<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>安全攻防团队</title>
    <link>https://wechat2rss.xlab.app/feed/85da1127d3027be44cf4f3a7b3198c622f8fbe1b.xml</link>
    <description>Tencent A&amp;D Team 关注安全前沿攻防技术研究。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (安全攻防团队)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7BohDQNp3wiazvlgepp6vs0rsHe7Fbf2knIAIpPFYHIBA/0</url>
      <title>安全攻防团队</title>
      <link>https://wechat2rss.xlab.app/feed/85da1127d3027be44cf4f3a7b3198c622f8fbe1b.xml</link>
    </image>
    <item>
      <title>「AI开源组件安全风险」系列二：VulnAgent发现 NVIDIA 3个AI基础设施漏洞，并获官方致谢</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485145&amp;idx=1&amp;sn=a715bdf057310c8fa51676cfd6976a84</link>
      <description>一、 引言：当AI基础设施成为攻击目标随着大语言模型（LLM）的爆发式发展，AI 训练和推理框架已成为支撑整</description>
      <content:encoded><![CDATA[<p><span>腾讯云安全</span> <span>2026-04-03 17:35</span> <span style="display: inline-block;">广东</span></p>




  <p>以下文章来源于：云鼎实验室</p>
  <strong>云鼎实验室</strong>
  <p>腾讯云鼎实验室官方微信公众号</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=838174bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FVL7Qr6N3skiafQQuicfXU3COZBfr4PJgAJYn3YJwNxX6tKhBysNIbPVjguBt4NWZGS8Ojf84kbJRPVxiaTWtlqA8DB5Tn9TV85R2Yazca4QvcQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <h1 style="margin: 10px auto;text-align: center;letter-spacing: 3px;color: rgb(0, 112, 192);font-size: 18px;box-sizing: border-box;text-shadow: rgb(219, 229, 241) 0.111em 0.111em 0.056em;" data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="" style="font-weight: bold;"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">一、 引言：当AI基础设施成为攻击目标</span></span></span></h1><p style="text-align: justify;line-height: 1.75em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">随着大语言模型（LLM）的爆发式发展，AI 训练和推理框架已成为支撑整个行业的关键基础设施。NVIDIA Megatron-LM 作为分布式训练框架的翘楚，在 GitHub 上斩获超过15K Stars，被广泛应用于 GPT、</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">D</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">e</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">e</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">p</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">S</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">e</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">e</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">k</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">、</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">GLM </span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">等主流大模型的训练过程。而 NVIDIA Model Optimizer 则是模型部署优化的核心工具，负责将训练好的模型量化压缩，适配TensorRT-LLM、vLLM 等推理引擎。</span></span></p><p style="text-align: justify;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">而近年来，Megatron-LM、vLLM、Model Optimizer等主流框架频繁披露安全漏洞，这些被视为&#34;AI时代操作系统&#34;的基础设施，其安全水位可能偏低，暴露了模型加载、推理服务等关键环节的安全缺陷。一旦这些漏洞被攻击者利用，其背后价值数</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">亿</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">美元的高性能算力资源将面临劫持风险，核心模型资产亦可能遭到窃取。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">腾讯安全云鼎实验室</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">借助</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">自研</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">漏洞挖掘</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">智能体</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">VulnAgent</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">，</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">对这些主流AI框架进行深度安全审计，连续发现三个高危反序列化漏洞：</span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">CVE-2025-33248</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">、</span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">CVE-2025-33247</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">（Megatron-LM）以及 </span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">CVE-2026-24141</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">（Model Optimizer），</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">均获得 NVIDIA 官方致谢。</span></span></p><p style="margin-bottom: 24px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-backh="311" data-backw="578" data-imgfileid="100013771" data-ratio="0.53774385072095" width="604.7333333333333" data-type="png" data-w="2358" height="325.1916010498688" style="margin-left:0px;margin-top:0px;width:100%;" src="https://wechat2rss.xlab.app/img-proxy/?k=ccf30d2b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FVL7Qr6N3skiaz3ic1aebRDekOYw7icENhlhsnWbMQ6q9rdS2MebrYGfC1R8LxZ9x1UT8TCxSo93nvUmUib6v2FiariaWvic2yV41djkp5kiakuKgnLI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">本文将以这三个漏洞为切入点，重点分析AI基础设施中因</span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">反序列化</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">导致的安全漏洞，剖析AI基础设施面临的系统性安全风险。</span></span></p><h2 style="margin: 10px auto;text-align: center;letter-spacing: 3px;color: rgb(0, 112, 192);font-size: 18px;box-sizing: border-box;text-shadow: rgb(219, 229, 241) 0.111em 0.111em 0.056em;"><span data-font-family="default"><span leaf="" style="font-weight: bold;"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">二、 反序列化漏洞：AI框架中普遍存在的安全问题</span></span></span></h2><h3 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">2.1 什么是反序列化漏洞？</span></span></span></h3><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">反序列化漏洞是 Python 生态中最为危险的漏洞类型之一。当程序使用 pickle、torch.load()、numpy.load()等函数加载数据时，如果数据源被攻击者控制，便可触发任意代码执行。</span></span></p><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">在AI训练场景中，模型文件、数据集文件、量化校准数据等都需要频繁序列化/反序列化，这为攻击者提供了大量的攻击面。</span></span></p><h3 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">2.2 为何AI框架频发此类漏洞？</span></span></span></h3><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">可能原因：</span></span></p><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="">1. </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">功能优先导向</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：AI 框架设计历史上优先考虑训练效率，安全功能滞后。PyTorch 在 2025 年发布的 2.6 版本才默认启用 weights_only=True，此前近9年（2016-2025）允许加载任意对象</span></span></p><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="">2. </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">生态依赖复杂</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：PyTorch 2.6 之前版本、 NumPy 1.16.3 之前版本、Yaml 5.3.1 之前版本及 Pickle 等底层库默认允许反序列化任意对象，缺乏安全边界</span></span></p><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="">3. </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">使用场景特殊</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：模型文件体积庞大（GB级别），安全校验成本高，开发者习惯直接加载，缺乏校验机制</span></span></p><h3 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">2.3 典型案例</span></span></span></h3><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">以下是近年来AI基础设施中已公开的反序列化相关漏洞：</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;border:none;mso-border-alt:solid #CBCDD1 .75pt;mso-yfti-tbllook:1184;mso-padding-alt:0cm 5.4pt 0cm 5.4pt;width:573px;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="119" width="119" style="border: 1pt solid rgb(239, 239, 239);background: rgb(245, 247, 250);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><b style="mso-bidi-font-weight:normal;"><span style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:&#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">组件</span></span></span></b></p></td><td data-colwidth="154" width="192" style="border-top: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);border-bottom: 1pt solid rgb(239, 239, 239);border-image: initial;border-left: none;background: rgb(245, 247, 250);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><b style="mso-bidi-font-weight:normal;"><span style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:&#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞编号</span></span></span></b></p></td><td data-colwidth="300" width="621" style="border-top: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);border-bottom: 1pt solid rgb(239, 239, 239);border-image: initial;border-left: none;background: rgb(245, 247, 250);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><b style="mso-bidi-font-weight:normal;"><span style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:&#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">核心问题</span></span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="119" width="119" style="border-right: 1pt solid rgb(239, 239, 239);border-bottom: 1pt solid rgb(239, 239, 239);border-left: 1pt solid rgb(239, 239, 239);border-image: initial;border-top: none;padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><b style="mso-bidi-font-weight:normal;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:&#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">PyTorch</span></span></span></b></p></td><td data-colwidth="154" width="192" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2024-48063</span></span></span></p></td><td data-colwidth="300" width="621" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">分布式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">RPC</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">框架中</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> RemoteModule </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">反序列化未校验输入，可远程执行任意命令</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="119" width="119" style="border-right: 1pt solid rgb(239, 239, 239);border-bottom: 1pt solid rgb(239, 239, 239);border-left: 1pt solid rgb(239, 239, 239);border-image: initial;border-top: none;padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><b style="mso-bidi-font-weight:normal;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:&#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">Keras</span></span></span></b></p></td><td data-colwidth="154" width="192" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2024-3660</span></span></span></p></td><td data-colwidth="300" width="621" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">加载恶意模型文件时，通过</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> Lambda </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">层注入并执行任意代码，绕过</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> safe_mode </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">防护</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="119" width="119" style="border-right: 1pt solid rgb(239, 239, 239);border-bottom: 1pt solid rgb(239, 239, 239);border-left: 1pt solid rgb(239, 239, 239);border-image: initial;border-top: none;padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><b style="mso-bidi-font-weight:normal;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:&#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">Megatron-LM</span></span></span></b></p></td><td data-colwidth="154" width="192" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2025-23354</span></span></span></p></td><td data-colwidth="300" width="621" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">ensemble_classifier  </span></span></span><span style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">脚本允许攻击者篡改输入并执行任意代码</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;"><td data-colwidth="119" width="119" style="border-right: 1pt solid rgb(239, 239, 239);border-bottom: 1pt solid rgb(239, 239, 239);border-left: 1pt solid rgb(239, 239, 239);border-image: initial;border-top: none;padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><b style="mso-bidi-font-weight:normal;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:&#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">MLflow</span></span></span></b></p></td><td data-colwidth="154" width="192" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2024-37052   ~ 37060</span></span></span></p></td><td data-colwidth="300" width="621" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">模型存储、实验追踪等多个模块存在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> pickle </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">反序列化漏洞，共计</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">9</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">个高危</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE</span></span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;"><td data-colwidth="119" width="119" style="border-right: 1pt solid rgb(239, 239, 239);border-bottom: 1pt solid rgb(239, 239, 239);border-left: 1pt solid rgb(239, 239, 239);border-image: initial;border-top: none;padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><b style="mso-bidi-font-weight:normal;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:&#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">vLLM</span></span></span></b></p></td><td data-colwidth="154" width="192" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2025-62164</span></span></span></p></td><td data-colwidth="300" width="621" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(239, 239, 239);border-right: 1pt solid rgb(239, 239, 239);padding: 7.5pt;"><p style="margin:0cm;line-height:normal;layout-grid-mode:
  both;"><span lang="EN-US" style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">Completions API  </span></span></span><span style="font-family:&#34;PingFang SC&#34;,serif;mso-fareast-font-family:
  &#34;PingFang SC&#34;;mso-bidi-font-family:&#34;PingFang SC&#34;;color:black;"><span leaf=""><span textstyle="" style="font-size: 14px;">中通过恶意嵌入向量触发</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> torch.load() </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">反序列化，导致远程代码执行</span></span></span></p></td></tr></tbody></table><p style="text-align: justify;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">可以看到，不安全的反序列化问题贯穿了从底层框架（PyTorch、Keras）到训练框架（Megatron-LM）、模型管理（MLflow）及推理服务（vLLM）的整个AI技术栈。而本文发现的三个NVIDIA CVE进一步印证了这一趋势。</span></span></p><h2 style="margin: 10px auto;text-align: center;letter-spacing: 3px;color: rgb(0, 112, 192);font-size: 18px;box-sizing: border-box;text-shadow: rgb(219, 229, 241) 0.111em 0.111em 0.056em;"><span data-font-family="default"><span leaf="" style="font-weight: bold;"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">三、 漏洞详解：从不安全反序列化到任意代码执行</span></span></span></h2><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">⚠️ 重要说明：本文涉及的漏洞均已通过 CNVD </span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">和 </span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">NVDB </span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">提交</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">，</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">并获得 NVIDIA 官方确认，官方已发布修复方案。请相关用户及时更新至最新版本以修复相关漏洞，避免因版本滞后导致运行环境暴露于安全风险之中。</span></span></p><h3 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">3.1 Megatron-LM 反序列化漏洞</span></span></span></h3><h4 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">CVE-2025-33248</span></span></h4><h5 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">漏洞原理</span></span></h5><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">Megatron-LM的hybrid_conversion.py 模块用于处理混合 Mamba-Transformer 架构模型在不同并行配置间的转换。这是 Megatron-LM 支持新兴架构的关键组件，直接影响模型的灵活部署能力。漏洞产生的</span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">根本原因</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：在加载模型文件时直接调用 torch.load()，未设置 weights_only=True 参数：</span></span></p><pre style="padding:10px;background-color:#fafafa;border:1px solid #e1e1e1;border-radius:2px;overflow-x: scroll;"><code style="background-color: inherit;" data-tco-code-type="python"><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#708090;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""># get the latest iteration</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">tracker_filename </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> os</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">path</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">join</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">args</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">load_dir</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#39;latest_checkpointed_iteration.txt&#39;</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">with</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">open</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">tracker_filename</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#39;r&#39;</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">as</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> f</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    metastring </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> f</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">read</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">().</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">strip</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">()</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">try</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        iteration </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">int</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">metastring</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">except</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> ValueError</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">raise</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> Exception</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;Invalid iteration found in latest_checkpointed_iteration.txt!&#34;</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">out_iteration </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> iteration </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">if</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">not</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> args</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">reset_iterations </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">else</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">0</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#708090;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""># get model directory and model parallel ranks</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">input_model_dir </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> os</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">path</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">join</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">args</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">load_dir</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#39;iter_{:07d}&#39;</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">format</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">iteration</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">))</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">input_sub_models </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> os</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">listdir</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">input_model_dir</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#708090;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""># load one of the model parallel ranks to get arguments</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">sample_model_file </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> os</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">path</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">join</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">input_model_dir</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> input_sub_models</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">[</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">0</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">],</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;model_optim_rng.pt&#34;</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#708090;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""># 危险：直接执行恶意代码</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">sample_model </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> torch</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">load</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">sample_model_file</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#708090;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""># 默认 weights_only=False</span></span></code></pre><p style="text-align: left;line-height: 1.75em;margin: 16px 0pt;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">在 PyTorch 2.6 之前，torch.load()的默认行为允许加载任意 Python 对象，攻击者可借此执行任意代码。这意味着，一旦用户加载恶意 checkpoint 文件，攻击者精心编造的任意代码就会在目标机器上执行。</span></span></p><h5 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">官方修复方案</span></span></h5><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">CVE-2025-33248 漏洞披露后，Megatron-LM官方修复方案是强制设置 torch 版本为2.6+，从而保证 torch.load() 的参数 weights_only 默认为 True。</span></span></p><pre style="padding:10px;background-color:#fafafa;border:1px solid #e1e1e1;border-radius:2px;overflow-x: scroll;"><code style="background-color: inherit;white-space: pre-wrap;word-wrap: break-word;" data-tco-code-type="makefile"><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">dependencies </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> [</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;torch&gt;=2.6.0&#34;</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">, </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;numpy&#34;</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">, </span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;packaging&gt;=24.2&#34;</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">] </span></span></code></pre><h4 style="text-align: left;line-height: 1.75em;margin: 16px 0pt;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">CVE-2025-33247</span></span></h4><h5 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">漏洞原理</span></span></h5><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">Megatron-LM的pretrain_gpt.py 模块用于 GPT 模型预训练和 SFT（监督微调）。漏洞产生的</span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">根本原因</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：在于其量化配置（Quantization Recipe）加载流程中直接调用yaml.load(Loader=yaml.FullLoader), 而非使用yaml.SafeLoader。</span></span></p><pre style="padding: 10px;background-color: rgb(250, 250, 250);border: 1px solid rgb(225, 225, 225);border-radius: 2px;overflow-x: scroll;margin-bottom: 16px;line-height: 1.75em;"><code style="background-color: inherit;" data-tco-code-type="python"><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 119, 170);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">def</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> from_yaml_file</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">recipe_yaml_path</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(102, 153, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">str</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(154, 110, 58);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">-&gt;</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(102, 153, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">&#34;RecipeConfig&#34;</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">&#34;&#34;&#34;Loads recipe from yaml configuration.&#34;&#34;&#34;</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 119, 170);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">if</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 119, 170);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">not</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> HAVE_YAML</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 119, 170);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">raise</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> ImportError</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(102, 153, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">&#34;yaml is not installed. Please install it with `pip install pyyaml`.&#34;</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 119, 170);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">with</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(102, 153, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">open</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">recipe_yaml_path</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(102, 153, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">&#34;r&#34;</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 119, 170);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">as</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> f</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(112, 128, 144);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""># 危险：直接执行恶意代码</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">        config </span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(154, 110, 58);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> yaml</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">load</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">f</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> Loader</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(154, 110, 58);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">yaml</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">FullLoader</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(112, 128, 144);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">#</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 119, 170);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">return</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> RecipeConfig</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">from_config_dict</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">config</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">)</span></span></code></pre><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">yaml.FullLoader 支持 Python 对象构造标签，攻击者构造恶意 YAML 文件即可在加载时执行任意代码。这意味着，一旦用户加载恶意 YAML 文件，攻击者精心编造的任意代码就会在目标机器上执行。</span></span></p><h5 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">官方修复方案</span></span></h5><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">CVE-2025-33247 漏洞披露后，Megatron-LM 官方修复方案是强制设置 yaml.load() 的参数 Loader 为 SafeLoader。</span></span></p><pre style="padding: 10px;background-color: rgb(250, 250, 250);border: 1px solid rgb(225, 225, 225);border-radius: 2px;overflow-x: scroll;margin-bottom: 16px;line-height: 1.75em;"><code style="background-color: inherit;" data-tco-code-type="python"><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 119, 170);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">with</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(102, 153, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">open</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">recipe_yaml_path</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(102, 153, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">&#34;r&#34;</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 119, 170);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">as</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> f</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">    config </span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(154, 110, 58);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> yaml</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">load</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">f</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> Loader</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(154, 110, 58);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">yaml</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">SafeLoader</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">)</span></span></code></pre><h3 style="text-align: left;line-height: 1.75em;margin: 24px 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">3.2 Model Optimizer 反序列化漏洞（CVE-2026-24141）</span></span></span></h3><h4 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">漏洞</span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">原理</span></span></h4><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">Model Optimizer 的 ONNX 量化模块（modelopt.onnx.quantization）是模型部署前压缩的关键步骤，用于将 FP32 模型量化为 INT8，大幅降低推理成本。漏洞产生的</span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">根本原因</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：在加载量化校准数据时，使用了numpy.load(allow_pickle=True)：</span></span></p><pre style="padding: 10px;background-color: rgb(250, 250, 250);border: 1px solid rgb(225, 225, 225);border-radius: 2px;overflow-x: scroll;margin-bottom: 16px;line-height: 1.75em;"><code style="background-color: inherit;" data-tco-code-type="python"><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(112, 128, 144);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""># 不安全的实现</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">calibration_data </span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(154, 110, 58);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> np</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">load</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">args</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">calibration_data_path</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf=""> allow_pickle</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(154, 110, 58);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 0, 85);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">True</span></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(153, 153, 153);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">)</span></span></code></pre><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">NumPy的allow_pickle参数在True时，可加载包含任意Python对象的.npy文件，与pickle模块存在相同的安全风险。这意味着，一旦用户加载恶意文件，攻击者精心编造的任意代码就会在目标机器上执行。