脆弱性の詳細を照会します。
今すぐお試しください
テスト
RAM 認証
|
アクション |
アクセスレベル |
リソースタイプ |
条件キー |
依存アクション |
|
yundun-sas:DescribeVulDetails |
get |
*All Resource
|
なし | なし |
リクエストパラメーター
|
パラメーター |
型 |
必須 / 任意 |
説明 |
例 |
| Lang |
string |
必須 |
リクエストおよび応答の言語タイプ。有効な値:
|
zh |
| Type |
string |
必須 |
クエリする脆弱性のタイプ。有効な値:
|
sca |
| Name |
string |
必須 |
脆弱性名。 説明
DescribeGroupedVul または DescribeVulList を呼び出してこのパラメーターを取得できます。 |
SCA:ACSV-2020-052801 |
| AliasName |
string |
任意 |
脆弱性のアナウンス。 |
RHSA-2019:3197-Important: sudo security update |
| ResourceDirectoryAccountId |
integer |
任意 |
リソースディレクトリフォルダ内のメンバーアカウントの Alibaba Cloud アカウント ID。 説明
DescribeMonitorAccounts を呼び出してこのパラメーターを取得できます。 |
127608589417**** |
レスポンスフィールド
|
フィールド |
型 |
説明 |
例 |
|
object |
応答パラメーター。 |
||
| RequestId |
string |
リクエスト ID。Alibaba Cloud がリクエストに対して生成する一意の識別子です。問題のトラブルシューティングに使用できます。 |
EDA40EA3-6265-5900-AD99-C83E4F109CA8 |
| Cves |
array<object> |
脆弱性の詳細のリスト。 |
|
|
array<object> |
脆弱性の詳細。 |
||
| Summary |
string |
脆弱性のまとめ。 |
Chanjet T-Plus is an Internet business management software. There is an unauthorized access vulnerability in one of its interfaces disclosed on the Internet. Attackers can construct malicious requests to upload malicious files to execute arbitrary code and control the server. |
Complexity
deprecated
|
string |
脆弱性の悪用の難易度。有効な値:
|
LOW |
Product
deprecated
|
string |
脆弱性の影響を受けるプロダクト。 |
Log4j2 |
PocCreateTime
deprecated
|
integer |
概念実証 (POC) が作成されたタイムスタンプ。単位: ミリ秒。 |
1554189334000 |
| CveId |
string |
CVE ID。 |
CVE-2019-9167 |
CnvdId
deprecated
|
string |
China National Vulnerability Database (CNVD) ID。 |
CNVD-2019-9167 |
| Reference |
string |
Alibaba Cloud 脆弱性データベースにおける脆弱性のリファレンスリンク。 |
https://example.com |
| CvssScore |
string |
Alibaba Cloud 脆弱性データベースにおける脆弱性の CVSS (共通脆弱性評価システム) スコア。 |
10.0 |
Vendor
deprecated
|
string |
脆弱性を公開したベンダー。 |
Apache |
PocDisclosureTime
deprecated
|
integer |
POC が公開されたタイムスタンプ。単位: ミリ秒。 |
1554189334000 |
| Classify |
string |
脆弱性の分類。 |
remote_code_execution |
| CvssVector |
string |
CVSS (共通脆弱性評価システム) スコアベクター。 |
AV:N/AC:L/Au:N/C:C/I:C/A:C |
| VulLevel |
string |
脆弱性の重大度レベル。有効な値:
|
serious |
| ReleaseTime |
integer |
Alibaba Cloud 脆弱性データベースで脆弱性が公開されたタイムスタンプ。単位: ミリ秒。 |
1554189334000 |
| Title |
string |
脆弱性アナウンスのタイトル。 |
Chanjet T-Plus SetupAccount/Upload. Aspx file upload vulnerability(CNVD-2022-60632) |
| Solution |
string |
脆弱性の修復に関する提案。 |
At present, Chanjet has urgently released a vulnerability patch to fix the vulnerability. CNVD recommends affected units and users to upgrade to the latest version immediately: ↵https://www.chanjetvip.com/product/goods/goods-detail?id=53aaa40295d458e44f5d3ce5 ↵At the same time, organizations and users affected by the vulnerability are requested to immediately follow the steps below to conduct self-inspection and repair work: ↵
If you have any technical problems, please contact Chanjet technical support: 4006600566-9 |
Content
deprecated
|
string |
CVE の内容。 |
