当前位置:网站首页>Apache multiple component vulnerability disclosure (cve-2022-32533/cve-2022-33980/cve-2021-37839)
Apache multiple component vulnerability disclosure (cve-2022-32533/cve-2022-33980/cve-2021-37839)
2022-07-07 14:51:00 【51CTO】
OSCS( Open source software supply chain security community ) Launch free vulnerabilities 、 Poison information subscription service , Community users can subscribe to intelligence information through robots , For specific subscription methods, please refer to : https://www.oscs1024.com/?src=wx
7 month 6 Japan ,OSCS Detected Apache The loopholes of many projects under the foundation are open , Please pay attention to the corresponding component users .
Summary of vulnerability
1、Apache Portals Jetspeed-2(CVE-2022-32533)
Apache Portals Jetspeed-2 User input is not handled securely , Led to including XSS、CSRF、XXE and SSRF Including many problems .
- Vulnerability impact level : Middle risk
- Utilization cost : low
- Affected components :
- Affects version :\[\*,2.3.1\], The government no longer maintains , No fix version
- CVE Number :CVE-2022-32533
With XSS For example , The registered user name is set to
But officials say Apache Portals Jetspeed-2 yes Apache Portals Items that are no longer maintained in , No updates will be provided ,OSCS Suggest developers to replace .
Reference link :
2、Apache Commons Configuration(CVE-2022-33980)
Apache Commons Configuration Is a component for managing configuration files , stay 2.8 Some previous versions supported multiple variable value methods , Include javax.script、dns and url, Result in arbitrary code execution or network access .
- Vulnerability impact level : Middle risk
- Utilization cost : high
- Affected components :
- Affects version :\[2.4,2.8.0), The authorities are already in 2.8.0 Version fixes this problem by disabling dangerous methods
- CVE Number :CVE-2022-33980
Form like ${prefix:name}
The string of can be parsed , When interpolate When the string of the operation is controllable , Vulnerabilities can be exploited , Supported by prefix Here's the picture .
The following code can trigger
Reference link :
3、Apache Superset(CVE-2021-37839) Apache Superset Is a data visualization and data exploration platform .
stay Apache Superset In the affected version , Authenticated users can access metadata information related to the dataset without authorization , Include dataset name 、 Columns and indicators .
- Vulnerability impact level : Middle risk
- Utilization cost : in
- Affected components :
- Affects version :\[\*,1.5.1), The authorities are already in 1.5.1 Version to fix this
- CVE Number :CVE-2021-37839
The disposal of advice
OSCS It is recommended that users use the above components according to the above risk tips , Repair to a safe version as soon as possible .
See more vulnerability information : https://www.oscs1024.com/hl
Learn more about
1、 Free use OSCS Intelligence subscription service
OSCS ( Open source software supply chain security community ) The latest security risk dynamics of open source projects will be released at the first time , Including open source component security vulnerabilities 、 Information such as events , Community users can use enterprise and wechat 、 nailing 、 Fly Book Robot and other ways to subscribe to intelligence information , For specific subscription methods, please refer to :
边栏推荐
- Applet directory structure
- Instructions d'utilisation de la trousse de développement du module d'acquisition d'accord du testeur mictr01
- [today in history] July 7: release of C; Chrome OS came out; "Legend of swordsman" issued
- PD virtual machine tutorial: how to set the available shortcut keys in the parallelsdesktop virtual machine?
- 6、Electron无边框窗口和透明窗口 锁定模式 设置窗口图标
- The method of parsing PHP to jump out of the loop and the difference between continue, break and exit
- FFmpeg----图片处理
- Cvpr2022 | backdoor attack based on frequency injection in medical image analysis
- 半小时『直播连麦搭建』动手实战,大学生技术岗位简历加分项get!
- 内部排序——插入排序
猜你喜欢
15、文本编辑工具VIM使用
Navigation - are you sure you want to take a look at such an easy-to-use navigation framework?
Introduction and use of Kitti dataset
Data connection mode in low code platform (Part 2)
Navigation - are you sure you want to take a look at such an easy-to-use navigation framework?
[today in history] July 7: release of C; Chrome OS came out; "Legend of swordsman" issued
Notes de l'imprimante substance: paramètres pour les affichages Multi - écrans et multi - Résolutions
Internal sort - insert sort
2022pagc Golden Sail award | rongyun won the "outstanding product technology service provider of the year"
[server data recovery] a case of RAID data recovery of a brand StorageWorks server
随机推荐
15、文本编辑工具VIM使用
Stm32cubemx, 68 sets of components, following 10 open source protocols
Computer win7 system desktop icon is too large, how to turn it down
Leetcode - Sword finger offer 05 Replace spaces
上半年晋升 P8 成功,还买了别墅!
[Yugong series] go teaching course 005 variables in July 2022
JS in the browser Base64, URL, blob mutual conversion
多商戶商城系統功能拆解01講-產品架構
[server data recovery] a case of RAID data recovery of a brand StorageWorks server
Ascend 910 realizes tensorflow1.15 to realize the Minist handwritten digit recognition of lenet network
全球首款 RISC-V 笔记本电脑开启预售,专为元宇宙而生!
Pinduoduo lost the lawsuit, and the case of bargain price difference of 0.9% was sentenced; Wechat internal test, the same mobile phone number can register two account functions; 2022 fields Awards an
云上“视界” 创新无限 | 2022阿里云直播峰会正式上线
13 ux/ui/ue best creative inspiration websites in 2022
Infinite innovation in cloud "vision" | the 2022 Alibaba cloud live summit was officially launched
「2022年7月」WuKong编辑器更版记录
智汀不用Home Assistant让小米智能家居接入HomeKit
潘多拉 IOT 开发板学习(HAL 库)—— 实验12 RTC实时时钟实验(学习笔记)
Discussion on CPU and chiplet Technology
leetcode:648. 单词替换【字典树板子 + 寻找若干前缀中的最短符合前缀】