</span></span></p><h4 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">官方修复方案</span></span></h4><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">CVE-2026-24141漏洞披露后，Model Optimizer官方修复方案是在加载量化校准数据时采用用户的输入参数trust_calibration_data，默认值False：</span></span></p><pre style="padding: 10px;background-color: rgb(250, 250, 250);border: 1px solid rgb(225, 225, 225);border-radius: 2px;overflow-x: scroll;margin-bottom: 16px;line-height: 1.75em;"><code style="background-color: inherit;" data-tco-code-type="plain text"><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">calibration_data = np.load(</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">    args.calibration_data_path, allow_pickle=args.trust_calibration_data</span></span><span leaf=""><br/></span><span style="font-size: 10.5pt;font-family: &#34;Courier New&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="Monaco"><span leaf="">)</span></span></code></pre><h2 style="margin: 10px auto;text-align: center;letter-spacing: 3px;color: rgb(0, 112, 192);font-size: 18px;box-sizing: border-box;text-shadow: rgb(219, 229, 241) 0.111em 0.111em 0.056em;"><span data-font-family="default"><span leaf="" style="font-weight: bold;"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">四、 AI基础设施面临的三重风险</span></span></span></h2><h3 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">4.1 算力资产劫持风险</span></span></span></h3><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">算力即金钱</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">。现代 GPU 集群的算力价值远超传统服务器：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">单卡价值高昂</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：NVIDIA H100单卡售价约2.5～3万美元，一个千卡训练集群的硬件价值可达数千万美元</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">训练成本惊人</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：据公开报道估算，GPT-4的训练成本超过1亿美元；Meta 训练 Llama 3 使用了 16,000 张 H100，消耗超过 2,000万 GPU 小时攻击者通过反序列化漏洞获得服务器控制权后，可：</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">挖矿牟利</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：部署加密货币挖矿程序，持续消耗高价 GPU 算力</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">算力盗用</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：私自运行模型训练任务，窃取企业算力资源</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 0px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">资源转售</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：将算力挂到黑市二次租赁，非法牟利</span></span></p></li></ul><h3 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">4.2 模型资产窃取风险</span></span></span></h3><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">大模型训练成本动辄数百上千万美元，模型权重是企业的核心资产：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">直接窃取</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：下载模型文件（数十GB至数百GB）</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 0px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">数据泄露</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：窃取训练数据集，可能包含敏感信息</span></span></p></li></ul><h3 style="text-align: left;line-height: 1.75em;margin: 0px 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">4.3 供应链污染风险</span></span></span></h3><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">AI模型供应链呈现**“中心化+长链条”**特征：</span></span></p><p style="margin-bottom: 24px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-backh="323" data-backw="578" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/VL7Qr6N3skjCA2vNkG81HlYgO7ICH5zlwAm2SoZoibnQ20IECdC44rhkoX1mrc5cYZU2U8PyBUccbubh5cqYqa3tvVQCLia93JzPa5JocWa6M/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="323" data-imgfileid="100013776" data-ratio="0.5581395348837209" data-s="300,640" style="margin-left:0px;margin-top:0px;width:100%;" data-type="png" data-w="1376" src="https://wechat2rss.xlab.app/img-proxy/?k=e1cc0916&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FVL7Qr6N3skjCA2vNkG81HlYgO7ICH5zlwAm2SoZoibnQ20IECdC44rhkoX1mrc5cYZU2U8PyBUccbubh5cqYqa3tvVQCLia93JzPa5JocWa6M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">攻击者只需在任一环节注入恶意代码：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">预训练模型投毒</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：在 Hugging Face 等平台上传含恶意 pickle 的模型文件，用户加载后即触发代码执行</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">量化数据投毒</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：构造恶意量化校准数据（.npy文件），在模型量化环节触发代码执行</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">训练配置投毒</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：发布恶意训练配置，加载时触发代码执行</span></span></p></li></ul><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">此次发现的三个CVE正是典型的供应链攻击节点</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">Megatron-LM 负责训练阶段（源头） </span></span></p></li><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">Model Optimizer 负责部署阶段（出口）</span></span></p></li></ul><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">一旦被利用，可实现对整个AI生产链的渗透。</span></span></p><h2 style="margin: 10px auto;text-align: center;letter-spacing: 3px;color: rgb(0, 112, 192);font-size: 18px;box-sizing: border-box;text-shadow: rgb(219, 229, 241) 0.111em 0.111em 0.056em;"><span data-font-family="default"><span leaf="" style="font-weight: bold;"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">五、 </span></span></span><span data-font-family="default"><span leaf="" style="font-weight: bold;"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">安全缓解措施</span></span></span></h2><h3 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">5.1 安全编码规范</span></span></span></h3><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">禁用不安全的反序列化调用</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：在代码中严格避免使用 torch.load() 的默认参数，强制设置 weights_only=True；使用 yaml.SafeLoader 替代 yaml.FullLoader；禁止 numpy.load(allow_pickle=True) 加载不可信数据</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">升级依赖版本</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：将 PyTorch 升级至 2.6+ 版本（默认启用 weights_only=True）；将 PyYAML 升级至 6.0+ 版本；定期使用 SCA 工具扫描第三方依赖的已知漏洞</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">使用安全数据格式</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：优先采用 Safetensors 格式替代传统的 .pt/.pkl 模型文件，从根本上杜绝反序列化攻击面；量化校准数据使用 JSON、CSV 等纯数据格式替代 .npy（pickle模式）</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">代码安全审查</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：使用 SAST 工具自动化扫描 pickle.load()、torch.load()、yaml.load(FullLoader)、numpy.load(allow_pickle=True) 等危险调用模式，将安全检查纳入 CI/CD 流程</span></span></p></li></ul><h3 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">5.2 模型文件与数据完整性校验</span></span></span></h3><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">来源验证</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：仅从官方渠道或可信源获取模型文件和预训练权重，避免使用来路不明的 checkpoint 文件</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">哈希校验</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：对模型文件、量化校准数据、训练配置文件进行 SHA-256 哈希校验，确保文件未被篡改</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">模型扫描</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：在加载前使用安全工具（如 Hugging Face 的 picklescan）扫描模型文件中是否包含恶意序列化对象</span></span></p></li></ul><h3 style="text-align: left;line-height: 1.75em;margin: 0pt 0pt 16px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">5.3 运行环境隔离</span></span></span></h3><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">最小权限原则</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：AI 训练和推理服务以非 root 用户运行，限制文件系统和网络访问权限</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">容器化部署</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：使用容器隔离训练/推理环境，限制容器的系统调用能力（如通过 seccomp、AppArmor 策略）</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">网络隔离</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：训练集群与外部网络严格隔离，仅开放必要的数据传输通道，防止攻击者在获取代码执行权限后进行横向移动或数据外传</span></span></p></li></ul><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">注：腾讯安全产品已全线支持上述漏洞的检测。</span></span></p><h2 style="margin: 10px auto;text-align: center;letter-spacing: 3px;color: rgb(0, 112, 192);font-size: 18px;box-sizing: border-box;text-shadow: rgb(219, 229, 241) 0.111em 0.111em 0.056em;"><span data-font-family="default"><span leaf="" style="font-weight: bold;"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">六、 结语</span></span></span></h2><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">此次针对 NVIDIA Megatron-LM 与 Model Optimizer 的安全研究表明，反序列化风险已成为AI基础设施中不可忽视的系统性安全短板</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：</span></span></p><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="">1. </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">漏洞普遍性</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：三个高危漏洞分布在预训练和后训练两个关键环节，涵盖模型文件加载、量化配置解析、校准数据加载等核心流程</span></span></p><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="">2. </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">影响严重性</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：可导致算力劫持、模型窃取、供应链污染，直接威胁价值数</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">亿</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">美元的GPU集群和核心模型资产</span></span></p><p style="text-align: left;line-height: 1.75em;margin: 3pt 0pt 16px;"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="">3. </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">生态脆弱性</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">：在供应链场景下，从代码缺陷到攻击实现的路径清晰且利用门槛低，攻击者仅需构造恶意模型文件或配置文件即可触发远程代码执行</span></span></p><h2 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">附录：</span></span></span></h2><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&amp;mid=2247497370&amp;idx=1&amp;sn=ce01885156e6575b6f57b984bd30a294&amp;scene=21#wechat_redirect" textvalue="「AI开源组件安全风险」系列一：配置缺陷，让你的GPU沦为矿机" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">「AI开源组件安全风险」系列一：配置缺陷，让你的 GPU 沦为矿机</span></a></span></span></p><div data-role="outer" data-lazy-bgimg="https://mmbiz.qpic.cn/mmbiz_png/7QRTvkK2qC4bpSQicpqMN82g7At53DQLBRLQ2ABo8ekbheKN2wEibo9BJyYFx8DOk9K3GBEgrB2dXU02wK4fOfnA/640?wx_fmt=jpeg" data-fail="0" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-size: auto;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=43963a41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7QRTvkK2qC4bpSQicpqMN82g7At53DQLBRLQ2ABo8ekbheKN2wEibo9BJyYFx8DOk9K3GBEgrB2dXU02wK4fOfnA%2F640%3Fwx_fmt%3Djpeg%26tp%3Dwebp%26wxfrom%3D15%26wx_lazy%3D1&#34;);font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;background-position: left top;background-repeat: repeat;" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="101592" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;line-height: 1.5em;"><div hm_fix="385:564" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;width: 32px;"><img alt="图片" class="__bg_gif rich_pages wxw-img" data-aistatus="1" data-ratio="0.8768115942028986" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;display: block;visibility: visible !important;width: 32px !important;" data-type="gif" data-w="276" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=21cdffce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FFIBZec7ucChYUNicUaqntiamEgZ1ZJYzLRasq5S6zvgt10NKsVZhejol3iakHl3ItlFWYc8ZAkDa2lzDc5SHxmqjw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D7"/></p><p data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 2px 0em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">END</span></strong></p></div></div></div></div><div data-role="paragraph" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(163, 163, 163);text-align: center;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div data-id="86318" data-tools="135编辑器" data-color="#3d8ed1" data-custom="#3d8ed1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 5px 1em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 8px 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关注云鼎实验室，获取更多安全情报</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;text-align: center;"><img alt="图片" class="rich_pages wxw-img" data-aistatus="1" data-backh="337" data-backw="561" data-copyright="0" data-ratio="0.6" data-s="300,640" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;letter-spacing: 0.54px;width: 389px !important;visibility: visible !important;" data-type="jpeg" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=eecbedb7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Djpeg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D8"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=82f2e5a7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485145%26idx%3D1%26sn%3Da715bdf057310c8fa51676cfd6976a84">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 03 Apr 2026 17:35:00 +0800</pubDate>
    </item>
    <item>
      <title>「AI开源组件安全风险」系列一：配置缺陷，让你的GPU沦为矿机</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485143&amp;idx=1&amp;sn=27a9c05f556f2aa6aaba628a2c0a45d1</link>
      <description>AI开源组件的 Web 安全水位可能偏低，而其背后的高性能算力资源却成为黑产眼中的&#34;香饽饽&#34;。</description>
      <content:encoded><![CDATA[<p><span>云鼎实验室</span> <span>2026-03-17 16:45</span> <span style="display: inline-block;">广东</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d92f661c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuzMNlw2o2BLUGsGAibtrRSpoqzxEdU9Ik1G7bM6zn7Dm7TobGibHqEGRicYAwNicPks6cCqKwiaTy9ES28wO4eGVhdZqCWRrqevib50VAYcOiajZHQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>AI开源组件的 Web 安全水位可能偏低，而其背后的高性能算力资源却成为黑产眼中的"香饽饽"。</p>
  <div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: break-spaces;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: block;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant-ligatures: none;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);font-size: 16px;visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;background-color: rgba(255, 255, 255, 0);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: block;font-size: 20px;color: rgb(1, 82, 217);letter-spacing: 1px;line-height: 1.6;font-family: PingFangSC-light;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 18px;">一</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 18px;">引言</span></span></strong></em></p></div></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);letter-spacing: normal;line-height: 2em;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">随着生成式AI技术的快速发展，ComfyUI、Stable Diffusion WebUI 等AI开源组件已成为 AI 应用开发的基础设施。然而，在这些组件快速迭代的背后，一个容易被忽视的安全问题正在浮现：</span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">AI开源组件的 Web 安全水位可能偏低，而其背后的高性能算力资源却成为黑产眼中的&#34;香饽饽&#34;</span><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);letter-spacing: normal;line-height: 2em;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">腾讯安全云鼎实验室长期聚焦于 </span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">AI 组件生态的安全风险研究</span><span textstyle="" style="font-size: 15px;">，对主流AI开源组件进行了系统性的安全分析，发现了多类普遍存在的安全隐患。本文是「AI开源组件安全风险分析」系列的第一篇，将重点分析AI开源组件中因</span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">配置缺陷</span><span textstyle="" style="font-size: 15px;">导致的安全漏洞——包括组件自身的设计缺陷，以及用户部署时的配置失误，并结合真实云上攻击案例进行深度剖析。后续我们将持续披露更多研究成果（如供应链安全，AI Infra安全等），敬请关注。</span></span></span></p><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div powered-by="xiumi.us" data-pm-slice="3 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;powered-by&#34;:&#34;xiumi.us&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;background-color: rgba(255, 255, 255, 0);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-size: 20px;color: rgb(1, 82, 217);letter-spacing: 1px;line-height: 1.6;font-family: PingFangSC-light;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 18px;">二</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 18px;">AI开源组件配置缺陷</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 18px;">一个普遍存在的安全问题</span></span></strong></em></p></div></div></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);letter-spacing: normal;line-height: 2em;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">近年来，多个主流 AI 开源组件被披露存在因配置缺陷导致的高危问题。这类问题往往具有共同特点：</span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">组件为了易用性/可扩展性，提供了“可远程触发的高权限能力”；而默认配置、暴露面判断或配套鉴权措施不足时，就会被攻击者利用</span><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);letter-spacing: normal;line-height: 2em;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(1, 82, 217);font-weight: bold;font-style: italic;">典型案例（公开披露）</span></span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7463087248322148" data-s="300,640" data-type="png" data-w="745" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;visibility: visible !important;width: 676.992px !important;" type="block" data-imgfileid="100013705" src="https://wechat2rss.xlab.app/img-proxy/?k=41e33896&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FVL7Qr6N3skjRy6752JRa2PxHlsY73LVjJpKUkbnfZvibUXgmbcE1L4OiadXcF97jeadcPN9fLwhRSvsEQkIrUBsn8UkeMJBIMUhLgxSicoM1Yc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D0"/></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);letter-spacing: normal;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">这些漏洞揭示了AI开源组件在安全设计上的共性问题：</span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">为了追求功能的灵活性和易用性，可能忽视了安全边界的控制</span><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);letter-spacing: normal;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">在对 AI 组件生态进行横向观察时，我们发现 </span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">Stable Diffusion WebUI（下称 SD WebUI）同样存在典型的“配置缺陷”风险</span><span textstyle="" style="font-size: 15px;">。更值得关注的是：即便某些保护机制已在项目侧引入，仍会因为“反向代理暴露、端口转发、多用户共享、升级滞后”等现实部署场景，导致公网中持续存在大量高风险实例。</span></span></span></p><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" data-pm-slice="3 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;powered-by&#34;:&#34;xiumi.us&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;background-color: rgba(255, 255, 255, 0);"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-size: 20px;color: rgb(1, 82, 217);letter-spacing: 1px;line-height: 1.6;font-family: PingFangSC-light;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">三</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">深度分析</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">Stable Diffusion WebUI的配置缺陷</span></span></strong></em></p></div></div></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);letter-spacing: normal;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">⚠️ </span></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">重要说明：</span><span textstyle="" style="font-size: 15px;">此漏洞于</span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">2023年</span><span textstyle="" style="font-size: 15px;">被披露，属于已知的Nday漏洞（CNVD-2023-81119）。</span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">官方已提供有效修复方案</span><span textstyle="" style="font-size: 15px;">——通过 disable_extension_access 参数默认禁止公网环境下的远程扩展安装。</span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">请所有用户立即检查并更新至最新版本，并参照本文末尾「安全配置建议」进行安全加固，避免因配置不当或版本滞后导致实例暴露于风险之中</span><span textstyle="" style="font-size: 15px;">。</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="background-color: rgb(0, 82, 255);color: rgb(255, 255, 255);font-weight: bold;">3.1 漏洞原理</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">漏洞的原理非常直接：攻击者可以远程安装恶意扩展插件，从而实现任意代码执行。 在SD WebUI的代码中，扩展安装流程会直接执行插件目录下的install.py脚本：</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);"><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="python"><code><span leaf=""><span class="code-snippet__comment"># SD WebUI 扩展安装代码（简化）</span></span></code><br/><code><span leaf=""><span class="code-snippet__keyword">def</span> <span class="code-snippet__title">run_extension_installer</span>(<span class="code-snippet__params">extension_dir</span>):</span></code><br/><code><span leaf="">    path_installer = os.path.join(extension_dir, <span class="code-snippet__string">&#34;install.py&#34;</span>)</span></code><br/><code><span leaf="">ifnot os.path.isfile(path_installer):</span></code><br/><code><span leaf=""><span class="code-snippet__keyword">return</span></span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""><span class="code-snippet__keyword">try</span>:</span></code><br/><code><span leaf="">        env = os.environ.copy()</span></code><br/><code><span leaf="">        env[<span class="code-snippet__string">&#39;PYTHONPATH&#39;</span>] = <span class="code-snippet__string">f&#34;</span><span class="code-snippet__string"><span class="code-snippet__subst">{script_path}{os.pathsep}{env.get(</span></span><span class="code-snippet__string"><span class="code-snippet__subst"><span class="code-snippet__string">&#39;PYTHONPATH&#39;</span></span></span><span class="code-snippet__string"><span class="code-snippet__subst">, </span></span><span class="code-snippet__string"><span class="code-snippet__subst"><span class="code-snippet__string">&#39;&#39;</span></span></span><span class="code-snippet__string"><span class="code-snippet__subst">)}</span></span><span class="code-snippet__string">&#34;</span></span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">        <span class="code-snippet__comment"># 危险：直接执行远程扩展的install.py脚本</span></span></code><br/><code><span leaf="">stdout = run(<span class="code-snippet__string">f&#39;&#34;</span><span class="code-snippet__string"><span class="code-snippet__subst">{python}</span></span><span class="code-snippet__string">&#34;&#34;</span><span class="code-snippet__string"><span class="code-snippet__subst">{path_installer}</span></span><span class="code-snippet__string">&#34;&#39;</span>, </span></code><br/><code><span leaf="">                    errdesc=<span class="code-snippet__string">f&#34;Error running install.py for extension </span><span class="code-snippet__string"><span class="code-snippet__subst">{extension_dir}</span></span><span class="code-snippet__string">&#34;</span>)</span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">if</span> stdout:</span></code><br/><code><span leaf="">            <span class="code-snippet__built_in">print</span>(stdout)</span></code><br/><code><span leaf="">    <span class="code-snippet__keyword">except</span> Exception <span class="code-snippet__keyword">as</span> e:</span></code><br/><code><span leaf="">        errors.report(<span class="code-snippet__built_in">str</span>(e))</span></code><br/></pre></p></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">这意味着，一旦用户安装了恶意扩展，攻击者编写的任意Python代码就会在目标机器上执行。</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="background-color: rgb(0, 82, 255);color: rgb(255, 255, 255);font-weight: bold;">3.2 官方修复方案</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">CNVD-2023-81119漏洞披露后，SD WebUI官方的修复方案</span><span textstyle="" style="font-size: 15px;">是在安装远程插件之前增加了检查机制：</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);"><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="python"><code><span leaf=""><span class="code-snippet__comment"># 安装前的安全检查（官方修复）</span></span></code><br/><code><span leaf=""><span class="code-snippet__keyword">if</span> disable_extension_access == <span class="code-snippet__literal">True</span>:</span></code><br/><code><span leaf=""><span class="code-snippet__keyword">return</span>  <span class="code-snippet__comment"># 禁止远程安装扩展</span></span></code><br/></pre></p></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">关键参数：disable_extension_access</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">这个参数是官方修复的核心，其值由多个启动配置共同决定：</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);"><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="ini"><code><span leaf=""><span class="code-snippet__comment"># disable_extension_access 的判断逻辑</span></span></code><br/><code><span leaf=""><span class="code-snippet__attr">is_exposed_to_internet</span> = any([</span></code><br/><code><span leaf="">    cmd_opts.share,        <span class="code-snippet__comment"># --share: 使用Gradio公共分享链接</span></span></code><br/><code><span leaf="">    cmd_opts.listen,       <span class="code-snippet__comment"># --listen: 监听0.0.0.0允许外部访问</span></span></code><br/><code><span leaf="">    cmd_opts.ngrok,        <span class="code-snippet__comment"># --ngrok: 使用ngrok隧道</span></span></code><br/><code><span leaf="">    cmd_opts.server_name   <span class="code-snippet__comment"># --server-name: 指定非默认服务器名称</span></span></code><br/><code><span leaf="">])</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""><span class="code-snippet__attr">disable_extension_access</span> = is_exposed_to_internet andnot cmd_opts.enable_insecure_extension_access</span></code><br/></pre></p></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">官方修复后的安全逻辑解析：</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3627232142857143" data-s="300,640" data-type="png" data-w="896" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;width: 661px !important;visibility: visible !important;" type="block" data-backw="562" data-backh="204" data-imgfileid="100045381" src="https://wechat2rss.xlab.app/img-proxy/?k=7e38f3fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiczOE5KEJun494Bgt7bzOJ36jMeibB6n1e2iaRomtk0Prk5pJaibicnUrBVhdicw4obzTyCHSYqfae56ANThdEviaOzGxK7waZSIbGYzibzjlx3CzRM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D1"/></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="background-color: rgb(0, 82, 255);color: rgb(255, 255, 255);font-weight: bold;">3.3 为什么公网仍存在大量可攻击实例</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">虽然官方已经默认对开到公网的服务加了限制，但我们实际发现</span><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">外网的机器多数都开启了扩展安装功能，可被此漏洞攻击</span><span textstyle="" style="font-size: 15px;">。</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">可能的原因：</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">服务开启在本地，通过反向代理或端口转发暴露到公网：</span><span textstyle="" style="font-size: 15px;">用户在本地启动SD WebUI（此时扩展安装默认开启），然后通过Nginx反向代理、frp、ngrok、Cloudflare Tunnel等方式将服务暴露到公网。由于SD WebUI检测不到公网暴露，安全限制不会生效。</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">主动开启了 --enable-insecure-extension-access：</span><span textstyle="" style="font-size: 15px;">部分用户为了便利性，在启动命令中添加了此参数，强制允许远程安装扩展。</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">使用的 Stable Diffusion WebUI 版本很老：</span><span textstyle="" style="font-size: 15px;">2023年修复前的旧版本（&lt;=1.6.0）完全没有 disable_extension_access 安全检查，任何公网可访问的实例都可被直接攻击。</span></span></p></li></ul><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" data-pm-slice="3 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;powered-by&#34;:&#34;xiumi.us&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;background-color: rgba(255, 255, 255, 0);"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-size: 20px;color: rgb(1, 82, 217);letter-spacing: 1px;line-height: 1.6;font-family: PingFangSC-light;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">四</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">云上威胁态势</span></span></strong></em></p></div></div></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">通过腾讯云主机安全和网络入侵等产品的安全感知能力，我们捕获到多起真实的云上 SD WebUI 失陷事件，以其中一次真实入侵事件为例，还原了攻击者从初始入侵到挖矿牟利的完整攻击链路。</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.9916666666666667" data-s="300,640" data-type="png" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;width: 661px !important;visibility: visible !important;" type="block" data-backw="562" data-backh="557" data-imgfileid="100045382" src="https://wechat2rss.xlab.app/img-proxy/?k=9e4eea7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiczOE5KEJun5icKo04Diczd4NibYdmMeHYuiafTKWZkNd9BAQrOpgLfh3ttU81yEtWSUNlnichGyHW7DiaLsKEdzK3nIlSAJiaiclDn16vWmD7Iqv7to%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D2"/></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">整个攻击过程分为以下四个阶段：</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">阶段一：初始入侵。</span><span textstyle="" style="font-size: 15px;">受害主机以 --listen 模式启动 SD WebUI，扩展安装 API 暴露于公网。攻击者远程安装了恶意扩展，安装后即为攻击者提供了一个持久化的 Web Shell。</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">阶段二：信息收集。</span><span textstyle="" style="font-size: 15px;">攻击者通过 Web Shell 执行了 whoami、ps aux、lscpu、uname -a、nvidia-smi 等命令，快速确认当前用户权限、运行环境和 GPU 算力情况，评估主机的利用价值。</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">阶段三：持久化。</span><span textstyle="" style="font-size: 15px;">攻击者下载并安装了 sshx 远程终端工具，随后执行 sshx -q &gt; /var/tmp/sshx_link.txt 生成远程访问链接。sshx 是一个开源工具，被攻击者滥用为反向隧道后门，通过浏览器即可获得完整 Shell 权限，属于无文件持久化技术，更难被检测。</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">阶段四：目标达成。</span><span textstyle="" style="font-size: 15px;">攻击者下载 XMRig v6.22.2 挖矿程序，将其重命名为 rdxr 以规避进程名检测，连接矿池。最终通过 nohup + trap + while true 无限循环实现持久化挖矿，确保进程被杀死后自动重启。</span></span></p></li></ul><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;powered-by&#34;:&#34;xiumi.us&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;background-color: rgba(255, 255, 255, 0);"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-size: 20px;color: rgb(1, 82, 217);letter-spacing: 1px;line-height: 1.6;font-family: PingFangSC-light;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">五、核心问题</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">高性能算力成为黑产新目标</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">行业特点导致安全水位偏低</span></span></strong></em></p></div></div></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="background-color: rgb(0, 82, 255);color: rgb(255, 255, 255);font-weight: bold;">5.1 传统Web应用 vs AI开源组件</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.6156941649899397" data-s="300,640" data-type="png" data-w="497" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;width: 661px !important;visibility: visible !important;" type="block" data-backw="497" data-backh="306" data-imgfileid="100013706" src="https://wechat2rss.xlab.app/img-proxy/?k=2037c0d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FVL7Qr6N3skj72hFzQ1Aw7ibN1uQRrtWzTALryiaUw76ELawusluib1LYBVm0jRUGlwktSwpFgIy5RV4ibZozlpIpyKfuNicBtJTMK26qNVtegX5I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D3"/></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="background-color: rgb(0, 82, 255);color: rgb(255, 255, 255);font-weight: bold;">5.2 黑产的新目标：高性能GPU算力</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">AI开源组件的典型硬件配置：</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">消费级：</span><span textstyle="" style="font-size: 15px;">RTX 4090（24GB显存）</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">专业级：</span><span textstyle="" style="font-size: 15px;">NVIDIA A10（24GB显存）</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">企业级：</span><span textstyle="" style="font-size: 15px;">A100（40GB/80GB显存）</span></span></p></li></ul><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">这些GPU的算力价值：</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">挖矿收益：</span><span textstyle="" style="font-size: 15px;">单张4090每日可产生5-10美元的挖矿收益</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">AI算力租赁：</span><span textstyle="" style="font-size: 15px;">A100的云端租赁价格高达每小时2-4美元</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">规模化攻击：</span><span textstyle="" style="font-size: 15px;">批量控制100台机器，月收益可达数万美元</span></span></p></li></ul><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="background-color: rgb(0, 82, 255);color: rgb(255, 255, 255);font-weight: bold;">5.3 为什么AI开源组件安全水位偏低？