当前位置:网站首页>Apache multiple component vulnerability disclosure (cve-2022-32533/cve-2022-33980/cve-2021-37839)
Apache multiple component vulnerability disclosure (cve-2022-32533/cve-2022-33980/cve-2021-37839)
2022-07-07 14:51:00 【51CTO】
OSCS( Open source software supply chain security community ) Launch free vulnerabilities 、 Poison information subscription service , Community users can subscribe to intelligence information through robots , For specific subscription methods, please refer to : https://www.oscs1024.com/?src=wx
7 month 6 Japan ,OSCS Detected Apache The loopholes of many projects under the foundation are open , Please pay attention to the corresponding component users .
Summary of vulnerability
1、Apache Portals Jetspeed-2(CVE-2022-32533)
Apache Portals Jetspeed-2 User input is not handled securely , Led to including XSS、CSRF、XXE and SSRF Including many problems .
- Vulnerability impact level : Middle risk
- Utilization cost : low
- Affected components :
- Affects version :\[\*,2.3.1\], The government no longer maintains , No fix version
- CVE Number :CVE-2022-32533
With XSS For example , The registered user name is set to
But officials say Apache Portals Jetspeed-2 yes Apache Portals Items that are no longer maintained in , No updates will be provided ,OSCS Suggest developers to replace .
Reference link :
2、Apache Commons Configuration(CVE-2022-33980)
Apache Commons Configuration Is a component for managing configuration files , stay 2.8 Some previous versions supported multiple variable value methods , Include javax.script、dns and url, Result in arbitrary code execution or network access .
- Vulnerability impact level : Middle risk
- Utilization cost : high
- Affected components :
- Affects version :\[2.4,2.8.0), The authorities are already in 2.8.0 Version fixes this problem by disabling dangerous methods
- CVE Number :CVE-2022-33980
Form like ${prefix:name}
The string of can be parsed , When interpolate When the string of the operation is controllable , Vulnerabilities can be exploited , Supported by prefix Here's the picture .
The following code can trigger
Reference link :
3、Apache Superset(CVE-2021-37839) Apache Superset Is a data visualization and data exploration platform .
stay Apache Superset In the affected version , Authenticated users can access metadata information related to the dataset without authorization , Include dataset name 、 Columns and indicators .
- Vulnerability impact level : Middle risk
- Utilization cost : in
- Affected components :
- Affects version :\[\*,1.5.1), The authorities are already in 1.5.1 Version to fix this
- CVE Number :CVE-2021-37839
The disposal of advice
OSCS It is recommended that users use the above components according to the above risk tips , Repair to a safe version as soon as possible .
See more vulnerability information : https://www.oscs1024.com/hl
Learn more about
1、 Free use OSCS Intelligence subscription service
OSCS ( Open source software supply chain security community ) The latest security risk dynamics of open source projects will be released at the first time , Including open source component security vulnerabilities 、 Information such as events , Community users can use enterprise and wechat 、 nailing 、 Fly Book Robot and other ways to subscribe to intelligence information , For specific subscription methods, please refer to :
边栏推荐
- 拼多多败诉,砍价始终差0.9%一案宣判;微信内测同一手机号可注册两个账号功能;2022年度菲尔兹奖公布|极客头条...
- C# 6.0 语言规范获批
- LeetCode 648. Word replacement
- [today in history] July 7: release of C; Chrome OS came out; "Legend of swordsman" issued
- Discussion on CPU and chiplet Technology
- Differences between cookies and sessions
- 低代码平台中的数据连接方式(下)
- 什么是云原生?这回终于能搞明白了!
- Leetcode one question per day (636. exclusive time of functions)
- KITTI数据集简介与使用
猜你喜欢
Stm32cubemx, 68 sets of components, following 10 open source protocols
leetcode:648. 单词替换【字典树板子 + 寻找若干前缀中的最短符合前缀】
小米的芯片自研之路
Pytorch model trains practical skills and breaks through the bottleneck of speed
15、文本编辑工具VIM使用
Webrtc audio anti weak network technology (Part 1)
The world's first risc-v notebook computer is on pre-sale, which is designed for the meta universe!
Pinduoduo lost the lawsuit, and the case of bargain price difference of 0.9% was sentenced; Wechat internal test, the same mobile phone number can register two account functions; 2022 fields Awards an
Today's sleep quality record 78 points
【历史上的今天】7 月 7 日:C# 发布;Chrome OS 问世;《仙剑奇侠传》发行
随机推荐
Pinduoduo lost the lawsuit, and the case of bargain price difference of 0.9% was sentenced; Wechat internal test, the same mobile phone number can register two account functions; 2022 fields Awards an
用于增强压缩视频质量的可变形卷积密集网络
Applet directory structure
Reading and understanding of eventbus source code
Introduction and use of Kitti dataset
Shengteng experience officer Episode 5 notes I
找到自己的价值
2022 cloud consulting technology series high availability special sharing meeting
数据库如何进行动态自定义排序?
Xiaomi's path of chip self-development
Ian Goodfellow, the inventor of Gan, officially joined deepmind as research scientist
Démontage de la fonction du système multi - Merchant Mall 01 - architecture du produit
Because the employee set the password to "123456", amd stolen 450gb data?
#yyds干货盘点# 解决名企真题:交叉线
Computer win7 system desktop icon is too large, how to turn it down
【历史上的今天】7 月 7 日:C# 发布;Chrome OS 问世;《仙剑奇侠传》发行
15、文本编辑工具VIM使用
JS image to Base64
一个程序员的水平能差到什么程度?尼玛,都是人才呀...
Leetcode——344. Reverse string /541 Invert string ii/151 Reverse the word / Sword finger in the string offer 58 - ii Rotate string left