Apache Shiro is a user authentication and authorization framework for a wide range of rights management applications.↵Recently, Apache Shiro released version 1.7.0, which fixes the Apache Shiro authentication bypass vulnerability (CVE-2020-17510).↵Attackers can bypass Shiro's authentication using malicious requests containing payloads.↵↵Related bugs:↵CVE-2020-17510 Shiro < 1.7.0 Validation Bypass Vulnerability↵CVE-2020-13933 Shiro < 1.6.0 Validation Bypass Vulnerability↵CVE-2020-11989 Shiro < 1.5.3 Validation Bypass Vulnerability↵CVE-2020-1957 Shiro < 1.5.2 Validation Bypass Vulnerability↵CVE-2016-6802 Shiro < 1.3.2 Validation Bypass Vulnerability Check whether the fastjson version currently running on the system is in the affected version and whether safeMode is configured to disable autoType. If it is in the affected version and safeMode is not configured to disable autoType, the vulnerability is considered to exist. |
Poc
deprecated
|
string |
POC の内容。 |
NewDomain.html The x and y values will need to be changed accordingly Authenticated Stored CSRF/XSS - Vonage Modem NewKeyword.html The x and y values will need to be changed accordinglyAuthenticated Stored CSRF/XSS - Vonage Modem |
| Classifys |
array<object> |
脆弱性の分類のリスト。 |
|
|
object |
脆弱性の分類の詳細。 |
||
| Description |
string |
脆弱性の種類に関する説明です。 |
privilege escalation |
| Classify |
string |
脆弱性の分類タイプです。 |
remote_code_execution |
| DemoVideoUrl |
string |
脆弱性に関するデモビデオの URL です。 |
https://example.com |
| OtherId |
string |
脆弱性 ID。 |
CVE-2020-8597 |
InstanceName
deprecated
|
string |
サーバーインスタンスの名前。 説明
このフィールドは非推奨です。脆弱性の影響を受けるインスタンスをクエリするには、 DescribeVulList を呼び出してください。 |
sql-test-001 |
InternetIp
deprecated
|
string |
サーバーのパブリック IP アドレス。 説明
このフィールドは非推奨です。脆弱性の影響を受けるインスタンスをクエリするには、 DescribeVulList を呼び出してください。 |
47.114.XX.XX |
IntranetIp
deprecated
|
string |
サーバーのプライベート IP アドレス。 説明
このフィールドは非推奨です。脆弱性の影響を受けるインスタンスをクエリするには、 DescribeVulList を呼び出してください。 |
172.19.XX.XX |
TargetId
deprecated
|
string |
スキャンターゲットの ID。 説明
このフィールドは非推奨です。脆弱性の影響を受けるインスタンスをクエリするには、 DescribeVulList を呼び出してください。 |
m-bp17m0pc0xprzbwo**** |
TargetName
deprecated
|
string |
スキャンターゲットの名前。 説明
このフィールドは非推奨です。脆弱性の影響を受けるインスタンスをクエリするには、 DescribeVulList を呼び出してください。 |
frontend |
| CveLink |
string |
CVE 脆弱性の詳細へのリンク。 |
https://avd.aliyun.com/detail/CVE-2022-1184 |
例
成功レスポンス
JSONJSON
{
"RequestId": "EDA40EA3-6265-5900-AD99-C83E4F109CA8",
"Cves": [
{
"Summary": "Chanjet T-Plus is an Internet business management software. There is an unauthorized access vulnerability in one of its interfaces disclosed on the Internet. Attackers can construct malicious requests to upload malicious files to execute arbitrary code and control the server.",
"Complexity": "LOW",
"Product": "Log4j2",
"PocCreateTime": 1554189334000,
"CveId": "CVE-2019-9167",
"CnvdId": "CNVD-2019-9167",
"Reference": "https://example.com",
"CvssScore": "10.0",
"Vendor": "Apache",
"PocDisclosureTime": 1554189334000,
"Classify": "remote_code_execution",
"CvssVector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"VulLevel": "serious",
"ReleaseTime": 1554189334000,
"Title": "Chanjet T-Plus SetupAccount/Upload. Aspx file upload vulnerability(CNVD-2022-60632)",
"Solution": "
At present, Chanjet has urgently released a vulnerability patch to fix the vulnerability. CNVD recommends affected units and users to upgrade to the latest version immediately:↵
https://www.chanjetvip.com/product/goods/goods-detail?id=53aaa40295d458e44f5d3ce5↵
At the same time, organizations and users affected by the vulnerability are requested to immediately follow the steps below to conduct self-inspection and repair work:↵↵