</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">技术栈侧重不同</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">AI 组件开发者通常更专注于模型算法与推理效果，Web 安全并非其核心关注领域</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">这与传统 Web 开发团队长期积累的安全经验形成了客观差异</span></span></p></li></ul><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">快速发展阶段的共性挑战</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">AI 开源生态正处于高速发展期，功能迭代速度快，安全审查机制尚在完善中 </span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">第三方扩展生态蓬勃发展的同时，统一的安全规范和准入标准仍在建立过程中</span></span></p></li></ul><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">部署场景的复杂性</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">部分组件在设计时主要面向本地或可信环境使用</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">但实际部署中，公网暴露、反向代理转发、多用户共享等场景较为普遍，超出了原始设计预期</span></span></p></li></ul><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">依赖管理的混乱</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">Python等语言生态的依赖问题</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">扩展插件权限过高</span></span></p></li></ul><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;powered-by&#34;:&#34;xiumi.us&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;background-color: rgba(255, 255, 255, 0);"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-size: 20px;color: rgb(1, 82, 217);letter-spacing: 1px;line-height: 1.6;font-family: PingFangSC-light;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">六</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">纵深防御</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">如何保护AI开源组件安全</span></span></strong></em></p></div></div></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">面对AI开源组件的安全威胁，需要从网络边界到主机层面构建纵深防御体系。</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="background-color: rgb(0, 82, 255);color: rgb(255, 255, 255);font-weight: bold;">6.1 腾讯云安全产品方案</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.45555555555555555" data-s="300,640" data-type="png" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;width: 661px !important;visibility: visible !important;" type="block" data-backw="562" data-backh="256" data-imgfileid="100013709" src="https://wechat2rss.xlab.app/img-proxy/?k=934a056d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FVL7Qr6N3skjaxZEJRdmv34icsTvUyibzLWyO8w7MBBJRvprX46WpfoqJibVibBHyGwFIayVNcR0fPfNKBMKLRQGhOf4x4UXhPmib0evUZic3v8dgE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D4"/></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">腾讯云NDR 腾讯云容器安全入侵防御模块支持对漏洞的后利用恶意行为的检测</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5296296296296297" data-s="300,640" data-type="png" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;width: 661px !important;visibility: visible !important;" type="block" data-backw="562" data-backh="298" data-imgfileid="100045386" src="https://wechat2rss.xlab.app/img-proxy/?k=210b6f75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiczOE5KEJun70fK3MyicEpzzWPlekEEj4QBFDasOD03fONtpwMsJSiaXSzzgyXv80B8I5Tu2E47hHibpktK25TnTB1dl80Ld6x2ic3K91YXlQVkQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="background-color: rgb(0, 82, 255);color: rgb(255, 255, 255);font-weight: bold;">6.2 安全配置建议</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">优先本地访问：</span><span textstyle="" style="font-size: 15px;">默认仅监听本地地址，避免直接暴露公网</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">启用认证：</span><span textstyle="" style="font-size: 15px;">如需远程访问，务必配置访问认证</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;color: rgb(1, 82, 217);font-weight: bold;">反向代理加固：</span><span textstyle="" style="font-size: 15px;">如通过Nginx反向代理，可以在配置时添加基础认证</span></span></p></li></ul><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;powered-by&#34;:&#34;xiumi.us&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;background-color: rgba(255, 255, 255, 0);"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-size: 20px;color: rgb(1, 82, 217);letter-spacing: 1px;line-height: 1.6;font-family: PingFangSC-light;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">七</span></span></strong></em></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><em style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: italic;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 18px;">结语</span></span></strong></em></p></div></div></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">本文作为「AI开源组件安全风险分析」系列的第一篇，重点分析了因配置缺陷导致的安全漏洞。从ComfyUI-Manager到Stable Diffusion WebUI，我们看到：</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">AI开源组件的扩展安装机制普遍缺乏安全控制</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">配置参数的复杂性增加了用户出错的概率</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;text-align: justify;text-indent: 0em;color: rgb(63, 63, 63);font-family: PingFangSC-light;font-size: 16px;letter-spacing: 1px;"><span textstyle="" style="font-size: 15px;">公网中仍存在大量可被攻击的脆弱实例</span></span></p></li></ul><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-role="outer" label="edit by 135editor" data-pm-slice="4 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;powered-by&#34;:&#34;xiumi.us&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;powered-by&#34;:&#34;xiumi.us&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;powered-by&#34;:&#34;xiumi.us&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><div data-tools="135编辑器" data-id="145837" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;flex-direction: column;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 15px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;border: 1px solid rgb(1, 82, 217);"><div data-autoskip="1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 10px 0px 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;text-align: justify;line-height: 1.75em;letter-spacing: 1.5px;font-size: 16px;color: rgb(51, 51, 51);background-color: transparent;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(1, 82, 217);font-size: 14px;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(1, 82, 217);letter-spacing: 1px;font-family: PingFangSC-Light;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关于我们</span></span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;font-size: 14px;font-family: PingFangSC-Light;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">腾讯安全云鼎实验室长期深耕云安全领域，持续关注AI生态的安全问题。</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;font-size: 14px;font-family: PingFangSC-Light;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">腾讯云提供完整的云原生安全产品矩阵，可有效应对AI开源组件面临的安全威胁：</span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;font-size: 14px;font-family: PingFangSC-Light;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(1, 82, 217);font-weight: bold;">腾讯云主机安全：</span>漏洞检测能力，实时监控异常进程，阻断恶意程序，主机安全的最后一道防线。</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;font-size: 14px;font-family: PingFangSC-Light;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(1, 82, 217);font-weight: bold;">腾讯云WAF：</span>支持Web漏洞的检测和防护。</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;font-size: 14px;font-family: PingFangSC-Light;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(1, 82, 217);font-weight: bold;">腾讯云防火墙：</span>精细化的访问控制和入侵防御。</span></span></p></li></ul><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;font-size: 14px;font-family: PingFangSC-Light;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(1, 82, 217);font-weight: bold;">腾讯云NDR：</span>网络流量深度分析，发现C2通信和横向移动。</span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span></span></p></li></ul></div></div></div></div></div></div></div></div></div></div></span></p><div hm_fix="385:564" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 32px;"><img data-aistatus="1" alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="0.8768115942028986" data-type="gif" data-w="276" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;display: block;width: 32px !important;visibility: visible !important;" data-width="100%" data-imgfileid="100012836" src="https://wechat2rss.xlab.app/img-proxy/?k=fd44b5e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FFIBZec7ucChYUNicUaqntiamEgZ1ZJYzLRasq5S6zvgt10NKsVZhejol3iakHl3ItlFWYc8ZAkDa2lzDc5SHxmqjw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D45"/></p><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px 0em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">END</span></strong></p></div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;color: rgb(163, 163, 163);text-align: center;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div data-role="paragraph" data-color="#1e9be8" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-id="86318" data-tools="135编辑器" data-color="#3d8ed1" data-custom="#3d8ed1" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 5px 1em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关注云鼎实验室，获取更多安全情报</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;min-height: 1em;color: rgb(163, 163, 163);letter-spacing: 0.54px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.6" data-s="300,640" data-type="jpeg" data-w="900" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;letter-spacing: 0.54px;width: 358px !important;visibility: visible !important;" data-copyright="0" data-imgfileid="100012835" src="https://wechat2rss.xlab.app/img-proxy/?k=29f21172&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D46"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b42600b7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485143%26idx%3D1%26sn%3D27a9c05f556f2aa6aaba628a2c0a45d1">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 17 Mar 2026 16:45:00 +0800</pubDate>
    </item>
    <item>
      <title>OpenClaw 新型绕过漏洞，上榜企业必修安全漏洞清单</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485138&amp;idx=1&amp;sn=6bfe45e19c28b9fc48036f9ef09fb8e6</link>
      <description>必修漏洞是指影响范围广、危害程度高、技术细节已公开或存在在野利用的安全漏洞。此类漏洞被攻击者利用后，可能导致</description>
      <content:encoded><![CDATA[<p><span>腾讯云安全</span> <span>2026-03-16 14:39</span> <span style="display: inline-block;">广东</span></p>




  <p>以下文章来源于：云鼎实验室</p>
  <strong>云鼎实验室</strong>
  <p>腾讯云鼎实验室官方微信公众号</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=015f8717&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FVL7Qr6N3skg6tm9gqlwic0Dvh1OglzwDD0YlnSOliaZUvaCvYxibR6c78SS7CHBZrjTW36SKWXL1FFGmf3K8j4jibVMNRKRPX4HJ4biafIPGHF2Q%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div><div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding: 27px;outline: 0px;display: inline-block;width: 663.458px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(78, 132, 216);visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-size: 15px;visibility: visible;"><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="">必修漏洞是指影响范围广、危害程度高、技术细节已公开或存在在野利用的安全漏洞。此类漏洞被攻击者利用后，可能导致业务系统中断、核心数据泄露、服务器被远程控制、内部网络被横向渗透等严重后果，造成经济损失和声誉损害。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="">腾讯云安全研究团队综合评估“漏洞危害程度、影响范围、技术细节披露情况、安全社区关注度、在野利用情况”等因素，筛选出需优先修复的安全漏洞，定期发布企业必修安全漏洞清单。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="">本清单旨在为企业安全运维人员提供漏洞修复优先级参考，助力企业提升安全防护能力、降低安全风险。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="">注：本清单为腾讯云安全基于专业评估提供的技术参考，企业应根据自身业务特点、系统架构、安全等级等实际情况，制定相应的漏洞修复计划。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(3, 97, 243);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">以下是2026年2月份必修安全漏洞清单</span></span></strong></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">：</span></span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">一、</span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">OpenClaw </span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">安全绕过漏洞（</span></span><span lang="EN-US"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2026-28363</span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">）</span></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">二、</span></span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">大蚂蚁</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;"> (BigAnt) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">即时通讯系统任意文件上传漏洞</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">(</span></span><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">TVD-2026-5210</span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">三、</span></span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span style=""><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">OpenCode </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">远程代码执行漏</span><span textstyle="" style="letter-spacing: normal;font-weight: normal;">洞</span></span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">（</span></span><span lang="EN-US" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-pm-slice="0 0 []"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2026-22812</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">) </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">四、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Langflow CSV Agent </span></span></span></strong><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">远程代码执行漏洞</span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">(</span></span><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2026-27966</span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">)</span></span></span></b></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">五、</span></span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Gradio SSRF </span></span></span><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">服务器端请求伪造漏洞</span></span><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">(</span></span><span lang="EN-US" data-pm-slice="0 0 []" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2026-28416</span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">)</span></span></span></b></b></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">六</span></span></span></strong><strong style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">、</span></span></strong><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">飞牛私有云</span></span></span></b><span lang="EN-US" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">fnOS </span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">路径遍历漏洞</span></span><span lang="EN-US" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">(TVD-2026-4961）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">七、Apache Camel </span></span></span></strong><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">反序列化远程代码执行漏洞（</span></span><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2026-25747）</span></span></span></b></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">八、</span></span></span></strong><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Gogs </span></span></span></b><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">远程代码执行漏洞（</span></span><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-64111）</span></span></span></b></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">九、</span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">n8n </span></span><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">沙箱逃逸漏洞（</span></span><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2026-27577）</span></span></span></b></span></p></div><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 15px;text-align: justify;color: rgb(3, 97, 243);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞介绍及修复建议详见后文</span></strong></span></p></div></div></div></div></div></div></div></div></div><p data-pm-slice="4 2 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">一、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">OpenClaw </span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">安全绕过漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012822" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenClaw</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">TVD-2026-8067</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE-2026-28363</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD-202602-4748</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可绕过命令执行安全验证机制，在无需审批的情况下执行任意系统命令。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenClaw</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款开源的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">编码代理工具，旨在为开发者提供智能化的代码编写和项目管理能力。它采用先进的大语言模型技术，能够理解用户的自然语言指令并执行相应的编码任务，包括代码生成、代码审查、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Bug</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">修复等。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenClaw</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">通过沙箱机制和命令白名单来保护系统安全，其中</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">`tools.exec.safeBins`</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">功能用于定义允许执行的安全命令列表，在白名单模式下只有明确允许的命令才能被执行，从而防止恶意命令的执行，保障开发环境的安全。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenClaw</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">tools.exec.safeBins</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">验证机制在处理</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">sort</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">命令时存在缺陷。攻击者可以利用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">GNU</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">长选项缩写特性（如使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">--compress-prog</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代替</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">--compress-program</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）绕过白名单验证，因为系统只拒绝完整的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">--compress-program</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">字符串，而允许其缩写形式通过，从而实现无需审批的命令执行。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">注：攻击者要成功利用该漏洞，系统必须配置为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">tools.exec.security=allowlist</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">tools.exec.ask=on-miss </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">且</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> tools.exec.safeBins </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">包含</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> sort</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012824" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012824" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">8.8</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012823" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">OpenClaw &lt; 2026.2.23</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012821" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解措施：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">二、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">大蚂蚁</span></span><span style="text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span lang="EN-US"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> (BigAnt) </span></span></span><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">即时通讯系统任意文件上传漏洞</span></span></span></strong></p></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012800" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于大蚂蚁即时通讯系统的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">TVD-2026-5210</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可上传恶意文件，远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">大蚂蚁（</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">BigAnt</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）即时通讯系统是由杭州九麒科技开发的一款专注于政企市场的私有化部署企业级即时通讯平台。该系统始于</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2003</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">年，提供即时通讯、文件共享、组织架构管理、协同办公、视频会议及文档管理等一体化功能，并以其独特的消息确认机制、离线消息支持和远程控制等特色著称。大蚂蚁即时通讯系统强调</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">“</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">自主可控、安全可靠</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">”</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，全面适配国产化软硬件环境，支持单机、跨域级联及高可用集群等多种部署方式。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据官方描述，该漏洞源于系统</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> API </span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">接口未对上传文件的类型及存储路径进行严格校验。远程攻击者无需登录即可利用该漏洞上传恶意脚本文件，从而获取服务器控制权限，导致数据泄露或系统被完全控制。</span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012804" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已发现</span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012804" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.6pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.5pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.9</span></span></p></td></tr></tbody></table><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012803" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">BigAnt 5.5.x </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">系列及以上版本</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012802" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://www.bigant.cn/article/news/435.html" target="_blank">https://www.bigant.cn/article/news/435.html</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免将服务开放至公网</span></span></p><span lang="EN-US" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></span></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">三、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">OpenCode </span></span><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;" data-pm-slice="0 0 []"><span leaf="" style="clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012807" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenCode</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">TVD-2026-3349</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE-2026-22812</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD-202601-1875</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenCode</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款开源的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码编程助手，旨在为开发者提供智能化的编码体验。它基于先进的人工智能技术，可以帮助开发者自动生成代码、提供代码补全建议、检测代码错误并给出修复方案。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenCode</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持多种主流编程语言，能够无缝集成到现有的开发环境中，提高开发效率。该工具通过本地</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTTP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器与用户进行交互，提供</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">接口以便于各种</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IDE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和编辑器进行集成调用，帮助开发者在编写代码过程中获得实时的智能辅助。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenCode</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在启动时会自动开启一个未经身份验证的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTTP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器，且该服务器配置了宽松的跨域资源共享</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(CORS)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">策略。攻击者可以通过</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">本地恶意程序或恶意网页</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">向该服务器发送请求，以当前用户权限执行任意</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Shell</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">命令，最终实现远程代码执行。</span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012808" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012808" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">8.8</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012806" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">OpenCode &lt; 1.0.216</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012805" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/anomalyco/opencode/releases" target="_blank">https://github.com/anomalyco/opencode/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免将服务开放至公网</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">四、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Langflow CSV Agent </span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></p></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012810" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">TVD-2026-7892(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE-2026-27966</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD-202602-4530)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款开源的可视化</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">工作流构建工具，专为构建和部署</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">驱动的智能代理和工作流程而设计。它提供了直观的拖拽式界面，让用户无需编写大量代码即可创建复杂的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用程序。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持与</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LangChain</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">深度集成，用户可以轻松组合各种</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">组件，包括大语言模型、向量数据库、文档处理器等。其中</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CSV Agent</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">功能允许用户通过自然语言与</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CSV</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">数据文件进行交互，实现数据查询、分析和可视化等操作，极大地简化了数据分析工作流程。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CSV Agent</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">节点在代码中硬编码了</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">allow_dangerous_code=True</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">参数，这会自动暴露</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LangChain</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python REPL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">工具（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">python_repl_ast</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）。攻击者可以通过构造恶意提示词注入攻击，在服务器上执行任意</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码和操作系统命令，最终实现完整的远程代码执行。</span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012811" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012811" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.8</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012806" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow &lt; 1.8.0.dev55</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012805" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/langflow-ai/langflow/" target="_blank">https://github.com/langflow-ai/langflow/</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">五、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Gradio SSRF </span></span><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">服务器端请求伪造漏洞</span></span></span></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012816" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gradio</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">TVD-2026-8173</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE-2026-28416</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD-202602-4619</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，最终可实现服务器端请求伪造，访问内部资源并窃取敏感信息。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gradio</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款开源的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">库，专为快速构建机器学习模型演示和原型应用而设计。它允许开发者通过几行代码就能为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">模型创建交互式</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Web</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">界面，支持各种输入输出组件，如文本、图像、音频、视频等。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gradio</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">因其简单易用的特性，被广泛应用于机器学习研究、模型展示和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用开发领域。其中</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">`gr.load()`</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">功能允许用户加载托管在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Hugging Face Spaces</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或其他平台上的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gradio</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用，方便用户复用和集成现有的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">模型和应用，促进了</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">社区的协作与共享。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ope</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gradio</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在处理</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">`gr.load()`</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">加载外部</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Space</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">时存在安全缺陷。当受害者应用使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">`gr.load()`</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">加载攻击者控制的恶意</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Space</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">时，配置中的恶意</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">`proxy_url`</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">会被信任并添加到允许列表中，使攻击者能够通过受害者的基础设施访问内部服务、云元数据端点和私有网络资源。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">注：任何使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> gr.load() </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">加载外部或不可信</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Spaces </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Gradio </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用程序均受该漏洞影响。</span></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 24px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 24px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012817" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">8.2</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012818" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gradio &lt;= 6.5.1</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012819" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，建议升级至最新版本。