2023年2月22日星期三

Apache Tomcat 阻斷服務漏洞

發佈日期: 2023年02月22日

風險: 中度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Apache Tomcat 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • Apache Tomcat 11.0.0-M1版本
  • Apache Tomcat 10.1.0-M1 to 10.1.4 版本
  • Apache Tomcat 9.0.0-M1 to 9.0.70 版本
  • Apache Tomcat 8.5.0 to 8.5.84 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Apache Tomcat Denial of Service Vulnerability

Release Date: 22 Feb 2023

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability has been identified in Apache Tomcat. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • Apache Tomcat version 11.0.0-M1
  • Apache Tomcat version 10.1.0-M1 to 10.1.4
  • Apache Tomcat version 9.0.0-M1 to 9.0.70
  • Apache Tomcat version 8.5.0 to 8.5.84

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

VMWare 產品多個漏洞

發佈日期: 2023年02月22日

風險: 中度風險

類型: 操作系統 - 網絡操作系統

類型: 網絡操作系統

於 VMware Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、篡改、繞過保安限制及洩露敏感資料。


影響

  • 權限提升
  • 資料洩露
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • VMware vRealize Orchestrator
  • VMware vRealize Automation
  • VMware Carbon Black App Control (App Control)
  • VMware Cloud Foundation (Cloud Foundation) 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

VMWare Products Multiple Vulnerabilities

Release Date: 22 Feb 2023

RISK: Medium Risk

TYPE: Operating Systems - VM Ware

TYPE: VM Ware

Multiple vulnerabilities were identified in VMware Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, data manipulation, security restriction bypass and sensitive information disclosure on the targeted system.


Impact

  • Elevation of Privilege
  • Information Disclosure
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • VMware vRealize Orchestrator
  • VMware vRealize Automation
  • VMware Carbon Black App Control (App Control)
  • VMware Cloud Foundation (Cloud Foundation) 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

蘋果產品多個漏洞

最後更新 2023年02月22日 發佈日期: 2023年02月14日

風險: 極高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於蘋果產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、權限提升、遠端執行任意程式碼、洩露敏感資料。

 

注意:

CVE-2023-23529 漏洞正被廣泛利用。

 

[更新於 2023-02-14] 

更新受影響之系統或技術、解決方案及相關連結。

 

[更新於 2023-02-22] 

更新影響及漏洞識別碼。


影響

  • 權限提升
  • 遠端執行程式碼
  • 資料洩露
  • 阻斷服務

受影響之系統或技術

  • iOS 16.3.1及 iPadOS 16.3.1 以前的版本
  • macOS 13.2.1 以前的版本
  • Safari 16.3.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • iOS 16.3.1及 iPadOS 16.3.1
  • macOS 13.2.1 
  • Safari 16.3.1

漏洞識別碼


資料來源


相關連結

Apple Products Multiple Vulnerabilities

Last Update Date: 22 Feb 2023 Release Date: 14 Feb 2023

RISK: Extremely High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service, elevation of privilege, remote code execution, sensitive information disclosure on the targeted system.

 

Note:

CVE-2023-23529 is being exploited in the wild.

 

[Updated on 2023-02-14] 

Updated System / Technologies affected, Solutions and Related Links.

 

[Updated on 2023-02-22] 

Updated Impact and Vulnerability Identifier.


Impact

  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Denial of Service

System / Technologies affected

  • Versions prior to iOS 16.3.1 and iPadOS 16.3.1
  • Versions prior to macOS 13.2.1
  • Versions prior to Safari 16.3.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • iOS 16.3.1 and iPadOS 16.3.1
  • macOS 13.2.1
  • Safari 16.3.1

Vulnerability Identifier


Source


Related Link

2023年2月20日星期一

Fortinet 產品多個漏洞

發佈日期: 2023年02月20日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 Fortinet Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、阻斷服務、資料洩露、跨網站指令碼及權限提升。


影響

  • 繞過保安限制
  • 阻斷服務
  • 資料洩露
  • 跨網站指令碼
  • 權限提升

受影響之系統或技術

  • FortiAuthenticator 5.5 所有版本
  • FortiAuthenticator 版本 6.0.0 至 6.0.4
  • FortiAuthenticator 版本 6.1.0
  • FortiOS 6.0 所有版本
  • FortiOS 6.2 所有版本
  • FortiOS 6.4 所有版本
  • FortiOS 版本 6.0.0 至 6.0.13
  • FortiOS 版本 6.2.0 至 6.2.12
  • FortiOS 版本 6.2.0 至 6.2.9
  • FortiOS 版本 6.4.0 至 6.4.1
  • FortiOS 版本 6.4.0 至 6.4.10
  • FortiOS 版本 7.0.0 至 7.0.7
  • FortiOS 版本 7.0.0 至 7.0.8
  • FortiOS 版本 7.2.0
  • FortiOS 版本 7.2.0 至 7.2.2
  • FortiOS 版本 7.2.0 至 7.2.3
  • FortiOS 版本 6.4.8 及以前
  • FortiOS 版本 7.0.3 及以前
  • FortiProxy 1.0 所有版本
  • FortiProxy 1.1 所有版本
  • FortiProxy 1.2 所有版本
  • FortiProxy 2.0 所有版本
  • FortiProxy 版本 2.0.0 至 2.0.10
  • FortiProxy 版本 7.0.0 至 7.0.6
  • FortiProxy 版本 7.0.0 至 7.0.7
  • FortiProxy 版本 7.2.0 至 7.2.1
  • FortiProxy 版本 2.0.7 及以前
  • FortiProxy 版本 7.0.1 及以前
  • FortiSwitch 6.0 所有版本
  • FortiSwitch 6.2 所有版本
  • FortiSwitch 版本 6.4.10 及以前
  • FortiSwitch 版本 7.0.3 及以前
  • FortiSwitchManager 版本 7.0.0
  • FortiSwitchManager 版本 7.2.0
  • FortiWeb 6.0 所有版本
  • FortiWeb 6.1 所有版本
  • FortiWeb 6.2 所有版本
  • FortiWeb 6.4 所有版本
  • FortiWeb 版本 6.3.16 及以前

