漏洞信息详情
Iteris Apache Velocity 跨站脚本漏洞
漏洞简介
Iteris Apache Velocity是美国 (Iteris)公司的一个应用软件。用于创建和维护与Apache Velocity Engine相关的开源软件功能。
Apache Velocity 3.1 存在安全漏洞,攻击者可利用该漏洞窃取会话cookie,以受害者的名义执行请求或进行网络钓鱼攻击。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://lists.apache.org/thread.html/r6802a38c3041059e763a1aadd7b37fe95de75408144b5805e29b84e3%40%3Cuser.velocity.apache.org%3E
参考网址
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/03/msg00021.html
来源:MLIST
链接:https://lists.apache.org/thread.html/r97edad0655770342d2d36620fb1de50b142fcd6c4f5c53dd72ca41d7@%3Cuser.velocity.apache.org%3E
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2021/03/10/2
来源:MLIST
链接:https://lists.apache.org/thread.html/r6802a38c3041059e763a1aadd7b37fe95de75408144b5805e29b84e3@%3Cuser.velocity.apache.org%3E
来源:CONFIRM
链接:https://lists.apache.org/thread.html/r6802a38c3041059e763a1aadd7b37fe95de75408144b5805e29b84e3%40%3Cuser.velocity.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rb042f3b0090e419cc9f5a3d32cf0baff283ccd6fcb1caea61915d6b6@%3Ccommits.velocity.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rf9868c564cff7adfd5283563f2309b93b3e496354a211a57503b2f72@%3Cannounce.apache.org%3E
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-apache-node-js-and-docker-affect-ibm-spectrum-protect-plus/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163643/Gentoo-Linux-Security-Advisory-202107-52.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021072614
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-13959
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Apache-Velocity-Tools-Cross-Site-Scripting-via-Default-Error-Page-34878
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0944
受影响实体
暂无
补丁
- Apache Velocity 跨站脚本漏洞的修复措施<!--2021-3-10-->
还没有评论,来说两句吧...