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/gradio-app/gradio/releases" target="_blank">https://github.com/gradio-app/gradio/releases</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解措施：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">避免使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">`gr.load()`</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">加载不受信任的外部</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Space</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，限制服务器对内部网络和云元数据端点的访问</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></p><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="8 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div><div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">六、</span></span></span></strong><strong style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">飞牛私有云</span></span><b data-pm-slice="0 0 []"><span lang="EN-US"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);"> fnOS </span></span></span><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">路径遍历漏洞</span></span></b></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于飞牛私有云</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">fnOS</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">TVD-2026-4961</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可读取服务器上的任意敏感文件。</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">飞牛私有云</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">FnOS</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款基于</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Linux</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">内核（</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Debian</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">发行版）深度开发的国产免费</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">NAS</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">系统，它兼容主流</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">x86</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">硬件，可将闲置旧电脑轻松改造为私有云存储服务器。该系统集成了智能影视刮削、相册备份、多用户文件管理、</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Docker</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">容器支持以及应用中心等丰富功能，并通过免费的</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">FN Connect</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">内网穿透服务实现安全便捷的远程访问，为个人用户和小型团队提供了低门槛、高效率的私有云存储与管理解决方案。</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该漏洞源于飞牛私有云</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> fnOS NAS</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">操作系统中的</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">/app-center-static/serviceicon/myapp/</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">接口中存在路径遍历漏洞，未经身份验证的远程攻击者可通过构造恶意请求读取</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> NAS </span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">上的所有数据，包括用户私人照片、视频、文档，乃至系统配置文件与私钥等，从而造成敏感信息泄露。</span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="31" data-imgfileid="100012796" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已发现</span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="31" data-imgfileid="100012796" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:17.55pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">8.8</span></span></p></td></tr></tbody></table><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div></div><p><span style="font-size:10.5pt;mso-bidi-font-size:12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#333333;background:white;"><span leaf="">飞牛私有云</span><span lang="EN-US"><span leaf=""> fnOS &lt; 1.1.18</span></span></span></p><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div></div></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://fnnas.com/download" target="_blank">https://fnnas.com/download</a></span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免将服务开放至公网</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">七、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Apache Camel </span></span><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);" data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">反序列化远程代码执行漏洞</span></span></b></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012826" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache Camel </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">组件的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">TVD-2026-7326</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE-2026-25747</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD-202602-3925</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache Camel</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">软件基金会开发的一款开源企业级集成框架，基于企业集成模式</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(EIP)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">设计，为开发者提供了丰富的组件和连接器，用于实现不同系统之间的数据交换和集成。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Camel</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持超过</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">300</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">种协议和数据格式，广泛应用于企业服务总线</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(ESB)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、微服务架构和消息驱动应用中。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LevelDB</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">组件是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Camel</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的聚合存储库实现之一，使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Google</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LevelDB</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">键值存储引擎来持久化聚合过程中的中间消息，确保消息在系统重启后不会丢失，为高可用性和容错性提供支持。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache Camel</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LevelDB</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">组件中</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">DefaultLevelDBSerializer</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">类在反序列化数据时存在安全缺陷。该类使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">java.io.ObjectInputStream</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">反序列化从</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LevelDB</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">聚合存储库读取的数据，但未应用任何</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ObjectInputFilter</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或类加载限制。攻击者若能够写入</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Camel</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用程序使用的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LevelDB</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">数据库文件，可注入恶意构造的序列化</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Java</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">对象，在正常聚合存储库操作期间触发反序列化，最终实现任意代码执行。</span></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 24px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:21.1pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 21.1pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 21.1pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 24px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">8.8</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012827" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="margin-bottom: 24px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">3.0.0 &lt;= Apache Camel &lt; 4.10.9</span></span></p><p style="margin-bottom: 24px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">4.11.0 &lt;= Apache Camel &lt; 4.14.5</span></span></p><p style="margin-bottom: 24px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">4.15.0 &lt;= Apache Camel &lt; 4.18.0</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012821" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，及时更新漏洞补丁</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://camel.apache.org/download/" target="_blank">https://camel.apache.org/download/</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解措施：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">八、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Gogs </span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012832" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gogs</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">TVD-2025-47166</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE-2025-64111</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD-202602-995</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gogs</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款开源的轻量级自托管</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Git</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务，采用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Go</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">语言编写，以其极低的资源占用和简单的部署方式而著称。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gogs</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">提供了类似于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">GitHub</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Web</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">界面，支持仓库管理、问题追踪、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Wiki</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、代码审查等功能，适合个人开发者和小型团队使用。它支持多种数据库后端，包括</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SQLite</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">MySQL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PostgreSQL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等，可以在各种操作系统上运行，包括</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Linux</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">macOS</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ARM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">架构设备。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Gogs</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的设计目标是成为一个易于安装、运行和维护的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Git</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">托管解决方案，让用户能够快速搭建私有的代码托管平台。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，由于针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Gogs </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程代码执行漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CVE-2024-56731</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）的补丁修复不完整，在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> internal/route/api/v1/repo/contents.go </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">文件的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">UpdateRepoFile </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">函数调用路径中，安全校验逻辑仍存在遗漏，攻击者仍可通过</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> API </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">接口，利用仓库中的符号链接文件（如指向</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> .git/config </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的链接），以</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Base64 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">编码的方式提交恶意配置内容，从而篡改</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Git </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> sshCommand </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等关键参数，最终在服务器端执行任意系统命令。</span></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 24px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 24px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.65pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.8</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012827" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="margin-bottom: 24px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">Gogs &lt;= 0.13.3</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012821" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/gogs/gogs/releases" target="_blank">https://github.com/gogs/gogs/releases</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">建议在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> app.ini </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">中关闭</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Gogs </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户注册功能，防止攻击者注册账号进行登录利用（修改后需重启</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Gogs </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务）：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">[auth]</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">DISABLE_REGISTRATION = true</span></span></span></p><p data-pm-slice="4 3 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">九、</span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">n8n </span></span><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);" data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">沙箱逃逸漏洞</span></span></b></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012832" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">TVD-2026-7841</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CVE-2026-27577</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">CNNVD-202602-4190</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);font-weight: bold;">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可通过表达式注入绕过沙箱限制，在宿主机上执行任意系统命令。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款开源的工作流自动化平台，专为技术人员和企业设计，用于连接各种应用程序和服务以实现业务流程自动化。它提供了直观的可视化界面，支持超过</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">400</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">个应用程序集成，包括常见的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SaaS</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务、数据库、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的核心优势在于其灵活性和可扩展性，用户可以通过拖拽方式创建复杂的自动化工作流，也可以使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JavaScript</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">编写自定义逻辑。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持自托管部署，让企业能够完全控制自己的数据和工作流，广泛应用于数据同步、通知推送、报表生成等自动化场景。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CVE-2025-68613</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的后续漏洞，源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在表达式求值机制中存在额外的安全缺陷。经过身份验证且具有工作流创建或修改权限的用户，可以在工作流参数中构造恶意表达式，绕过沙箱限制，在运行</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的宿主机上触发非预期的系统命令执行，最终实现沙箱逃逸和远程代码执行。</span></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 24px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 24px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.9</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; padding-top: 10px; padding-bottom: 10px; outline: 0px; text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012827" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n &lt; 1.123.22</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.0.0 &lt;= n8n &lt; 2.9.3</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.10.0 &lt;= n8n &lt; 2.10.1</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; padding-top: 10px; padding-bottom: 10px; outline: 0px; text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012821" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/n8n-io/n8n/releases" target="_blank">https://github.com/n8n-io/n8n/releases</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">将工作流的创建和编辑权限限制在完全可信的用户范围内，避免不可信用户利用该漏洞</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">将</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> n8n </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">部署在强化后的环境中，限制其操作系统权限和网络访问范围，以降低漏洞被成功利用后可能造成的危害</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 等线;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-style: italic;">*</span><span textstyle="" style="font-size: 15px;font-style: italic;">以上</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 宋体;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 15px;font-style: italic;">漏洞评分为腾讯云安全研究人员根据漏洞情况作出，仅供参考，具体漏洞细节请以原厂商或是相关漏洞平台公示为准。</span></span></span></p><div hm_fix="385:564" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 32px;"><img data-aistatus="1" alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="0.8768115942028986" data-type="gif" data-w="276" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: block;width: 32px !important;visibility: visible !important;" data-width="100%" data-imgfileid="100012836" src="https://wechat2rss.xlab.app/img-proxy/?k=816b6918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FFIBZec7ucChYUNicUaqntiamEgZ1ZJYzLRasq5S6zvgt10NKsVZhejol3iakHl3ItlFWYc8ZAkDa2lzDc5SHxmqjw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 2px 0em;outline: 0px;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">END</span></strong></p></div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;color: rgb(163, 163, 163);text-align: center;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div data-role="paragraph" data-color="#1e9be8" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div data-id="86318" data-tools="135编辑器" data-color="#3d8ed1" data-custom="#3d8ed1" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;outline: 0px;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 5px 1em;outline: 0px;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;text-indent: 0em;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="">关注云鼎实验室，获取更多安全情报</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;min-height: 1em;color: rgb(163, 163, 163);letter-spacing: 0.54px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.6" data-s="300,640" data-type="jpeg" data-w="900" style="-webkit-tap-highlight-color:transparent;outline:0px;letter-spacing:0.54px;width:358px;visibility:visible !important;height:215px;" data-copyright="0" data-imgfileid="100012835" src="https://wechat2rss.xlab.app/img-proxy/?k=8264a853&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=43c44177&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485138%26idx%3D1%26sn%3D6bfe45e19c28b9fc48036f9ef09fb8e6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 16 Mar 2026 14:39:00 +0800</pubDate>
    </item>
    <item>
      <title>2026年1月企业必修安全漏洞清单</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485136&amp;idx=1&amp;sn=99db518f5db0321868f0810a424375b8</link>
      <description>所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重</description>
      <content:encoded><![CDATA[<p><span>腾讯云安全</span> <span>2026-02-06 18:46</span> <span style="display: inline-block;">广东</span></p>




  <p>以下文章来源于：云鼎实验室</p>
  <strong>云鼎实验室</strong>
  <p>腾讯云鼎实验室官方微信公众号</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9fffd6b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FVL7Qr6N3skhiaY7LeqWQCynS6nBXLm1mPlvg3KkQUtuyISkpWVqg8mE6LFUKxyDNgQftyzqK10ibvLKOWlicjtvl3xRWtxG2YS1hjuLq9agfgQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div><div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding: 27px;outline: 0px;display: inline-block;width: 663.458px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(78, 132, 216);visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-size: 15px;visibility: visible;"><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重的后果。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf=""><span textstyle="" style="letter-spacing: normal;">腾讯云安全参考“安全漏洞的危害及影响力、漏洞技术细节披露情况、该漏洞在安全技术社区的讨论热度”等因素，综合评估该漏洞在攻防实战场景的风险。当漏洞综合评估为风险严重、影响面较广、技术细节已披露，且被安全社区高度关注时，就将该漏洞列入必修安全漏洞候选清单。 </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">腾讯云安全定期发布安全漏洞必修清单，以此指引企业安全运维人员修复漏洞，从而避免重大损失。 </span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(3, 97, 243);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">以下是2026年1月份必修安全漏洞清单</span></span></strong></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">：</span></span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">一、</span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">RAGFlow 远程代码执行</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">漏洞(</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-68700）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">二、</span></span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">n8n 远程代码执行漏洞(</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;MsoNormal&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin-bottom: 16px; outline: 0px; line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;lang&#34;:&#34;EN-US&#34;,&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-68668</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">三、</span></span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">n8n 未授权文件访问漏洞(CVE-2026-21858)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">四、</span></span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">ComfyUI Manager CRLF 注入远程代码执行漏洞(CVE-2026-22777)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">五、</span></span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Apache Struts2 XWork XML外部实体注入漏洞(CVE-2025-68493)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">六、</span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Crawl4AI</span></span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-font-family="等线"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">远程代码执行漏</span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">洞( TVD-2026-3804)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">七、</span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">GNU InetUtils telnetd 远程身份认证绕过漏洞(CVE-2026-24061)</span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">八、</span></span></span></strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-font-family="等线"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">SmarterMail 身份认证绕过漏洞(CVE-2026-23760)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">九、</span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">SmarterMail ConnectToHub 远程代码执行漏洞(CVE-2026-24423）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">十、</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-font-family="等线"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">OpenCode 远程代码执行漏洞(CVE-2026-22813)</span></span></span></p></div><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 15px;text-align: justify;color: rgb(3, 97, 243);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞介绍及修复建议详见后文</span></strong></span></p></div></div></div></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">一、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">RAGFlow </span></span><b style="mso-bidi-font-weight:normal;" data-pm-slice="0 0 []"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></span></b></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RAGFlow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-44186(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-68700</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-5500)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RAGFlow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款开源的检索增强生成（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RAG</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）引擎，旨在通过结合外部知识检索与生成式模型，提升大语言模型在问答、内容生成等场景下的准确性与知识覆盖度。该引擎广泛应用于智能客服、企业知识库、自动化文档处理等需要知识推理与自然语言交互的场景中。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RAGFlow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">具备灵活的插件架构和前端可视化操作界面，支持多种数据源接入与自定义数据处理流程，方便开发者与业务人员构建定制化的智能应用。</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RAGFlow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的前端</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Canvas CodeExec</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">组件在处理未受信任的数据（如</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">stdout</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">输出）时，直接使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">eval()</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">函数进行解析，且未实施任何过滤或沙箱隔离措施，攻击者可通过构造恶意输入，利用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">eval()</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行任意代码，从而在服务器上运行系统命令。</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><i><span leaf="" style="font-style: italic;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 41, 65);">注：未经身份验证的攻击者可结合</span></span><span lang="EN-US"><span leaf="" style="font-style: italic;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 41, 65);"> RAGFlow </span></span></span><span leaf="" style="font-style: italic;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 41, 65);">身份认证绕过漏洞（</span></span><span lang="EN-US"><span leaf="" style="font-style: italic;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 41, 65);">CVE-2025-69286</span></span></span><span leaf="" style="font-style: italic;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 41, 65);">）绕过身份认证执行任意代码。</span></span></i></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="31" data-imgfileid="100012796" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="31" data-imgfileid="100012796" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:17.55pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">8.8</span></span></p></td></tr></tbody></table><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#333333;background:white;"><span leaf="">RAGFlow</span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:12.0pt;font-family:等线;mso-bidi-font-family:等线;"><span leaf="">&lt; 0.23.0</span></span></p><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div></div></div><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/infiniflow/ragflow/releases" target="_blank">https://github.com/infiniflow/ragflow/releases</a></span></span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免将服务开放至公网</span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">二、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">n8n </span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></p></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012800" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-43636(CVE</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-68668</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-4823)</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个开源的工作流自动化平台，它允许用户通过可视化界面或代码来创建、管理和执行各种自动化任务和工作流。该平台具有高度的灵活性和可扩展性，支持多种集成方式和节点类型，可用于数据处理、系统集成、自动化业务流程等多种场景。用户可以根据自身需求自定义工作流，实现不同系统之间的数据交互和任务自动化，提高工作效率和准确性，在企业级自动化流程中应用广泛。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">中基于</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Pyodide</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">实现的</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码节点存在沙箱隔离缺陷。该节点旨在为工作流提供安全的</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码执行环境，但其隔离机制（</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Pyodide</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）可能被经过身份验证的攻击者通过注入或构造特定的</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python</span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码绕过，从而突破沙箱限制，直接访问并操作底层主机操作系统的资源。这使得拥有创建工作流权限的攻击者可以通过编辑或创建包含恶意代码的</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Python </span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">节点，以</span></span><span lang="EN-US"><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> n8n </span></span></span><span leaf="" style="color: rgb(51, 51, 51);-webkit-tap-highlight-color: transparent;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">进程的权限在服务器上执行任意系统命令。</span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012804" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012804" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.6pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.5pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.9</span></span></p></td></tr></tbody></table><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012803" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">1.0.0 &lt;= n8n &lt; 2.0.0</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012802" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/n8n-io/n8n/releases" target="_blank">https://github.com/n8n-io/n8n/releases</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">由于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">从</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.111.0</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本起，引入了基于任务运行器（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">task-runner</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）的原生</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">实现可选功能，提供了更安全的隔离模型。因此也可通过配置环境变量</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> N8N_RUNNERS_ENABLED</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">N8N_NATIVE_PYTHON_RUNNER</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">启用进行修复。并且此安全实现自</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.0.0</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本起已成为默认配置。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">3. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解措施：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">禁用代码节点：设置环境变量</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> NODES_EXCLUDE: &#34;[\&#34;n8n-nodes-base.code\&#34;]&#34;</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，可参考以下链接：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://docs.n8n.io/hosting/securing/blocking-nodes/" target="_blank">https://docs.n8n.io/hosting/securing/blocking-nodes/</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">禁用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Python </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持：设置环境变量</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> N8N_PYTHON_ENABLED=false</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">（该环境变量自</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 1.104.0 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本引入）。