆóÒµWiki²¢Ïò¹«¼ÒÊ¢¿ª¡£¡£¡£¡£¡£
CVE-2019-3395:Atlassian¹«Ë¾µÄConfluence ServerºÍData Center²úÆ·ÖеÄWebDAV¶Ëµã´æÔÚ·þÎñÆ÷¶ËÒªÇóαÔì·ì϶¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ƾ½èConfluence Server»òData CenterÊ·ý·¢ËÍËÁÒâHTTPºÍWebDAVÒªÇ󡣡£¡£¡£¡£
CVE-2019-3396:Atlassian¹«Ë¾µÄConfluence ServerºÍData Center²úÆ·ÖÐʹÓõÄwidgetconnecter×é¼þ(°æ±¾<=3.1.3)ÖдæÔÚ·þÎñÆ÷¶ËÄ£°å×¢Èë(SSTI)·ì϶¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄHTTPÒªÇó²ÎÊý£¬£¬£¬£¬£¬£¬£¬¶ÔÖ¸±êϵͳִÐУ¨õè¾¶±éÀú¡¢ËÁÒâÎļþ¶ÁÈ¡ÒÔ¼°Ô¶³ÌºÅÁîÖ´ÐУ©¹¥»÷¡£¡£¡£¡£¡£¸ÃÀ๥»÷¿Éµ¼ÖÂÖ¸±êϵͳÖеÄÃô¸ÐÐÅÏ¢±»Ð¹Â¶£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ö´Ðй¥»÷Õß»ú¹ØµÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£
¾Ýͳ¼Æ£¬£¬£¬£¬£¬£¬£¬È«Çò¹²ÓÐ78158¸öConfluenceÊ¢¿ª·þÎñ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú×î¶à£¬£¬£¬£¬£¬£¬£¬ÓÐ23002¸ö·þÎñ£¬£¬£¬£¬£¬£¬£¬µÂ¹úµÚ¶þ£¬£¬£¬£¬£¬£¬£¬ÓÐ14385¸öÊ¢¿ª·þÎñ£¬£¬£¬£¬£¬£¬£¬ÖйúµÚÈý£¬£¬£¬£¬£¬£¬£¬ÓÐ7281¸ö·þÎñ£¬£¬£¬£¬£¬£¬£¬°Ä´óÀûÑǵÚËÄ£¬£¬£¬£¬£¬£¬£¬ÓÐ7959¸ö·þÎñ£¬£¬£¬£¬£¬£¬£¬°®¶ûÀ¼µÚÎ壬£¬£¬£¬£¬£¬£¬ÓÐ2893¸ö·þÎñ¡£¡£¡£¡£¡£È«¹úµÄÊ¢¿ªµÄConfluence·þÎñÖУ¬£¬£¬£¬£¬£¬£¬Õã½×î¶à£¬£¬£¬£¬£¬£¬£¬ÓÐ3040¸ö·þÎñ£¬£¬£¬£¬£¬£¬£¬±±¾©µÚ¶þ£¬£¬£¬£¬£¬£¬£¬ÓÐ1713¸ö·þÎñ£¬£¬£¬£¬£¬£¬£¬ÉϺ£µÚÈý£¬£¬£¬£¬£¬£¬£¬ÓÐ532¸ö·þÎñ£¬£¬£¬£¬£¬£¬£¬¹ã¶«µÚËÄ£¬£¬£¬£¬£¬£¬£¬ÓÐ525¸ö·þÎñ¡£¡£¡£¡£¡£
·ì϶ÀûÓÃ
ʹÓÃ_template²ÎÊý¸²¸ÇVelocityäÖȾģ°å£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃfile:ºÍ̸Äܹ»½øÐÐËÁÒâÎļþ¶ÁÈ¡(²»ÔÙÊÜÏÞÓÚclasspath)
ͨ¹ý¸Ã²½ÖèÄܹ»½øÐб¾µØÎļþÔ̺¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://jira.atlassian.com/browse/CONFSERVER-57974¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201903-909
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201903-910
https://nvd.nist.gov/vuln/detail/CVE-2019-3396
https://nvd.nist.gov/vuln/detail/CVE-2019-3395


¾©¹«Íø°²±¸11010802024551ºÅ