User self-check steps:↵Check whether website/bin/load.aspx.cdcab7d2.compiled, website/bin/App_Web_load.aspx.cdcab7d2.dll, and tplus/Load.aspx files exist locally. If they exist, it means that they have been poisoned, and you must reinstall the system and install the product. patch.↵↵
Non-poisoned users please:↵1) Update the latest product patch.↵2) Install anti-virus software and update the virus database in time.↵3) Upgrade the lower version of IIS and Nginx to IIS10.0 and Windows 2016.↵4) Local installation customers need to confirm whether the backup file is complete as soon as possible, and do off-site backup. Customers on the cloud should enable the mirroring function in time.↵5) Users who fail to update the patch in time can contact Chanjet technical support and take temporary preventive measures such as deleting files.↵↵
Poisoned users please:↵1) Check whether the server has taken regular snapshots or backups. If so, you can restore data through snapshots or backups.↵2) Contact Chanjet technical support to confirm whether it has the conditions and operation methods to restore data from backup files.↵↵↵
If you have any technical problems, please contact Chanjet technical support: 4006600566-9",
"Content": "Apache Shiro is a user authentication and authorization framework for a wide range of rights management applications.↵Recently, Apache Shiro released version 1.7.0, which fixes the Apache Shiro authentication bypass vulnerability (CVE-2020-17510).↵Attackers can bypass Shiro's authentication using malicious requests containing payloads.↵↵Related bugs:↵CVE-2020-17510 Shiro < 1.7.0 Validation Bypass Vulnerability↵CVE-2020-13933 Shiro < 1.6.0 Validation Bypass Vulnerability↵CVE-2020-11989 Shiro < 1.5.3 Validation Bypass Vulnerability↵CVE-2020-1957 Shiro < 1.5.2 Validation Bypass Vulnerability↵CVE-2016-6802 Shiro < 1.3.2 Validation Bypass Vulnerability\nCheck whether the fastjson version currently running on the system is in the affected version and whether safeMode is configured to disable autoType. If it is in the affected version and safeMode is not configured to disable autoType, the vulnerability is considered to exist.",
"Poc": "NewDomain.html\nThe x and y values will need to be changed accordingly\n\n
Authenticated Stored CSRF/XSS - Vonage Modem\n\n\n\n\n\n\n\nalert(1)\" />\n\n\n\n\n\n\n\n\n\n\n \nNewKeyword.html\nThe x and y values will need to be changed accordingly\n\n
Authenticated Stored CSRF/XSS - Vonage Modem\n\n\n\n\n\nalert(1)\" / >\n\n\n\n\n\n\n\n\n\n\n\n",
"Classifys": [
{
"Description": "privilege escalation",
"Classify": "remote_code_execution",
"DemoVideoUrl": "https://example.com"
}
],
"OtherId": "CVE-2020-8597",
"InstanceName": "sql-test-001",
"InternetIp": "47.114.XX.XX",
"IntranetIp": "172.19.XX.XX",
"TargetId": "m-bp17m0pc0xprzbwo****",
"TargetName": "frontend",
"CveLink": "https://avd.aliyun.com/detail/CVE-2022-1184"
}
]
}
エラーコード
|
HTTP ステータスコード |
エラーコード |
エラーメッセージ |
説明 |
|---|---|---|---|
| 400 | InnerError | InnerError | |
| 400 | DataExists | %s data exist | |
| 400 | RdCheckNoPermission | Resource directory account verification has no permission. | |
| 400 | MissingType | Type is mandatory for this action. | |
| 400 | MissingName | Name is mandatory for this action. | |
| 500 | RdCheckInnerError | Resource directory account service internal error. | |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission |
完全なリストについては、「エラーコード」をご参照ください。
変更履歴
完全なリストについては、「変更履歴」をご参照ください。