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">启用安全沙箱：配置环境变量</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> N8N_RUNNERS_ENABLED</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">N8N_NATIVE_PYTHON_RUNNER</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，以使用基于任务运行器的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Python </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">沙箱，可参考以下链接：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://docs.n8n.io/hosting/configuration/task-runners/" target="_blank">https://docs.n8n.io/hosting/configuration/task-runners/</a></span></span></span></p></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">三、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">n8n </span></span><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;" data-pm-slice="0 0 []"><span leaf="" style="clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">未授权文件访问漏洞</span></span></b></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012807" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于n8n的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2026-3136</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2026-21858，CNNVD编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202601-1364</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可访问服务器上的敏感文件，造成敏感信息泄露</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，由于</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Webhook和文件处理逻辑中存在Content-Type混淆缺陷，当系统处理 Webhook请求时，错误的 Content-Type 标头处理会导致内部请求解析状态被覆盖。攻击者通过向公开的 Webhook 端点发送经过特制的 HTTP 请求，从而覆盖内部状态、访问包括身份验证密钥在内的敏感文件，并且可能通过伪造管理员会话，最终在主机上实现任意代码执行，从而完全控制自动化实例、窃取凭证和密钥，并横向渗透到连接的内部系统、API 和云服务中。</span></span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012808" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012808" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.0</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012806" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">1.65.0 &lt;= n8n &lt; 1.121.0 </span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012805" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/n8n-io/n8n/releases" target="_blank">https://github.com/n8n-io/n8n/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">限制或禁用公开访问的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> webhook </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和表单端点的访问</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">四、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">ComfyUI Manager CRLF </span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">注入远程代码执行漏洞</span></span></b></p></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012810" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ComfyUI-Manager</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2026-3230(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2026-22777</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202601-1731)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ComfyUI-Manager</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是专为增强</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ComfyUI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">易用性而设计的扩展工具，旨在为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ComfyUI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户提供更便捷的操作体验和功能管理能力。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ComfyUI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">通常用于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">图像生成与处理领域，而</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ComfyUI-Manager</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">作为其官方或社区推荐的扩展组件，提供了配置管理、插件集成、用户界面优化等功能，广泛被</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">艺术创作者、开发者及研究人员所使用。该组件通过简化配置流程和增强交互体验，帮助用户更高效地使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ComfyUI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">平台，是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">图像生成生态中的重要辅助工具。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ComfyUI Manager</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">暴露了可通过</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Web API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">修改配置的接口，且在处理用户输入时，未能对回车换行符等特殊字符进行有效过滤，导致存在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CRLF</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">注入漏洞，攻击者可向该接口发送特制请求，在配置值中注入换行符，从而更改配置文件。攻击者可进一步利用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> ComfyUI Manager </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Git URL </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">安装功能，诱使应用从攻击者控制的仓库安装恶意自定义节点，最终在服务器上执行任意代码。</span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012811" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012811" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">7.5</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012814" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">ComfyUI Manager</span><span leaf="">&lt; 3.39.2</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">4.0.0 &lt; ComfyUI Manager &lt; 4.0.4</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012813" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/Comfy-Org/ComfyUI-Manager/tags" target="_blank">https://github.com/Comfy-Org/ComfyUI-Manager/tags</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如非必要，避免将</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> ComfyUI </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务以</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> --listen 0.0.0.0 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等参数暴露在公网。</span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">五、</span></span></span></strong><b><span lang="EN-US"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Apache Struts2 XWork XML</span></span></span></b><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">外部实体注入漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012816" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache Struts</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-45593(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-68493</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202601-1787)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可读取系统敏感文件或导致拒绝服务。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache Struts</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个用于开发</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Java EE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">网络应用程序的开源</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Web</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用框架，它简化了基于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">MVC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">设计模式的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Web</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用程序的开发过程。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Struts</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">通过提供一系列标签库、拦截器和配置文件，帮助开发者更高效地构建动态网页和处理用户输入。该框架广泛应用于企业级应用中，因其灵活性和扩展性而受到开发者的青睐。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据官方描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache Struts2</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">XWork</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">组件在处理</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">XML</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置文件时存在安全缺陷，其</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">XML</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">解析器在解析过程中未能以安全的方式验证</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> XML</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">输入，未禁用或限制对外部实体的加载。攻击者可构造并发送一个包含指向本地文件或远程资源外部实体声明的特制</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> XML </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求。当该请求被</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> XWork </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">组件解析时，解析器会加载并处理这些外部实体，导致将服务器上的文件内容或内网服务响应嵌入至应用响应中返回给攻击者，或引发解析过程中的资源耗尽等。</span></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 0px;"><b data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;MsoNormal&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012811" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><b data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;MsoNormal&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012811" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">8.1</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012818" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;">2.0.0 &lt;=Apache Struts &lt;= 2.3.37</span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;">2.5.0 &lt;= Apache Struts &lt;= 2.5.33</span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;">6.0.0 &lt;= Apache Struts&lt;= 6.1.0</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012819" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，建议升级至最新版本。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://struts.apache.org/download.cgi" target="_blank">https://struts.apache.org/download.cgi</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解措施：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(1) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">自定义</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> XML </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">解析器：通过设置系统属性 </span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">xwork.saxParserFactory</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，指定一个自定义的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> SAXParserFactory </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">类，该类需在默认配置中禁用外部实体解析。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(2) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或配置</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> JVM </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">全局设置：通过</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> JVM </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">启动参数，配置默认</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> XML </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">解析器以禁用所有外部资源的访问，具体参考以下配置，将值设为空字符串来阻断所有协议：</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-Djavax.xml.accessExternalDTD=&#34;&#34;</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-Djavax.xml.accessExternalSchema=&#34;&#34;</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-Djavax.xml.accessExternalStylesheet=&#34;&#34;</span></span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">六、</span></span></span></strong><b><span lang="EN-US"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Crawl4AI</span></span></span></b><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012822" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Crawl4AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">TVD-2026-3804</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Crawl4AI </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款专为大型语言模型和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> AI </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用设计的开源网络爬虫与数据提取框架，其核心目标是解决传统爬虫工具在支持</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> AI </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">工作流（如</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> RAG</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、模型微调、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代理）时面临的数据适配问题。它通过智能化的内容处理管道，能够将网页内容高效转换为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> AI </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">友好的格式（如结构清晰的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Markdown </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> JSON</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">），并在此过程中自动过滤广告、导航栏等噪声内容，显著提升数据质量。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，当使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Docker API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">部署</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Crawl4AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">时，其</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">/crawl</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">端点存在严重安全缺陷。该端点接收的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">hooks</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">参数中包含的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码，会通过不安全的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">exec()</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">函数执行，以支持用户自定义钩子功能，但执行代码时的安全沙箱配置将</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">__import__</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">这个内置函数保留在了允许使用的内置函数列表中，这使得攻击者可以在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">hooks </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">参数中导入</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">os</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等任意模块，最终远程执行任意代码。</span></span></p><p style="margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012811" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012811" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.8</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012818" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="margin-bottom: 24px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">Crawl4AI &lt; 0.8.0</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012819" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/unclecode/crawl4ai/releases/tag/" target="_blank">https://github.com/unclecode/crawl4ai/releases/tag/</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">注：更新指南可参考以下官方链接：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/unclecode/crawl4ai/blob/release/v0.8.0/docs/migration/v0.8.0-upgrade-guide.md" target="_blank">https://github.com/unclecode/crawl4ai/blob/release/v0.8.0/docs/migration/v0.8.0-upgrade-guide.md</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解措施：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">停止并禁用此</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Docker API </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务容器。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在网络层面（如防火墙）阻断对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> /crawl </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">端点的访问。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">为该</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> API </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务添加强身份验证。</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">七、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">GNU InetUtils telnetd </span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">远程身份认证绕过漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012826" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">GNU Inetutils</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2026-4039</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2026-24061</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202601-3437</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可绕过身份验证，以</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">root</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">权限登录。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">GNU Inetutils </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个由</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> GNU </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">项目开发和维护的开源软件套件，它集成了一套传统的、用于网络管理和运维的基础命令行工具，包括常见的客户端和服务器端程序，例如</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> ftp</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">telnet</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ping </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">GNU InetUtils telnetd </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> GNU InetUtils </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">软件套件中的一个组件，它是一个实现了</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Telnet </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">协议的服务器端守护进程，其主要功能是监听</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> TCP 23 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">端口，为客户端提供基于明文的远程终端登录服务，在认证环节通常会调用系统的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> /usr/bin/login</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">程序来完成用户身份验证。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据官方描述，在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> GNU InetUtils 1.9.3 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">至</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 2.7 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> telnetd </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务端中，由于服务端在处理来自客户端的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> USER </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">环境变量值时，未对其内容进行任何验证或净化，便直接将此值作为参数传递给</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> /usr/bin/login </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">程序。当攻击者通过客户端指定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> USER=&#39;-f root&#39; </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">并向服务端发送时，该值最终会作为命令的一部分执行，从而直接以</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> root </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户身份登录，完全绕过正常的认证流程。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">注：在主流</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;"> Linux </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">发行版（如</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;"> Debian</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">RHEL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">）的软件仓库中，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">telnet </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">服务器功能通常由多个独立的上游项目实现提供。其中，来自</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;"> netkit </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;"> xinetd </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">项目的实现是默认的、首选的软件包（如</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;"> telnetd </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;"> telnet-server</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">）。而来自</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;"> GNU </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">项目的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;"> inetutils-telnetd</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">，则作为另一个可选的、备选的实现存在于同一仓库中。截止目前，受该漏洞影响设备主要以</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;"> NAS </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">设备为主。</span></span></p><p style="margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已发现</span></span></p></td></tr></tbody></table><p style="line-height: 1.5em;margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.8</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012827" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="margin-bottom: 24px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">1.9.3 &lt;= GNU InetUtils &lt;= 2.7</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012829" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，及时更新漏洞补丁</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b" target="_blank">https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc" target="_blank">https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解措施：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">禁用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> telnetd </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">使用定制的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> login </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">程序：修改</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> telnetd </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置，使其调用一个经过修改的、移除了</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> -f </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">参数的自定义</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> login </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">程序，这样可以阻断该漏洞的直接利用路径。</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">八、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">SmarterMail </span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">身份认证绕过漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012832" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SmarterMail</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2026-4115</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2026-23760</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202601-3816</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可接管管理员用户，最终远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SmarterMail </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是由美国</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> SmarterTools </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">公司开发的一款企业级邮件服务器软件，它被广泛视为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Microsoft Exchange </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的经济型替代方案。它不仅提供安全的企业邮件服务，还集成了共享日历、联系人、任务管理、即时通讯和文件存储等完整的团队协作功能。其核心优势在于原生支持关键的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> MAPI/Exchange </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">协议以实现与</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Microsoft Outlook </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的无缝集成，同时具备跨平台能力（支持</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Windows </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Linux </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器，甚至</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Docker </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">部署）、更低的总体拥有成本、开箱即用的企业级垃圾邮件与防病毒保护，以及可通过</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">“</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用市场</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">”</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">扩展功能的灵活性，使其成为从中小型企业到互联网服务提供商（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ISP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）及托管服务商等多种场景的理想选择。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SmarterMail</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的密码重置接口</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">/force-reset-password</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">未验证系统管理员</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OldPassword</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">字段的有效性，未授权的攻击者可直接向该接口发送特制请求重置管理员密码，随后利用内置的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Volume Mounts</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">功能远程执行任意代码。</span></span></p><p style="margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.65pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.8</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012834" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="margin-bottom: 24px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">SmarterMail &lt; Build 9511</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012831" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://www.smartertools.com/smartermail/release-notes/current" target="_blank">https://www.smartertools.com/smartermail/release-notes/current</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">九、</span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">SmarterMail ConnectToHub </span></span><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);" data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012832" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SmarterTools SmarterMail</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2026-4422(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2026-24423</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202601-3955)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞由于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SmarterMail</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ConnectToHub API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">接口缺乏对访问源的有效身份验证和鉴权，并且设计上允许从外部服务器获取并执行指令，远程攻击者可以构造一个包含恶意操作系统命令的响应，并架设一个恶意</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> HTTP </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器。当攻击者诱导存在漏洞的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> SmarterMail </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器向该恶意服务器发起</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> ConnectToHub </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求时，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SmarterMail </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">会接收并直接执行来自恶意响应的操作系统命令，从而在服务器上实现远程代码执行。</span></span></p><p style="margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.3</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012834" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="margin-bottom: 24px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;"><span leaf="">SmarterMail &lt; Build 9511</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012831" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://www.smartertools.com/smartermail/downloads" target="_blank">https://www.smartertools.com/smartermail/downloads</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">十、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">OpenCode </span></span></span></strong><b style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-imgfileid="100012832" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenCode</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">TVD-2026-3345(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CVE-2026-22813</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CNNVD-202601-1874)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenCode</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款开源的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">编码代理工具，旨在通过集成大型语言模型（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）来辅助开发者进行代码编写、问题解答和编程任务自动化。该工具提供了一个交互式的聊天界面，用户可以通过自然语言与</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">进行对话，获取代码建议、错误修复以及编程相关的指导。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenCode</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">通常部署在本地环境中，供开发者在开发过程中快速获得智能辅助。其设计初衷是提升开发效率，简化编程流程，适合个人开发者或小团队使用。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenCode</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">使用的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Markdown</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">渲染器在将</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">响应插入到</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">DOM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">时，未对其中的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTML</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">内容进行任何形式的清理或净化，且未部署内容安全策略（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CSP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）。这使得攻击者可以通过控制</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的响应内容，注入任意的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTML</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JavaScript</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码，并在用户的浏览器中执行。注入的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JavaScript</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码可利用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Opencode API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">暴露的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">/pty/</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">端点，从而在受害者机器上执行任意代码。</span></span></p><p style="margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012828" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;mso-bidi-font-size:12.0pt;color:#222222;letter-spacing:.4pt;"><span leaf="">9.4</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012834" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="margin-bottom: 24px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#333333;background:white;"><span leaf="">OpenCode &lt; 1.1.10</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012831" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/anomalyco/opencode/releases" target="_blank">https://github.com/anomalyco/opencode/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 等线;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-style: italic;">*</span><span textstyle="" style="font-size: 15px;font-style: italic;">以上</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 宋体;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 15px;font-style: italic;">漏洞评分为腾讯云安全研究人员根据漏洞情况作出，仅供参考，具体漏洞细节请以原厂商或是相关漏洞平台公示为准。</span></span></span></p><div hm_fix="385:564" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 32px;"><img data-aistatus="1" alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="0.8768115942028986" data-type="gif" data-w="276" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: block;width: 32px !important;visibility: visible !important;" data-width="100%" data-imgfileid="100012836" src="https://wechat2rss.xlab.app/img-proxy/?k=816b6918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FFIBZec7ucChYUNicUaqntiamEgZ1ZJYzLRasq5S6zvgt10NKsVZhejol3iakHl3ItlFWYc8ZAkDa2lzDc5SHxmqjw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 2px 0em;outline: 0px;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">END</span></strong></p></div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;color: rgb(163, 163, 163);text-align: center;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div data-role="paragraph" data-color="#1e9be8" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div data-id="86318" data-tools="135编辑器" data-color="#3d8ed1" data-custom="#3d8ed1" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;outline: 0px;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 5px 1em;outline: 0px;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;text-indent: 0em;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="">关注云鼎实验室，获取更多安全情报</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;min-height: 1em;color: rgb(163, 163, 163);letter-spacing: 0.54px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><img alt="图片" class="rich_pages wxw-img" data-aistatus="1" data-copyright="0" data-imgfileid="100012835" data-ratio="0.6" data-s="300,640" style="-webkit-tap-highlight-color:transparent;outline:0px;letter-spacing:0.54px;width:355px;visibility:visible !important;height:213px;" data-type="jpeg" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=8264a853&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9e31edb0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485136%26idx%3D1%26sn%3D99db518f5db0321868f0810a424375b8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 06 Feb 2026 18:46:00 +0800</pubDate>
