漏洞信息详情
openHAB 代码问题漏洞
漏洞简介
openHAB before versions 2.5.12 and 3.0.1 存在安全漏洞,攻击者可利用该漏洞从文件系统中检索内部信息。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/openhab/openhab-addons/commit/81935b0ab126e6d9aebd2f6c3fc67d82bb7e8b86
参考网址
来源:MISC
链接:https://dev.to/brianverm/configure-your-java-xml-parsers-to-prevent-xxe-213c
来源:CONFIRM
链接:https://github.com/openhab/openhab-addons/security/advisories/GHSA-r2hc-pmr7-4c9r
来源:MISC
链接:https://github.com/openhab/openhab-addons/commit/81935b0ab126e6d9aebd2f6c3fc67d82bb7e8b86
来源:MISC
链接:https://www.contrastsecurity.com/security-influencers/xml-xxe-pitfalls-with-jaxb
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-21266
受影响实体
暂无
补丁
- openHAB 代码问题漏洞的修复措施<!--2021-2-1-->
还没有评论,来说两句吧...