当前位置:网站首页>Apache multiple component vulnerability disclosure (cve-2022-32533/cve-2022-33980/cve-2021-37839)
Apache multiple component vulnerability disclosure (cve-2022-32533/cve-2022-33980/cve-2021-37839)
2022-07-07 14:51:00 【51CTO】
OSCS( Open source software supply chain security community ) Launch free vulnerabilities 、 Poison information subscription service , Community users can subscribe to intelligence information through robots , For specific subscription methods, please refer to : https://www.oscs1024.com/?src=wx
7 month 6 Japan ,OSCS Detected Apache The loopholes of many projects under the foundation are open , Please pay attention to the corresponding component users .
Summary of vulnerability
1、Apache Portals Jetspeed-2(CVE-2022-32533)
Apache Portals Jetspeed-2 User input is not handled securely , Led to including XSS、CSRF、XXE and SSRF Including many problems .
- Vulnerability impact level : Middle risk
- Utilization cost : low
- Affected components :
- Affects version :\[\*,2.3.1\], The government no longer maintains , No fix version
- CVE Number :CVE-2022-32533
With XSS For example , The registered user name is set to
But officials say Apache Portals Jetspeed-2 yes Apache Portals Items that are no longer maintained in , No updates will be provided ,OSCS Suggest developers to replace .
Reference link :
2、Apache Commons Configuration(CVE-2022-33980)
Apache Commons Configuration Is a component for managing configuration files , stay 2.8 Some previous versions supported multiple variable value methods , Include javax.script、dns and url, Result in arbitrary code execution or network access .
- Vulnerability impact level : Middle risk
- Utilization cost : high
- Affected components :
- Affects version :\[2.4,2.8.0), The authorities are already in 2.8.0 Version fixes this problem by disabling dangerous methods
- CVE Number :CVE-2022-33980
Form like ${prefix:name} The string of can be parsed , When interpolate When the string of the operation is controllable , Vulnerabilities can be exploited , Supported by prefix Here's the picture .

The following code can trigger

Reference link :
3、Apache Superset(CVE-2021-37839) Apache Superset Is a data visualization and data exploration platform .
stay Apache Superset In the affected version , Authenticated users can access metadata information related to the dataset without authorization , Include dataset name 、 Columns and indicators .
- Vulnerability impact level : Middle risk
- Utilization cost : in
- Affected components :
- Affects version :\[\*,1.5.1), The authorities are already in 1.5.1 Version to fix this
- CVE Number :CVE-2021-37839
The disposal of advice
OSCS It is recommended that users use the above components according to the above risk tips , Repair to a safe version as soon as possible .
See more vulnerability information : https://www.oscs1024.com/hl
Learn more about
1、 Free use OSCS Intelligence subscription service
OSCS ( Open source software supply chain security community ) The latest security risk dynamics of open source projects will be released at the first time , Including open source component security vulnerabilities 、 Information such as events , Community users can use enterprise and wechat 、 nailing 、 Fly Book Robot and other ways to subscribe to intelligence information , For specific subscription methods, please refer to :


边栏推荐
- 时空可变形卷积用于压缩视频质量增强(STDF)
- 多商戶商城系統功能拆解01講-產品架構
- PD virtual machine tutorial: how to set the available shortcut keys in the parallelsdesktop virtual machine?
- 寺岗电子称修改IP简易步骤
- 全球首款 RISC-V 笔记本电脑开启预售,专为元宇宙而生!
- PLC: automatically correct the data set noise, wash the data set | ICLR 2021 spotlight
- Multi merchant mall system function disassembly lecture 01 - Product Architecture
- 关于后台动态模板添加内容的总结 Builder使用
- Cocos creator direction and angle conversion
- Source code analysis of ArrayList
猜你喜欢

大厂做开源的五大痛点

2022PAGC 金帆奖 | 融云荣膺「年度杰出产品技术服务商」

Multi merchant mall system function disassembly lecture 01 - Product Architecture

Bill Gates posted his resume 48 years ago: "it's not as good-looking as yours."

KITTI数据集简介与使用

小程序目录结构

Leetcode one question per day (636. exclusive time of functions)

Navigation — 这么好用的导航框架你确定不来看看?

多商戶商城系統功能拆解01講-產品架構

15、文本编辑工具VIM使用
随机推荐
Mmkv use and principle
2022 cloud consulting technology series high availability special sharing meeting
Demis hassabis talks about alphafold's future goals
"July 2022" Wukong editor update record
Navigation - are you sure you want to take a look at such an easy-to-use navigation framework?
What is cloud primordial? This time, I can finally understand!
Ian Goodfellow, the inventor of Gan, officially joined deepmind as research scientist
「2022年7月」WuKong编辑器更版记录
GAN发明者Ian Goodfellow正式加入DeepMind,任Research Scientist
AWS learning notes (III)
Cvpr2022 | backdoor attack based on frequency injection in medical image analysis
用于增强压缩视频质量的可变形卷积密集网络
Substance Painter筆記:多顯示器且多分辨率顯示器時的設置
KITTI数据集简介与使用
潘多拉 IOT 开发板学习(HAL 库)—— 实验12 RTC实时时钟实验(学习笔记)
Half an hour of hands-on practice of "live broadcast Lianmai construction", college students' resume of technical posts plus points get!
Navigation — 这么好用的导航框架你确定不来看看?
Deformable convolutional dense network for enhancing compressed video quality
The method of parsing PHP to jump out of the loop and the difference between continue, break and exit
Because the employee set the password to "123456", amd stolen 450gb data?