    </item>
    <item>
      <title>招人啦！腾讯云安全运营岗位（深圳/武汉）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485134&amp;idx=1&amp;sn=ee7c2c8857e71f243a6741a21fb69d94</link>
      <description>腾讯云安全运营岗位（深圳/武汉）期待您的加入！</description>
      <content:encoded><![CDATA[<p><span>huntchen</span> <span>2026-02-04 11:13</span> <span style="display: inline-block;">广东</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=4a647fbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FC47afWcpnua4IOBPiax7ED37WEh1FNs37DWYf4aBbqEZrN2qX8uSA2oIyqJtichKHYsbykj1RMlw6XwhCnt4ulRA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>腾讯云安全运营岗位（深圳/武汉）期待您的加入！</p>
  <p style="margin-bottom: 0px;"><strong><span leaf="">岗位职责：</span></strong></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 16px;">1、负责腾讯云主机与容器安全产品能力运营工作，持续提升产品安全竞争力； </span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 16px;">2、协助解决入侵溯源、攻防演练、黑客攻击等应急响应问题；</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 16px;">3、梳理安全事件中的产品表现，发掘产品不足、安全能力需求和改进建议；</span></span></p><p style="margin-bottom: 0px;"><strong><span leaf="">岗位要求：</span></strong></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 16px;">1、熟悉主机/终端常见安全问题及处置方法，对主机安全产品原理及防御方法有较深入理解； </span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 16px;">2、熟悉常见安全漏洞及技术原理，熟悉常见的攻防对抗手段，具备安全防护实战经验； </span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 16px;">3、工作主动，有进取心，乐于持续学习，抗压性强，有良好的服务意识和协调能力； </span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 16px;">4、善于沟通表达，思维缜密，有敏锐的洞察力； </span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 16px;">5、本科及以上学历，计算机及相关专业，3年以上工作经验。</span></span></p><p><span leaf="">工作地点：<span textstyle="" style="font-weight: bold;">武汉、深圳</span></span></p><p style="margin-bottom: 0px;"><span style="font-size: 16px;"><span leaf="">简历投递：huntchen@tencent.com</span></span></p><p style="margin-bottom: 0px;"><span style="font-size: 16px;"><span leaf="">欢迎各位安全大佬自荐、推荐、转发！</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001483" data-ratio="0.7556818181818182" data-s="300,640" type="block" data-type="jpeg" data-w="528" style="width:578px;height:437px;" src="https://wechat2rss.xlab.app/img-proxy/?k=17e37f44&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FC47afWcpnua4IOBPiax7ED37WEh1FNs37LCVyy2jS43MF0nxRlicdn3Yhfy2pUh1pEum1b9fKtR0u4NT7gHciaZibQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=97e57894&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485134%26idx%3D1%26sn%3Dee7c2c8857e71f243a6741a21fb69d94">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 04 Feb 2026 11:13:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年12月企业必修安全漏洞清单</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485128&amp;idx=1&amp;sn=1fbc1ceef8a90709e3d5644a809a5c12</link>
      <description>所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重的后果</description>
      <content:encoded><![CDATA[<p><span>腾讯云安全</span> <span>2026-01-08 16:35</span> <span style="display: inline-block;">广东</span></p>




  <p>以下文章来源于：云鼎实验室</p>
  <strong>云鼎实验室</strong>
  <p>腾讯云鼎实验室官方微信公众号</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a297f3a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FNNSr7XSrt0nVIv1ZRpAkIGRVQsw9wsYMvWLxwiaCjtQn95mcIo92YM27YfgrAqStnadmh0PS6P5Q9WoR3vZyuJg%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div><div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding: 27px;outline: 0px;display: inline-block;width: 663.458px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(78, 132, 216);visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-size: 15px;visibility: visible;"><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重的后果。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf=""><span textstyle="" style="letter-spacing: normal;">腾讯云安全参考“安全漏洞的危害及影响力、漏洞技术细节披露情况、该漏洞在安全技术社区的讨论热度”等因素，综合评估该漏洞在攻防实战场景的风险。当漏洞综合评估为风险严重、影响面较广、技术细节已披露，且被安全社区高度关注时，就将该漏洞列入必修安全漏洞候选清单。 </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">腾讯云安全定期发布安全漏洞必修清单，以此指引企业安全运维人员修复漏洞，从而避免重大损失。 </span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(3, 97, 243);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">以下是2025年12月份必修安全漏洞清单：</span></span></strong></span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">一、</span></span></strong><strong><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">React Server Components 远程代码执行漏洞</span></span></span></strong><strong><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">（CVE-2025-55182）</span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">二、</span></span></span></strong><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Next.js 远程代码执行漏洞</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">（</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-66478</span></span></span><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">）</span></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">三、</span></span></span></strong><strong><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Vite Plugin RSC 远程代码执行漏洞</span></span></strong><strong><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">（CVE-2025-67489）</span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">四、</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Vite Plugin RSC 任意文件读取漏洞</span></span></span></span></strong><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">（CVE-2025-68155）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">五、</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">MongoDB 信息泄露漏洞</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">（CVE-2025-14847）</span></span></span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">六、</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">n8n 远程代码执行漏洞</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">（CVE-2025-68668）</span></span></span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">七、</span></span></span></strong><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">n8n 远程代码执行漏洞</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">（CVE-2025-68613）</span></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">八、</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Langflow 远程代码执行漏洞（CVE-2025-34291）</span></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">九、</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Langflow 服务器端请求伪造漏洞（CVE-2025-68477）</span></span></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">十、</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">LangChain 反序列化漏洞（CVE-2025-68664）</span></span></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">十一、</span></span><span data-font-family="等线"><span leaf="" style="font-size: 14px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Dify 硬编码漏洞（CVE-2025-56157）</span></span></span></span></span></p></div><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 15px;text-align: justify;color: rgb(3, 97, 243);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞介绍及修复建议详见后文</span></strong></span></p></div></div></div></div></div></div></div></div></div></div></div><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="8 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;rich_media_title &#34;,&#34;id&#34;:&#34;activity-name&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px 0px 14px; padding: 0px; outline: 0px; font-weight: 500; font-size: 22px; line-height: 1.4; user-select: text; color: rgba(0, 0, 0, 0.9); font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: 0.544px; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">一、</span></span><b style="line-height: 1.4;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span lang="EN-US"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">React Server Components </span></span></span><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=ae9f7fd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D0"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">React Server Components</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-39596</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-55182</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-393</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">React Server Components</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">React</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">框架的一项创新功能，允许开发者在服务器端渲染组件，从而减少客户端</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JavaScript</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的负担，提升应用性能。它通过将部分组件逻辑移至服务器端执行，实现了更高效的数据获取和处理，同时保持了</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">React</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的声明式编程模型。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">React Server Components</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持与传统客户端组件无缝集成，为开发者提供了灵活的架构选择。该技术特别适用于需要处理大量数据或复杂业务逻辑的应用场景，能够显著改善用户体验和应用响应速度。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">React Server Components</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">中的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Server Function</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">端点对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTTP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求载荷进行了不安全的反序列化处理，攻击者可以通过构造恶意的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTTP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求载荷，在未经身份验证的情况下触发反序列化漏洞，最终实现远程代码执行。</span></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 8px;text-align: left;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=bd67476a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D1"/></span><span leaf="" style="line-height: 1.4;user-select: text;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;-webkit-tap-highlight-color: transparent;margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 8px;text-align: left;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=bd67476a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D1"/></span><span leaf="" style="line-height: 1.4;user-select: text;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;-webkit-tap-highlight-color: transparent;margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:17.55pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">10</span></span></p></td></tr></tbody></table><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></p></div></div></div></h1></p></h1></p></div></div></div></div><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0pt 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">React 19.0.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">React 19.1.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">React 19.1.1</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">React 19.2.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">React DOM 19.0.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">React DOM 19.1.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">React DOM 19.1.1</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">React DOM 19.2.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-parcel (npm) 19.0.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-parcel (npm) 19.1.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-parcel (npm) 19.1.1</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-parcel (npm) 19.2.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-turbopack (npm) 19.0.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-turbopack (npm) 19.1.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-turbopack (npm) 19.1.1</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-turbopack (npm) 19.2.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-webpack (npm) 19.0.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-webpack (npm) 19.1.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-webpack (npm) 19.1.1</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">react-server-dom-webpack (npm) 19.2.0</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">14.3.0-canary.77 &lt;= next.js &lt; 15.0.5</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">15.1.0 &lt;= next.js &lt; 15.1.9</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">15.2.0 &lt;= next.js &lt; 15.2.6</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">15.3.0 &lt;= next.js &lt; 15.3.6</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">15.4.0 &lt;= next.js &lt; 15.4.8</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">15.5.0 &lt;= next.js &lt; 15.5.7</span></span></p><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">16.0.0 &lt;= next.js &lt; 16.0.7</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=9e0b47b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D4"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">修复建议</span></span></strong></p></div></div></div></h1></p></h1></p></div></div></div></div></div><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(1) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Next.js </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">所有用户都应升级到其版本系列中的最新补丁版本：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install next@15.0.5</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">// </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 15.0.x</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install next@15.1.9</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">// </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 15.1.x</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install next@15.2.6</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">// </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 15.2.x</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install next@15.3.6</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">// </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 15.3.x</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install next@15.4.8</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">// </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 15.4.x</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install next@15.5.7</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">// </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 15.5.x</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install next@16.0.7</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">// </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 16.0.x</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(2) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如果您使用的是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Next.js 14.3.0-canary.77 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或更高版本的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> canary </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本，请降级到最新的稳定版</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 14.x</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install next@14</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">更多信息请参阅</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Next.js </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">更新日志：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://nextjs.org/blog/CVE-2025-66478" target="_blank">https://nextjs.org/blog/CVE-2025-66478</a></span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(3) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> React Router </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如果您使用的是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> React Router </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">不稳定的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> RSC API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，则应升级</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> package.json </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">文件中存在的以下依赖项：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react-dom@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react-server-dom-parcel@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react-server-dom-webpack@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install @vitejs/plugin-rsc@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(4) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Expo </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">升级到最新版本</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> react-server-dom-webpack</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react@latest react-dom@latest react-server-dom-webpack@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(5) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Redwood SDK </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请确保您使用的是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> rwsdk </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> &gt;= 1.0.0-alpha.0</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install rwsdk@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">升级到最新版本</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> react-server-dom-webpack</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react@latest react-dom@latest react-server-dom-webpack@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">具体请参阅</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Redwood </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">文档：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://docs.rwsdk.com/migrating/" target="_blank">https://docs.rwsdk.com/migrating/</a></span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(6) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Waku </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">升级到最新版本</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> react-server-dom-webpack</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react@latest react-dom@latest react-server-dom-webpack@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(7) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> RSC </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">插件</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">@vitejs/plugin-rsc </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">升级到最新版</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> RSC </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">插件：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react@latest react-dom@latest @vitejs/plugin-rsc@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(8) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> react-server-dom-parcel </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">更新至最新版本：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react@latest react-dom@latest react-server-dom-parcel@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(9) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> react-server-dom-turbopack </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">更新至最新版本：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react@latest react-dom@latest react-server-dom-turbopack@latest</span></span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(10) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">针对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> react-server-dom-webpack </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">更新至最新版本：</span></span></p><p style="font-weight: 400;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npm install react@latest react-dom@latest react-server-dom-webpack@latest</span></span></span></p></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">二、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Next.js </span></span></span></strong><b style="font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Next.js</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-39597(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-66478</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Next.js</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个基于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> React </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的流行全栈框架，以其强大的服务器端渲染（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SSR</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）和静态站点生成（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SSG</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）能力而闻名，旨在简化高性能、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SEO </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">友好的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Web </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用的开发过程。它提供了开箱即用的功能，如基于文件系统的路由、自动代码分割、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">路由支持以及内置的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> CSS </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">处理，使得开发者能够快速构建从静态博客到复杂动态应用的各种项目。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Next.js</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持多种渲染方式，允许开发者根据页面需求灵活选择静态生成或服务器端渲染，以优化加载速度和用户体验。</span></span></p><span style="clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;text-align: justify;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">由于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> React Server Components (RSC) </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">存在反序列化漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CVE-2025-55182</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">），依赖该组件的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Next.js</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">框架同样受到影响。攻击者可以通过构造恶意请求触发该漏洞，从而导致远程代码执行。</span></span></span><p data-pm-slice="0 0 []" style="margin-bottom: 8px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 8px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.6pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.5pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">10</span></span></p></td></tr></tbody></table><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></p></div></div></div></h1></p></div></div></div></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">14.3.0-canary.77 &lt;= next.js &lt; 15.0.5</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">15.1.0 &lt;= next.js &lt; 15.1.9</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">15.2.0 &lt;= next.js &lt; 15.2.6</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">15.3.0 &lt;= next.js &lt; 15.3.6</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">15.4.0 &lt;= next.js &lt; 15.4.8</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">15.5.0 &lt;= next.js &lt; 15.5.7</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">16.0.0 &lt;= next.js &lt; 16.0.7</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></h1></p></div></div></div><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://nextjs.org/" target="_blank">https://nextjs.org/</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问服务器。</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;" data-pm-slice="8 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">三、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Vite Plugin RSC 远程代码执行漏洞</span></span></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Vite Plugin RSC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-39935</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-67489</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-1092</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Vite Plugin RSC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Vite</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">构建工具提供</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">React Server Components</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RSC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）支持的插件。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Vite</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是新一代前端构建工具，以其快速的冷启动和热模块替换（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HMR</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）能力而闻名。该插件通过集成</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RSC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">功能，使开发者能够在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Vite</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">项目中使用服务器端组件，从而实现更高效的应用架构。它支持在开发环境中快速迭代和测试</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RSC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用，提供了与</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Vite</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">生态系统的无缝集成。该插件特别适用于需要结合服务器端渲染和客户端交互的现代</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Web</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用开发场景，为开发者提供了灵活的开发体验和优化的性能表现。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Vite Plugin RSC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在服务器函数</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">loadServerAction</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">decodeReply</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">decodeAction</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）中使用了不安全的动态导入机制，当集成到暴露服务器函数端点的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RSC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用中时，攻击者可以利用该动态导入机制执行任意代码，进而读取或修改文件、窃取源代码、环境变量、凭证等敏感数据，或访问其他内部服务。</span></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 8px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 8px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.8</span></span></p></td></tr></tbody></table><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></p></div></div></div></h1></p></div></div></div></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">Vite Plugin RSC &lt;= 0.5.5</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">修复建议</span></span></strong></p></div></div></div></h1></p></div></div></div></div></div></div><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/vitejs/vite-plugin-react/releases" target="_blank">https://github.com/vitejs/vite-plugin-react/releases</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">避免使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">vite --host</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">将开发服务器暴露在所有网络接口上。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问服务器。</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">四、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Vite Plugin RSC 任意文件读取漏洞</span></span></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div></div></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Vite Plugin RSC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-42416</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-68155</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-2780</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可读取任意文件，窃取敏感信息。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Vite Plugin RSC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">中的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">/__vite_rsc_findSourceMapURL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">端点在开发模式下允许未经身份验证的任意文件读取，攻击者可以通过在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">filename</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">查询参数中发送带有</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">file://</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">协议</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTTP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求，读取</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Node.js</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">进程可访问的任何文件，从而窃取源代码、配置文件、环境变量等敏感信息。</span></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 8px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="margin-bottom: 8px;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">7.5</span></span></p></td></tr></tbody></table><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></p></div></div></div></h1></p></div></div></div></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">Vite Plugin RSC &lt;= 0.5.7</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">修复建议</span></span></strong></p></div></div></div></h1></p></div></div></div></div></div><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/vitejs/vite-plugin-react/releases" target="_blank">https://github.com/vitejs/vite-plugin-react/releases</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">使用默认配置启动</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Vite</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，限制对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Vite </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">开发服务器的访问，关闭</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> server.host </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或绑定到特定的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> IP </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址。</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;" data-pm-slice="8 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">五、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">MongoDB </span></span></span></strong><b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">信息泄露漏洞</span></span></b></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">MongoDB</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-43023</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-14847</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-3766</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可读取服务器堆内存中未初始化的敏感数据。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">MongoDB</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一款流行的开源文档型数据库，它使用类似</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JSON</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">BSON</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">格式存储数据，支持动态模式，允许数据结构灵活变化，非常适合需要快速迭代和存储多样化数据格式的现代应用。