English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210190
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í Atlassian Confluence ServerÀÇ À§Á¬ Ä¿³ØÅÍ ¸ÅÅ©·Î´Â ¹öÀü 6.6.12 ÀÌÀü ¹öÀü (6.6.xÀÇ °íÁ¤ ¹öÀü), ¹öÀü 6.7.0 ÀÌÀü 6.12.3 (6.12.xÀÇ ¼öÁ¤ ¹öÀü), ¹öÀü 6.13.0 ÀÌÀü 6.13. 3 (6.13.x ¿ë °íÁ¤ ¹öÀü) ¹× 6.14.2 ÀÌÀü ¹öÀü 6.14.0 (6.14.x ¿ë °íÁ¤ ¹öÀü)ºÎÅÍ ¿ø°Ý °ø°ÝÀÚ°¡ Confluence ¼­¹ö ¶Ç´Â µ¥ÀÌÅÍ ¼¾ÅÍ ÀνºÅϽº¿¡¼­ ¼­¹ö Ãø ÅÛÇø´ ÁÖÀÔÀ» ÅëÇØ °æ·Î Ž»ö ¹× ¿ø°Ý ÄÚµå ½ÇÇàÀ» ¼öÇà ÇÒ ¼ö ÀÖ½À´Ï´Ù.

* Âü°í »çÀÌÆ®:
http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.html
http://www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connector
https://jira.atlassian.com/browse/CONFSERVER-57974
https://www.exploit-db.com/exploits/46731/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Confluence ServerÀÇ 6.6.12 ÀÌÀü ¹öÀü (6.6.xÀÇ °íÁ¤ ¹öÀü), ¹öÀü 6.7.0 ÀÌÀü 6.12.3 (6.12.xÀÇ ¼öÁ¤ ¹öÀü), ¹öÀü 6.13.0 ÀÌÀü 6.13.3 (6.13.x ¿ë °íÁ¤ ¹öÀü) ¹× 6.14.2 ÀÌÀü ¹öÀü 6.14.0 (6.14.x ¿ë °íÁ¤ ¹öÀü)
Any operating system Any version
ÇØ°áÃ¥ Confluence Server À¥ »çÀÌÆ®ÀÎ https://www.atlassian.com/software/confluence/download ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃֽŠ¹öÀü(6.6.12/ 6/12.3/ 6.13.3/ 6.14.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2019-3396 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)