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Release Date: 20 Feb 2023

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, denial of service, information disclosure, cross-site scripting and elevation of privilege on the targeted system.


Impact

  • Security Restriction Bypass
  • Denial of Service
  • Information Disclosure
  • Cross-Site Scripting
  • Elevation of Privilege

System / Technologies affected

  • FortiAuthenticator 5.5 all versions
  • FortiAuthenticator version 6.0.0 through 6.0.4
  • FortiAuthenticator version 6.1.0
  • FortiOS 6.0 all versions
  • FortiOS 6.2 all versions
  • FortiOS 6.4 all versions
  • FortiOS version 6.0.0 through 6.0.13
  • FortiOS version 6.2.0 through 6.2.12
  • FortiOS version 6.2.0 through 6.2.9
  • FortiOS version 6.4.0 through 6.4.1
  • FortiOS version 6.4.0 through 6.4.10
  • FortiOS version 7.0.0 through 7.0.7
  • FortiOS version 7.0.0 through 7.0.8
  • FortiOS version 7.2.0
  • FortiOS version 7.2.0 through 7.2.2
  • FortiOS version 7.2.0 through 7.2.3
  • FortiOS versions 6.4.8 and below
  • FortiOS versions 7.0.3 and below
  • FortiProxy 1.0 all versions
  • FortiProxy 1.1 all versions
  • FortiProxy 1.2 all versions
  • FortiProxy 2.0 all versions
  • FortiProxy version 2.0.0 through 2.0.10
  • FortiProxy version 7.0.0 through 7.0.6
  • FortiProxy version 7.0.0 through 7.0.7
  • FortiProxy version 7.2.0 through 7.2.1
  • FortiProxy versions 2.0.7 and below
  • FortiProxy versions 7.0.1 and below
  • FortiSwitch 6.0 all versions
  • FortiSwitch 6.2 all versions
  • FortiSwitch versions 6.4.10 and below
  • FortiSwitch versions 7.0.3 and below
  • FortiSwitchManager version 7.0.0
  • FortiSwitchManager version 7.2.0
  • FortiWeb 6.0 all versions
  • FortiWeb 6.1 all versions
  • FortiWeb 6.2 all versions
  • FortiWeb 6.4 all versions
  • FortiWeb versions 6.3.16 and below

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Mozilla Thunderbird 多個漏洞

發佈日期: 2023年02月20日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Mozilla Thunderbird 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發彷冒、遠端執行任意程式碼、洩露敏感資料、阻斷服務及繞過保安限制。


影響

  • 仿冒
  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制
  • 阻斷服務

受影響之系統或技術

以下版本之前的版本﹕

 

  • Thunderbird 102.8

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Thunderbird 102.8

漏洞識別碼


資料來源


相關連結

Mozilla Thunderbird Multiple Vulnerabilities

Release Date: 20 Feb 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Mozilla Thunderbird. A remote attacker could exploit some of these vulnerabilities to trigger spoofing, remote code execution, sensitive information disclosure,  denial of service and security restriction bypass on the targeted system.


Impact

  • Spoofing
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass
  • Denial of Service

System / Technologies affected

Versions prior to:

 

  • Thunderbird 102.8

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Thunderbird 102.8

Vulnerability Identifier


Source


Related Link

Node.js 多個漏洞

發佈日期: 2023年02月20日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 Node.js 發現一些漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、繞過保安限制、權限提升及阻斷服務。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 阻斷服務
  • 權限提升

受影響之系統或技術

  • Node.js 14.21.3 以前的版本
  • Node.js 16.19.1 (LTS) 以前的版本
  • Node.js 18.14.1 (LTS) 以前的版本
  • Node.js 19.6.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 更新至 Node.js 14.21.3 (LTS) 版本
  • 更新至 Node.js 16.19.1 (LTS) 版本
  • 更新至 Node.js 18.14.1 (LTS) 版本
  • 更新至 Node.js 19.6.1 版本

漏洞識別碼


資料來源


相關連結

https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/

WordPress 多個漏洞

WordPress 多個漏洞 發佈日期 : 2026 年 09 月 22 日 於 WordPress 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改。   注意 : 針對 Word...