作为介于关系型和非关系型数据库之间的产品，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">MongoDB</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">兼具高性能、易扩展、易部署等特点，并提供了丰富的查询功能和索引支持。它广泛应用于移动应用、物联网、游戏、社交、物流等多个领域，能够有效满足实时数据处理、高并发写入及海量数据存储的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据官方描述，在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> MongoDB Server </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的受影响版本中，当其处理使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Zlib </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">压缩的协议消息时，对消息头部中的长度字段校验存在缺陷。若攻击者构造一个包含不匹配长度字段的特制压缩消息并发送给</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> MongoDB </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器，服务器在解压并处理该消息的过程中，可能基于声明的长度从堆内存缓冲区中读取超出实际数据范围的数据。这些超出部分的数据是先前残留在堆内存中、未经过初始化的旧数据，从而导致服务器在响应中包含这些本不应被访问的内存残片信息。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p></h1></p></h1></p></div></div></h1></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已发现</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p></h1></p></h1></p></div></div></h1></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">8.7</span></span></p></td></tr></tbody></table><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong></p></div></div></div></div></div></div></h1></p></h1></p></div><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p data-pm-slice="0 0 []"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">MongoDB Server 3.6</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">MongoDB Server 4.0</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">MongoDB Server 4.2</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">4.4.0 &lt;= MongoDB &lt; 4.4.30</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">5.0.0 &lt;= MongoDB &lt; 5.0.32</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">6.0.0 &lt;= MongoDB &lt; 6.0.27</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">7.0.0 &lt;= MongoDB &lt; 7.0.28</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">8.0.0 &lt;= MongoDB &lt; 8.0.17</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">8.2.0 &lt;= MongoDB &lt; 8.2.3</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></h1></p></div></div></div><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://www.mongodb.com/try/download/community" target="_blank">https://www.mongodb.com/try/download/community</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">缓解措施：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在 MongoDB 服务器上禁用 Zlib 压缩。具体操作方法如下：</span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可通过为 mongod或mongos 进程设置 networkMessageCompressors 或 net.compression.compressors 启动选项，并明确排除 zlib（可使用其它示例安全值：snappy、zstd 或直接设置 disabled 完全禁用），来禁用 Zlib 压缩，从而临时缓解该漏洞。</span></span></span></p></div></div></div></div></div></div></div></div></div></div><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;" data-pm-slice="8 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">六、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">n8n 远程代码执行漏洞</span></span></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-43636</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-68668</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-4823</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个开源的工作流自动化平台，允许用户通过可视化界面创建和管理复杂的自动化工作流。它支持数百种集成服务和应用，使用户能够连接不同的系统和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，实现数据同步、任务自动化和业务流程优化。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">提供了灵活的节点系统，包括代码节点（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Code Node</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">），允许用户编写自定义的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JavaScript</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码来处理数据和实现特定逻辑。该平台可以自托管部署，为企业提供了完全的数据控制权和隐私保护。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python Code Node</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Pyodide</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在浏览器环境中运行</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Python</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码，为用户提供了强大的数据处理能力。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据官方描述，在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> n8n 1.0.0 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">至</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 2.0.0 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">之前的版本中，其基于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Pyodide </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">实现的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Python </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码节点存在沙箱隔离缺陷。该节点旨在为工作流提供安全的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Python </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码执行环境，但其隔离机制（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Pyodide</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）可能被经过身份验证的攻击者通过注入或构造特定的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Python </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码绕过，从而突破沙箱限制，直接访问并操作底层主机操作系统的资源。这使得拥有创建工作流权限的攻击者可以通过编辑或创建包含恶意代码的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Python </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">节点，以</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> n8n </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">进程的权限在服务器上执行任意系统命令。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p></h1></p></h1></p></div></div></h1></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p></h1></p></h1></p></div></div></h1></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.9</span></span></p></td></tr></tbody></table><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></p></div></div></div></h1></p></div></div></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;"><span leaf="">1.0.0 &lt;= n8n &lt; 2.0.0</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></h1></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/n8n-io/n8n/releases" target="_blank">https://github.com/n8n-io/n8n/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">由于 n8n 从 1.111.0 版本起，引入了基于任务运行器（task-runner）的原生 Python 实现可选功能，提供了更安全的隔离模型。因此也可通过配置环境变量 N8N_RUNNERS_ENABLED 和 N8N_NATIVE_PYTHON_RUNNER 启用进行修复。并且此安全实现自 2.0.0 版本起已成为默认配置。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">3. </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">缓解措施：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">禁用代码节点：设置环境变量 NODES_EXCLUDE: &#34;[\&#34;n8n-nodes-base.code\&#34;]&#34;，可参考以下链接：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://docs.n8n.io/hosting/securing/blocking-nodes/" target="_blank">https://docs.n8n.io/hosting/securing/blocking-nodes/</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 禁用 Python 支持：设置环境变量 N8N_PYTHON_ENABLED=false（该环境变量自 1.104.0 版本引入）。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 启用安全沙箱：配置环境变量 N8N_RUNNERS_ENABLED 和 N8N_NATIVE_PYTHON_RUNNER，以使用基于任务运行器的 Python 沙箱，可参考以下链接：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-font-family="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://docs.n8n.io/hosting/configuration/task-runners/" target="_blank">https://docs.n8n.io/hosting/configuration/task-runners/</a></span></span></span></p></div></div></div></div></div></div></div><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;" data-pm-slice="8 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">七、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">n8n </span></span></span></strong><b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-43077</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-68613</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-3773</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，，最终可远程执行任意代码。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据官方描述，由于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">工作流表达式的评估环境未能与底层</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Node.js </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">运行时充分隔离，导致经过身份验证的远程攻击者可在特定条件下，通过配置恶意表达式突破沙箱限制，从而直接访问并操作</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Node.js </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">全局对象或内置模块，最终在运行</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">进程的服务器上以该进程权限执行任意操作系统命令。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p></h1></p></div></div></h1></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p></h1></p></div></div></h1></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.9</span></span></p></td></tr></tbody></table><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></p></div></div></div></h1></p></div></div></div></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">0.211.0 &lt;= n8n &lt; 1.120.4</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">1.121.0 &lt;= n8n &lt; 1.121.1</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">n8n &lt; 1.122.0</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></h1></p></div></div></div><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/n8n-io/n8n/releases" target="_blank">https://github.com/n8n-io/n8n/releases</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">限制工作流创建和编辑权限，仅授予完全可信的用户。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在加固的环境中部署</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">n8n</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，限制操作系统权限和网络访问，以减少潜在利用的影响。</span></span></p></div></div></div></div></div></div></div></div><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;" data-pm-slice="8 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">八、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Langflow </span></span></span></strong><b><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-39936</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-34291</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-629</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可实现账户接管和远程代码执行。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个开源的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代理工作流平台，专为构建和部署基于大语言模型（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）的应用而设计。它提供了直观的可视化界面，允许开发者通过拖放组件的方式创建复杂的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">工作流，无需编写大量代码。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持多种</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">提供商和集成，包括</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Hugging Face</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等，使开发者能够快速原型设计和部署</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用。该平台提供了丰富的预构建组件和自定义代码执行功能，适用于聊天机器人、数据处理管道、智能助手等多种应用场景。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的灵活性和易用性使其成为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用开发的热门选择。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Langflow </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">中，由于后端服务器启用了过度宽松的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> CORS </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">策略（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">allow_origins=&#39;*&#39; </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">且</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> allow_credentials=True</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">），并且如果关键的身份验证令牌</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Cookie</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">refresh_token_lf</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）被设置为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> SameSite=None</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，则导致攻击者可构造恶意网页并诱导受害者发起包含该</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Cookie </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">凭证的跨源请求，成功调用受攻击的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> /api/v1/refresh </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">端点，从而获取新的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> access_token </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">与</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> refresh_token </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">令牌对，实现完全会话劫持。攻击者可利用窃取的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> access_token</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，调用已认证的内置代码执行（如</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">/api/v1/validate/code</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）等端点，最终在受害者会话中实现远程代码执行，从而彻底控制系统。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p></h1></p></div></div></h1></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p></h1></p></div></div></h1></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.4</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></strong></p></div></div></div></h1></p></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">Langflow &lt;= 1.6.9</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></h1></p></div></div></div><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 1.6.0 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本中通过环境变量自定义</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> CORS </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">来源进行修复，但是默认配置下仍然存在该漏洞。官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】由于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.7.0 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本升级后显示持久化数据时出现回归问题，目前已从</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PyPI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">下架，因此受影响用户应升级至</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.7.1</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或更高版本。建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/langflow-ai/langflow/releases" target="_blank">https://github.com/langflow-ai/langflow/releases</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解措施：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可参考以下官方</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> CORS </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置文档强化部署：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://docs.langflow.org/api-keys-and-authentication#cors-configuration-for-authentication" target="_blank">https://docs.langflow.org/api-keys-and-authentication#cors-configuration-for-authentication</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务。</span></span></p></div></div></div></div></div></div></div></div><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;" data-pm-slice="8 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">九、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Langflow </span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">服务器端请求伪造漏洞</span></span></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-43051</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-68477</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-3805</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可实现服务器端请求伪造，访问内部资源并窃取敏感信息。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据官方描述，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API Request </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">组件在接收用户输入（来自工作流配置或运行时参数）的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> URL </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">后，仅进行格式校验与协议标准化，而未对目标地址实施任何网络边界检查（如阻止对本地回环地址</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 127.0.0.1</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、私有</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> IP </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">10.0.0.0/8</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">172.16.0.0/12</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">192.168.0.0/16</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或云元数据地址</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 169.254.169.254 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的访问）。由于执行工作流的接口仅需有效的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> API </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">密钥即可调用，因此攻击者可通过构造包含恶意</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> URL </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的工作流参数，使服务器端的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> httpx </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">客户端代理其发起请求，并将完整的响应内容（包括响应体）返回给攻击者，从而实现非盲的服务器端请求伪造，导致信息泄露。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p></h1></p></div></div></h1></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p></h1></p></div></div></h1></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">7.7</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></strong></p></div></div></div></h1></p></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;"><span leaf="">Langflow &lt; 1.7.0</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></h1></p></div></div></div><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】由于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 1.7.0 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本升级后显示持久化数据时出现回归问题，目前已从</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PyPI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">下架，因此受影响用户应升级至</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.7.1</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或更高版本。建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/langflow-ai/langflow/releases" target="_blank">https://github.com/langflow-ai/langflow/releases</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">限制</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">密钥的使用范围，仅授予可信用户。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Langflow</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务。</span></span></p></div></div></div></div></div></div></div></div><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;" data-pm-slice="8 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">十、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">LangChain </span></span></span></strong><b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">反序列化漏洞</span></span></b></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LangChain</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-43363</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-68664</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-4029</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可通过序列化注入实现任意代码执行或数据篡改。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LangChain</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个用于构建基于大语言模型（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）的代理和应用程序的开源框架。它提供了丰富的工具和抽象层，使开发者能够轻松地将</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">集成到各种应用场景中，包括聊天机器人、问答系统、文档分析等。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LangChain</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持多种</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">提供商，如</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Anthropic</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Hugging Face</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等，并提供了链式调用、记忆管理、工具集成等高级功能。该框架的序列化功能允许将复杂的对象结构转换为可存储或传输的格式，通过</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">dumps()</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">dumpd()</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">函数实现对象的序列化和反序列化。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LangChain</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的灵活性和强大功能使其成为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用开发的热门选择。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LangChain</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">dumps()</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">dumpd()</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">函数在序列化自由格式字典时未对包含</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">&#39;lc&#39;</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">键的字典进行转义处理。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">&#39;lc&#39;</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">键是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LangChain</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">内部用于标记序列化对象的特殊键，当用户控制的数据包含此键结构时，在反序列化过程中会被视为合法的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LangChain</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">对象而非普通用户数据，从而导致序列化注入漏洞，攻击者可以利用此漏洞执行任意代码或篡改数据。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p></h1></p></div></div></h1></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p></h1></p></div></div></h1></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;mso-bidi-font-size:12.0pt;color:#222222;letter-spacing:.4pt;"><span leaf="">9.3</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></strong></p></div></div></div></h1></p></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#333333;background:white;"><span leaf="">LangChain &lt; 0.3.81</span></span></p><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#333333;background:white;"><span leaf="">1.0.0 &lt;= LangChain &lt; 1.2.5</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></h1></p></div></div></div><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/langchain-ai/langchain/releases" target="_blank">https://github.com/langchain-ai/langchain/releases</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">更新至安全版本后，通过以下官方迁移指南检查并修改自己的业务代码：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm" target="_blank">https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">3.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span></p></div></div></div></div></div></div></div></div><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;" data-pm-slice="8 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">十一、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Dify </span></span></span></strong><b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">硬编码漏洞</span></span></b></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=47ef1bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D5"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Dify</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-42913</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-56157</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202512-3420</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可使用默认凭证访问</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PostgreSQL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">数据库，窃取或篡改敏感数据。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Dify</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个开源的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用开发平台，旨在简化</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用的构建和部署流程。它提供了可视化的工作流编排、提示词管理、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RAG</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">（检索增强生成）引擎、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代理构建等功能，使开发者能够快速创建和部署基于大语言模型的应用。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Dify</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持多种</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">提供商，包括</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Anthropic</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Azure OpenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等，并提供了完整的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SDK</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">供开发者集成。该平台的文件管理功能允许用户上传和管理各种文件资源，这些文件用于支持</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">RAG</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用、知识库构建等场景。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Dify</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的灵活性和强大功能使其成为企业级</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用开发的热门选择。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Dify</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在其源代码中包含的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">docker-compose.yaml</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">文件中使用了默认的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PostgreSQL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户名和密码，这些默认凭证未被强制要求在部署时更改。攻击者可以利用这些公开的默认凭证直接访问</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PostgreSQL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">数据库，从而窃取敏感数据（如用户信息、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">密钥、工作流配置等）或篡改数据库内容，导致严重的安全风险。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p></h1></p></div></div></h1></p><table style="margin-left:-.5pt;background:white;border-collapse:collapse;mso-table-layout-alt:
 fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.0pt;mso-bidi-font-size:12.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:
  minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">安全补丁</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞细节</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">PoC</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">已公开</span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">在野利用</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">未发现</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><b><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf38274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D6"/></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;align-items: center;justify-content: flex-start;letter-spacing: 2px;color: rgb(63, 62, 63);font-weight: bold;visibility: visible;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p></h1></p></div></div></h1></p><table style="background:white;border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><b><span style="font-size:11.5pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:white;letter-spacing:.4pt;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">威胁等级</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高危</span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">影响面</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">攻击者价值</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">高</span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">利用难度</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">低</span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span style="font-size:10.0pt;mso-ascii-font-family:等线;mso-ascii-theme-font:minor-fareast;mso-hansi-font-family:等线;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">漏洞评分</span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;word-break:break-all;"><span lang="EN-US" style="font-size:10.0pt;font-family:等线;mso-ascii-theme-font:minor-fareast;mso-fareast-font-family:宋体;mso-hansi-theme-font:minor-fareast;color:#222222;letter-spacing:.4pt;"><span leaf="">9.8</span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=61f67fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D3"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">影响版本</span></span></strong></strong></p></div></div></div></h1></p></div></div></div><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:等线;mso-bidi-font-family:等线;color:#222222;letter-spacing:
.4pt;"><span leaf="">Dify &lt;= 1.5.1</span></span></p><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.4;user-select: text;background-color: rgb(255, 255, 255);"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 20px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3c225c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D9"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></h1></p></div></div></div><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布安全建议，请评估业务是否受影响后，立即更改</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PostgreSQL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">数据库的默认用户名和密码。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在修改前做好数据备份工作，避免出现意外。</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/langgenius/dify" target="_blank">https://github.com/langgenius/dify</a></span></span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">修改</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">docker-compose.yaml</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">文件中的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PostgreSQL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">默认凭证</span></span></p><p style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PostgreSQL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">数据库端口</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;font-family: 等线;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-style: italic;">*</span><span textstyle="" style="font-size: 15px;font-style: italic;">以上</span></span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;font-family: 宋体;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;font-style: italic;">漏洞评分为腾讯云安全研究人员根据漏洞情况作出，仅供参考，具体漏洞细节请以原厂商或是相关漏洞平台公示为准。</span></span></span></p><div hm_fix="385:564" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 0.544px;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 32px;"><img data-aistatus="1" alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="0.8768115942028986" data-type="gif" data-w="276" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;display: block;width: 32px !important;visibility: visible !important;" data-width="100%" data-imgfileid="100012836" src="https://wechat2rss.xlab.app/img-proxy/?k=1fabce25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FFIBZec7ucChYUNicUaqntiamEgZ1ZJYzLRasq5S6zvgt10NKsVZhejol3iakHl3ItlFWYc8ZAkDa2lzDc5SHxmqjw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D40"/></p><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px 0em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">END</span></strong></p></div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 0.544px;color: rgb(163, 163, 163);font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 5px 1em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 24px 8px 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-indent: 0em;font-variant-numeric: normal;font-variant-east-asian: normal;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关注云鼎实验室，获取更多安全情报</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-variant-numeric: normal;font-variant-east-asian: normal;min-height: 1em;color: rgb(163, 163, 163);letter-spacing: 0.54px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;text-align: center;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.6" data-s="300,640" data-type="jpeg" data-w="900" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;letter-spacing: 0.54px;width: 397px !important;visibility: visible !important;" data-copyright="0" data-imgfileid="100012835" src="https://wechat2rss.xlab.app/img-proxy/?k=dee947fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D41"/></p></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=63342c4a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485128%26idx%3D1%26sn%3D1fbc1ceef8a90709e3d5644a809a5c12">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 08 Jan 2026 16:35:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年11月企业必修安全漏洞清单</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485126&amp;idx=1&amp;sn=9725c8d9c998e8d681b2254469fa44d1</link>
