ÿÖÜÉý¼¶Í¨¸æ-2022-01-11

Ðû²¼Ê±¼ä 2022-01-12

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_´úÂëÖ´ÐÐ_Dubbo·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-30179]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃDubboµÄGenericFilter½Ó¿ÚµÄ·´ÐòÁл¯Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³ÌЧÀÍŲÓüƻ®£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°SOAЧÀÍÖÎÀí¼Æ»®¡£¡£¡£¡£¡£¡£¡£ApacheDubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇ󡣡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220111

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ApiSix_í§Òâ´úÂëÖ´ÐÐ[CVE-2021-45232][CNNVD-202112-2629]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÔÚ2.10.1֮ǰµÄApacheAPISIXDashboardÖУ¬£¬£¬£¬£¬£¬£¬ManagerAPIʹÓÃÁ½¸ö¿ò¼Ü²¢ÔÚ»ù´¡ÉÏÒýÈë`droplet`ºÍ`gin`Á½¸ö¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬¿ª·¢ËùÓÐAPIºÍÈÏÖ¤ÖÐÐļþ»ùÓÚ¿ò¼Ü`droplet`£¬£¬£¬£¬£¬£¬£¬µ«²¿·ÖAPIÖ±½ÓʹÓýӿÚ`gin`¿ò¼Üδ¾ÙÐÐdropletÈÏÖ¤£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÒÔδÊÚȨ»á¼û¡£¡£¡£¡£¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬£¬£¬£¬ÔÚÌØ±ðµÄ·¾¶Ï£¬£¬£¬£¬£¬£¬£¬±£´æ±»¹¥»÷ÕßÖ´ÐÐí§Òâlua´úÂëµÄΣº¦¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220111


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_FastjsonÎó²î_hex±àÂëʹÓÃ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬£¬£¬£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬£¬£¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¡£¡£¡£¡£¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£fastjson¿É½ÓÊܲ¢ÆÊÎöhex±àÂëÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉʹÓÃhex±àÂëÈÆ¹ý¼ì²â×°±¸¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220111