漏洞信息详情
Red Hat WildFly Core 安全漏洞
漏洞简介
Red Hat WildFly Core(前称JBoss Application Server)是美国红帽(Red Hat)公司的一款基于JavaEE的开源应用服务器。
Red Hat WildFly Core 6.0.0.Alpha3之前版本中存在安全漏洞,该漏洞源于程序没有正确的验证.war归档文件中的文件路径。攻击者可利用该漏洞覆盖任意文件。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,详情请关注厂商主页:
https://github.com/wildfly/wildfly-core
参考网址
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2428
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2425
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2424
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2423
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2643
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2279
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2277
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2276
来源:MISC
链接:https://snyk.io/research/zip-slip-vulnerability
来源:CONFIRM
链接:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10862
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:0877
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:0877
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2071/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79650
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152620/Red-Hat-Security-Advisory-2019-0877-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/158097/Red-Hat-Security-Advisory-2020-2562-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.1858/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/157835/Red-Hat-Security-Advisory-2020-2321-01.html
受影响实体
- Redhat Virtualization:4.0<!--2000-1-1-->
- Redhat Jboss_enterprise_application_platform:7.1.0<!--2000-1-1-->
- Redhat Wildfly_core:5.0.0<!--2000-1-1-->
- Redhat Wildfly_core:6.0.0:Alpha1<!--2000-1-1-->
- Redhat Wildfly_core:6.0.0:Alpha2<!--2000-1-1-->
补丁
- Red Hat WildFly Core 安全漏洞的修复措施<!--2018-7-30-->
还没有评论,来说两句吧...