当前位置:网站首页>Apache multiple component vulnerability disclosure (cve-2022-32533/cve-2022-33980/cve-2021-37839)
Apache multiple component vulnerability disclosure (cve-2022-32533/cve-2022-33980/cve-2021-37839)
2022-07-07 14:51:00 【51CTO】
OSCS( Open source software supply chain security community ) Launch free vulnerabilities 、 Poison information subscription service , Community users can subscribe to intelligence information through robots , For specific subscription methods, please refer to : https://www.oscs1024.com/?src=wx
7 month 6 Japan ,OSCS Detected Apache The loopholes of many projects under the foundation are open , Please pay attention to the corresponding component users .
Summary of vulnerability
1、Apache Portals Jetspeed-2(CVE-2022-32533)
Apache Portals Jetspeed-2 User input is not handled securely , Led to including XSS、CSRF、XXE and SSRF Including many problems .
- Vulnerability impact level : Middle risk
- Utilization cost : low
- Affected components :
- Affects version :\[\*,2.3.1\], The government no longer maintains , No fix version
- CVE Number :CVE-2022-32533
With XSS For example , The registered user name is set to
But officials say Apache Portals Jetspeed-2 yes Apache Portals Items that are no longer maintained in , No updates will be provided ,OSCS Suggest developers to replace .
Reference link :
2、Apache Commons Configuration(CVE-2022-33980)
Apache Commons Configuration Is a component for managing configuration files , stay 2.8 Some previous versions supported multiple variable value methods , Include javax.script、dns and url, Result in arbitrary code execution or network access .
- Vulnerability impact level : Middle risk
- Utilization cost : high
- Affected components :
- Affects version :\[2.4,2.8.0), The authorities are already in 2.8.0 Version fixes this problem by disabling dangerous methods
- CVE Number :CVE-2022-33980
Form like ${prefix:name}
The string of can be parsed , When interpolate When the string of the operation is controllable , Vulnerabilities can be exploited , Supported by prefix Here's the picture .
The following code can trigger
Reference link :
3、Apache Superset(CVE-2021-37839) Apache Superset Is a data visualization and data exploration platform .
stay Apache Superset In the affected version , Authenticated users can access metadata information related to the dataset without authorization , Include dataset name 、 Columns and indicators .
- Vulnerability impact level : Middle risk
- Utilization cost : in
- Affected components :
- Affects version :\[\*,1.5.1), The authorities are already in 1.5.1 Version to fix this
- CVE Number :CVE-2021-37839
The disposal of advice
OSCS It is recommended that users use the above components according to the above risk tips , Repair to a safe version as soon as possible .
See more vulnerability information : https://www.oscs1024.com/hl
Learn more about
1、 Free use OSCS Intelligence subscription service
OSCS ( Open source software supply chain security community ) The latest security risk dynamics of open source projects will be released at the first time , Including open source component security vulnerabilities 、 Information such as events , Community users can use enterprise and wechat 、 nailing 、 Fly Book Robot and other ways to subscribe to intelligence information , For specific subscription methods, please refer to :
边栏推荐
- Introduction and use of Kitti dataset
- Base64 encoding
- 2022年13个UX/UI/UE最佳创意灵感网站
- 「2022年7月」WuKong编辑器更版记录
- PD virtual machine tutorial: how to set the available shortcut keys in the parallelsdesktop virtual machine?
- 数据湖(九):Iceberg特点详述和数据类型
- 【愚公系列】2022年7月 Go教学课程 005-变量
- leetcode:648. Word replacement [dictionary tree board + find the shortest matching prefix among several prefixes]
- Because the employee set the password to "123456", amd stolen 450gb data?
- 《微信小程序-进阶篇》组件封装-Icon组件的实现(一)
猜你喜欢
Internal sort - insert sort
Simple use of websocket
Zhiting doesn't use home assistant to connect Xiaomi smart home to homekit
PyTorch模型训练实战技巧,突破速度瓶颈
AWS学习笔记(三)
Ian Goodfellow, the inventor of Gan, officially joined deepmind as research scientist
什么是云原生?这回终于能搞明白了!
The world's first risc-v notebook computer is on pre-sale, which is designed for the meta universe!
【历史上的今天】7 月 7 日:C# 发布;Chrome OS 问世;《仙剑奇侠传》发行
Data Lake (IX): Iceberg features and data types
随机推荐
属性关键字OnDelete,Private,ReadOnly,Required
What is cloud primordial? This time, I can finally understand!
Huawei cloud database DDS products are deeply enabled
leetcode:648. 单词替换【字典树板子 + 寻找若干前缀中的最短符合前缀】
PAG experience: complete AE dynamic deployment and launch all platforms in ten minutes!
JSON解析实例(Qt含源码)
Navigation — 这么好用的导航框架你确定不来看看?
Instructions d'utilisation de la trousse de développement du module d'acquisition d'accord du testeur mictr01
FFmpeg----图片处理
潘多拉 IOT 开发板学习(HAL 库)—— 实验12 RTC实时时钟实验(学习笔记)
How bad can a programmer be? Nima, they are all talents
NLLB-200:Meta开源新模型,可互译200种语言
Es log error appreciation -trying to create too many buckets
Wechat applet - Advanced chapter component packaging - Implementation of icon component (I)
Internal sort - insert sort
激光雷達lidar知識點滴
Summary on adding content of background dynamic template builder usage
Today's sleep quality record 78 points
PLC: automatically correct the data set noise, wash the data set | ICLR 2021 spotlight
Source code analysis of ArrayList