      <description>所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重的后果。</description>
      <content:encoded><![CDATA[<p><span>云鼎实验室</span> <span>2025-12-12 10:17</span> <span style="display: inline-block;">广东</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7445f4c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FC47afWcpnuY0tGZTZVmz60aNQoL1yYYZJbrfcbCF1kwS5Wia3hDffTeb2EicrwmtlfCKFBH38ExEqHmCcIZUWkOg%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 27px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;width: 663.458px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(78, 132, 216);visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;visibility: visible;"><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);letter-spacing: 0.544px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重的后果。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">腾讯云安全参考“安全漏洞的危害及影响力、漏洞技术细节披露情况、该漏洞在安全技术社区的讨论热度”等因素，综合评估该漏洞在攻防实战场景的风险。当漏洞综合评估为风险严重、影响面较广、技术细节已披露，且被安全社区高度关注时，就将该漏洞列入必修安全漏洞候选清单。 </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;line-height: 1.75em;text-align: justify;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">腾讯云安全定期发布安全漏洞必修清单，以此指引企业安全运维人员修复漏洞，从而避免重大损失。 </span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(3, 97, 243);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">以下是2025年11月份必修安全漏洞清单</span></span></strong></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;text-align: justify;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">一、React Native CLI 命令注入漏洞</span></span></strong><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">(</span></span></span><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background: rgb(255, 255, 255);justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;font-size: 15px;clear: both;min-height: 1em;letter-spacing: 0.544px;line-height: 1.75em;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">11953</span></span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;text-align: justify;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">二</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">、</span><span textstyle="" style="font-size: 14px;font-weight: normal;">Anyscale Ray 远程代码执行漏洞（CVE-2025-34351）</span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;text-align: justify;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">三、</span><span textstyle="" style="font-size: 14px;font-weight: normal;"> Fugue Pickle 反序列化远程代码执行漏洞（CVE-2025-62703）</span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;text-align: justify;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">四、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;font-weight: normal;">GeoServer XML 外部实体注入漏洞（CVE-2025-58360）</span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;text-align: justify;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">五、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;font-weight: normal;">Grafana Enterprise SCIM 权限提升漏洞（CVE-2025-41115）</span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;text-align: justify;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">六、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;font-weight: normal;">Fortinet Fortiweb 命令注入漏洞（CVE-2025-58034）</span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;text-align: justify;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">七、</span><span textstyle="" style="font-size: 14px;font-weight: normal;">Google Chrome V8 类型混淆漏洞（CVE-2025-13223）</span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;text-align: justify;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;font-weight: normal;">八、</span></span></strong><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;font-weight: normal;">Fortinet FortiWeb 路径遍历漏洞（CVE-2025-64446）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;font-weight: normal;">九、 </span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;font-weight: normal;">Open WebUI 远程代码执行漏洞（CVE-2025-64496）</span></span></span></p></div><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;text-align: justify;color: rgb(3, 97, 243);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">漏洞介绍及修复建议详见后文</span></strong></span></p></div></div></div></div></div></div><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="8 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;rich_media_title &#34;,&#34;id&#34;:&#34;activity-name&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px 0px 14px; padding: 0px; outline: 0px; font-weight: 500; font-size: 22px; line-height: 1.4; user-select: text; color: rgba(0, 0, 0, 0.9); font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: 0.544px; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">一、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);"> React Native CLI 命令注入漏洞</span></span></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img data-imgfileid="100012797" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ae9f7fd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D0"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于React Native Community CLI的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"> TVD-2025-36321</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-11953</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202511-058</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程执行</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意代码</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">React Native Community CLI是React Native框架的核心命令行工具，用于创建、构建和管理React Native移动应用项目。该工具集成了Metro开发服务器，为开发者提供实时代码更新、调试和打包功能。Metro服务器是React Native开发环境的关键组件，负责处理JavaScript代码的打包和热重载，使开发者能够快速迭代和测试移动应用。该CLI工具广泛应用于iOS和Android平台的跨平台移动应用开发，是React Native生态系统中不可或缺的开发基础设施</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在 React Native CLI 开启的 Metro 开发服务器中，由于其默认绑定到外部网络接口，且暴露的 /open-url 服务端点存在输入验证缺陷，导致未经身份验证的远程攻击者可通过向该服务器发送特制的请求注入并执行任意操作系统命令，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在Windows系统上攻击者还可以获得对shell命令参数的额外控制权，进一步扩大攻击面</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img data-imgfileid="100012815" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: inherit;height: auto !important;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=bd67476a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D1"/></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">状态</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">等级</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 17.55pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 17.55pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">9.8</span></span></span></p></td></tr></tbody></table></div></h1></p></div></div></h1><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong></p></div></div></div></div></div></div></div></h1><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">4.8.0 &lt;= </span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">React Native CLI</span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">&lt; 20.0.0</span></span></p></div></h1></p></div></div></div><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></div></div></h1><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;font-weight: 400;font-size: 16px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/react-native-community/cli/releases" target="_blank">https://github.com/react-native-community/cli/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 参考以下配置将开发服务器显式绑定到本地主机接口：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npx react-native start --host 127.0.0.1</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">npx react-native-community/cli start --host 127.0.0.1</span></span></span></p></div></h1></p></div></div></div></div></h1><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">二、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Anyscale Ray 远程代码执行漏洞</span></span></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Anyscale Ray的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-39025</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-34351</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202511-2970</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可远程</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Anyscale Ray是一个开源的分布式计算框架，专为人工智能和机器学习工作负载设计。该框架提供了统一的API来构建和运行分布式应用程序，支持大规模并行计算、分布式训练和强化学习等场景。Ray框架包含多个核心组件，其中管理界面（Dashboard）和作业API（Jobs API）用于监控集群状态、提交和管理计算任务。Ray被广泛应用于AI模型训练、超参数调优、数据处理等领域，是现代机器学习基础设施的重要组成部分，被众多科技公司和研究机构采用。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Anyscale Ray </span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的默认配置存在安全隐患，除非显式启用（通过设置 RAY_AUTH_MODE=token），否则Ray管理接口的基于令牌的身份验证功能将被禁用。在默认的未认证状态下，远程攻击者可以通过网络访问这些接口，从而提交作业并在 Ray 集群上执行任意代码。</span></span></span></p><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">状态</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 548px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">等级</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">9.3</span></span></p></td></tr></tbody></table></div></h1></p></h1></p></div></div></h1><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong></p></div></div></div></div></div></div></h1></p></h1></p></div><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0pt 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(34, 34, 34);letter-spacing: 0.4pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Anyscale Ray </span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(34, 34, 34);letter-spacing: 0.4pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">&lt;</span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(34, 34, 34);letter-spacing: 0.4pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">= 2.52.</span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(34, 34, 34);letter-spacing: 0.4pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">0</span></span></p></div></div></div></div></div></div><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div></div></div></div></div></h1><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.官方暂未发布漏洞补丁及修复版本，请持续关注官方公告，待修复版本发布评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/ray-project/ray" target="_blank">https://github.com/ray-project/ray</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. 临时缓解方案：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 请按照以下指南在 Ray 中启用身份验证机制：</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://docs.ray.io/en/latest/ray-security/token-auth.html" target="_blank">https://docs.ray.io/en/latest/ray-security/token-auth.html</a></span></span></span></p></div></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">三、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Fugue Pickle 反序列化远程代码执行漏洞</span></span></strong></p></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Fugue的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-39016</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">:CVE-2025-62703</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202511-2699</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Fugue是一个开源的分布式计算框架，旨在简化大规模数据处理和分析工作流程。该框架提供了统一的编程接口，支持在多种执行引擎（如Spark、Dask等）上运行相同的代码，使开发者能够轻松地在本地和分布式环境之间切换。Fugue的RPC（远程过程调用）服务器组件负责处理分布式节点之间的通信和数据传输，是框架实现分布式计算能力的核心基础设施。该框架被广泛应用于数据科学、机器学习和大数据分析领域，为企业提供灵活高效的数据处理解决方案。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Fugue存在不安全的pickle反序列化缺陷，在fugue/rpc/flask.py文件中的_decode()函数</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">没有对数据</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">进行验证检查</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">直接使用cloudpickle.loads()方法对接收到的数据进行反序列化</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">攻击者可以向RPC服务器发送</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">特制</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">触发任意代码执行，从而完全控制服务器，并可能在分布式环境中实现横向移动</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">状态</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">等级</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">8.8</span></span></p></td></tr></tbody></table></div></h1></p></div></h1></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong></p></div></div></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(34, 34, 34);letter-spacing: 0.4pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Fugue &lt;= 0.9.2</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></p></div></div></div><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="宋体" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/fugue-project/fugue/releases" target="_blank">https://github.com/fugue-project/fugue/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">缓解</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">方案</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">避免开放</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">至</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">公网</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 利用安全组设置仅对可信地址开放</span></span></span></p></div></div></div></div></div></h1></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">四、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);"> GeoServer XML 外部实体注入漏洞</span></span></span></strong></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于GeoServer的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-38902</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-58360</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202511-2702</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">读取服务器敏感文件</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">探测</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">内部</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">网络</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">GeoServer是一个开源的地理空间数据服务器，遵循开放地理空间联盟（OGC）标准，用于发布、共享和处理地理空间数据。该软件支持多种地理数据格式，包括Shapefile、GeoTIFF、PostGIS等，并提供WMS（Web地图服务）、WFS（Web要素服务）、WCS（Web覆盖服务）等标准化接口。GeoServer被广泛应用于政府、科研机构和企业的地理信息系统（GIS）中，用于构建地图服务、空间数据分析和可视化平台。其WMS模块是核心功能之一，负责根据客户端请求生成和返回地图图像。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于GeoServer的WMS模块在处理GetMap操作时，XML解析器未能正确禁用DTD和外部实体引用</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">攻击者可以向/geoserver/wms端点发送包含恶意外部实体的XML请求，利用</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">漏洞读取服务器上的敏感文件，或通过SSRF探测内部网络和云元数据服务</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-pm-slice="4 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">状态</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">等级</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.6pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.6pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">9.8</span></span></span></p></td></tr></tbody></table></div></div></h1><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;justify-content: flex-start;display: inline-block;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;">影响版本</span></strong></p></div></div></div></div></div></h1></div></div><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(34, 34, 34);letter-spacing: 0.4pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">GeoServer &lt; 2.25.6</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(34, 34, 34);letter-spacing: 0.4pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2.26.0 &lt;= GeoServer &lt; 2.26.</span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(34, 34, 34);letter-spacing: 0.4pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2</span></span></p></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复建议</span></strong></strong></p></div></div></div></div><p data-role="paragraph" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="宋体" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/geoserver/geoserver/releases" target="_blank">https://github.com/geoserver/geoserver/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. 临时缓解方案：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 限制对/geoserver/wms端点的访问，仅允许受信任的IP地址访问</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 配置防火墙或网络规则，仅允许特定IP地址或IP段访问GeoServer服务</span></span></span></p></div></div></div></div></h1></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><code style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></code></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">五、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);"> Grafana Enterprise SCIM 权限提升漏洞</span></span></span></strong></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Grafana的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-38607</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">:CVE-2025-41115</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202511-2460</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">实现身份冒充或权限提升，获取管理员权限</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Grafana是一个开源的数据可视化和监控平台，广泛应用于企业级IT基础设施监控、应用性能管理和业务数据分析。该平台支持多种数据源（如Prometheus、InfluxDB、Elasticsearch等），提供强大的仪表板创建和数据查询功能。Grafana Enterprise是其商业版本，提供了额外的企业级功能，包括SCIM（跨域身份管理系统）支持。SCIM是一个开放标准协议，用于自动化用户身份的创建、更新和删除，使企业能够在多个系统之间同步用户身份信息。Grafana的SCIM组件允许组织通过身份提供商（如Okta、Azure AD）自动管理Grafana用户账户，简化用户生命周期管理流程。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据官方描述，在 Grafana Enterprise 的 SCIM 用户配置功能中，由于系统将 SCIM 协议中的 externalId 字段直接映射到内部用户 ID（user.uid）而未进行类型安全校验，导致恶意的 SCIM 客户端可通过提交数字形式的 externalId（如&#34;1&#34;）覆盖系统内置管理员账户身份，从而实现用户冒充和权限提升，并获得 Grafana 实例的最高控制权</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。该漏洞仅在同时启用enableSCIM功能标志和user_sync_enabled配置选项时才会被触发</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-pm-slice="4 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">状态</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table></div></div></h1><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></table><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(255, 255, 255);">类别</span></span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(255, 255, 255);">等级</span></span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">10</span></span></span></p></td></tr></tbody></table><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></div></div></div></h1><div data-pm-slice="4 4 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">12.0.0 &lt;= Grafana Enterprise &lt; 12.0.6</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">12.1.0 &lt;= Grafana Enterprise &lt; 12.1.3</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">12.2.0 &lt;= Grafana Enterprise &lt; 12.2.1</span></span></p></div><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></p></div></div></div></div></div></div></h1><div data-pm-slice="4 4 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. 官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="宋体" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://grafana.com/blog/2025/11/19/grafana-enterprise-security-update-critical-severity-security-fix-for-cve-2025-41115/" target="_blank">https://grafana.com/blog/2025/11/19/grafana-enterprise-security-update-critical-severity-security-fix-for-cve-2025-41115/</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. 临时缓解方案：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 如非必需，禁用SCIM配置功能（将enableSCIM和user_sync_enabled设置为false）</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">六、</span></span></span></strong><span data-font-family="等线" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Fortinet Fortiweb 命令注入漏洞</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Fortinet FortiWeb的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-38261</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-58034</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202511-2017</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">命令</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">FortiWeb是Fortinet公司推出的企业级Web应用防火墙（WAF）产品，专门用于保护Web应用程序和API免受各种网络攻击。该产品提供了全面的安全防护功能，包括SQL注入防护、跨站脚本（XSS）防护、DDoS防护、机器人检测和API安全等。FortiWeb支持多种部署模式，包括反向代理、透明代理和离线检测模式，可灵活集成到现有网络架构中。作为企业安全基础设施的关键组件，FortiWeb被广泛部署在金融、电商、政府和医疗等行业，用于保护关键业务应用和敏感数据免受Web层攻击。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于FortiWeb在处理特殊字符时未能正确过滤和验证输入，已通过身份验证的攻击者可以通过发送精心构造的HTTP请求或CLI命令，将恶意命令注入到系统调用中，从而在FortiWeb设备上执行任意操作系统命令</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">漏洞</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可结合 Fortinet FortiWeb 路径遍历漏洞（CVE-2025-64446）漏洞实现未经身份验证的命令执行。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">状态</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 548px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">等级</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">中</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">7.2</span></span></span></p></td></tr></tbody></table><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></div></div></h1></p></h1><div data-pm-slice="4 4 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7.0.0 &lt;= FortiWeb &lt; 7.0.12</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7.2.0 &lt;= FortiWeb &lt; 7.2.12</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7.4.0 &lt;= FortiWeb &lt; 7.4.11</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7.6.0 &lt;= FortiWeb &lt; 7.6.6</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">8.0.0 &lt;= FortiWeb &lt; 8.0.2</span></span></p></div><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></p></div></div></div></div></div></h1></p></h1><div data-pm-slice="4 4 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. 官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="宋体" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-513" target="_blank">https://fortiguard.fortinet.com/psirt/FG-IR-25-513</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. 临时缓解方案：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 限制对FortiWeb管理界面的访问，仅允许受信任的管理员IP地址访问</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 配置防火墙或网络规则，仅允许特定IP地址或IP段访问FortiWeb管理接口</span></span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">七、</span></span></span></strong><span data-font-family="等线" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.4;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Google Chrome V8 类型混淆漏洞 </span></span></span></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Google Chrome的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：TVD-2025-38173(CVE编号：CVE-2025-13223，CNNVD编号：CNNVD-202511-1851)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Google Chrome是全球使用最广泛的网络浏览器之一，基于开源的Chromium项目开发。V8是Chrome浏览器的核心JavaScript引擎，负责解析和执行网页中的JavaScript代码，为现代Web应用提供高性能的运行环境。V8引擎采用即时编译（JIT）技术，将JavaScript代码转换为机器码以提升执行效率。该引擎不仅应用于Chrome浏览器，还被广泛集成到Node.js、Microsoft Edge等多个平台和产品中，是现代Web技术栈的关键基础设施组件。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Chrome V8 JavaScript引擎在处理JavaScript对象类型时存在类型混淆缺陷。当V8引擎错误地处理对象类型时会导致内存损坏和堆破坏，远程攻击者可通过诱导用户打开精心构造的 HTML 页面触发类型混淆，进而实现远程代码执行。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">状态</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">等级</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">8.6</span></span></span></p></td></tr></tbody></table><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></div></h1></p></div></h1></p></div></h1><div data-pm-slice="4 4 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Google Chrome</span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">(Windows)</span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> &lt; 142.0.7444.175/176</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Google Chrome</span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">(Linux)</span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> &lt; 142.0.7444.175</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Google Chrome(Mac) &lt; 142.0.7444.176</span></span></p></div><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></p></div></div></div></div></h1></p></div></h1></p></div></h1><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. 官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="宋体" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html" target="_blank">https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html</a></span></span></span></p></span><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">八、</span></span></span></strong><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Fortinet FortiWeb 路径遍历漏洞</span></span></span></b></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Fortinet FortiWeb的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-38003</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-64446</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202511-1746</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可创建未授权的管理员账户并完全控制设备。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于FortiWeb的通用网关接口组件中存在相对路径遍历缺陷</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">未经身份验证的远程攻击者可以通过发送精心构造的请求绕过访问控制</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">创建未授权的管理员账户，从而完全控制FortiWeb设备</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">状态</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">等级</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">9.8</span></span></span></p></td></tr></tbody></table><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></div></h1></p></div></h1></p></div></h1><div data-pm-slice="4 4 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7.0.0 &lt;= FortiWeb &lt; 7.0.12</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7.2.0 &lt;= FortiWeb &lt; 7.2.12</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7.4.0 &lt;= FortiWeb &lt; 7.4.10</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7.6.0 &lt;= FortiWeb &lt; 7.6.5</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">8.0.0 &lt;= FortiWeb &lt; 8.0.2</span></span></p></div><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></p></div></div></div></div></h1></p></div></h1></p></div></h1><div data-pm-slice="4 4 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. 官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-910" target="_blank">https://fortiguard.fortinet.com/psirt/FG-IR-25-910</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. 临时缓解方案：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 限制对FortiWeb管理界面的访问，仅允许受信任的管理员IP地址访问</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 配置防火墙或网络规则，仅允许特定IP地址或IP段访问FortiWeb管理接口</span></span></span></p></div><div data-pm-slice="5 5 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">九、</span></span></span></strong><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Open WebUI 远程代码执行漏洞</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Open WebUI的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-37170</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-64496</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202511-854</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可窃取身份验证令牌实现账户接管，并可能在后端服务器上执行远程代码。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Open WebUI是一个基于Python开发的开源Web用户界面框架，专为大型语言模型（LLM）和AI应用设计。该框架提供了直观的聊天界面和模型管理功能，支持用户与多种AI模型进行交互。Open WebUI的直接连接（Direct Connections）功能允许用户添加外部模型服务器的URL，直接与第三方AI模型建立连接，而无需通过中间代理。该功能使用服务器发送事件（Server-Sent Events，SSE）协议实现实时通信，使浏览器能够接收来自服务器的持续数据流。Open WebUI被广泛应用于AI研究、开发和生产环境中，为用户提供灵活的模型访问和管理能力。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Open WebUI的直接连接功能中存在代码注入缺陷</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">当用户启用直接连接功能并添加恶意外部模型服务器URL时，攻击者可以通过服务器发送事件（SSE）的execute事件发送恶意JavaScript代码，</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在受害者浏览器中执行任意命令，窃取认证令牌并完全接管账户</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">；</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">若结合 Functions API 漏洞可进一步实现后端服务器远程代码执行。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞状态</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">状态</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20.25pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 20.25pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></b></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 677px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border: 1pt solid windowtext;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: rgb(68, 114, 196);height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><b style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: white;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">等级</span></span></b></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.65pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 18.3pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">中</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top: none;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;border-image: initial;max-width: 100%;background: white;height: 16.4pt;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;">8</span></span></span></p></td></tr></tbody></table><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></h1></p></div></h1></p></div></h1><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(34, 34, 34);letter-spacing: 0.4pt;vertical-align: baseline;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Open WebUI &lt; 0.6.35</span></span></p><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></p></div></div></div></h1></p></div></h1></p></div></h1><div data-pm-slice="4 4 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 500;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="宋体" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/open-webui/open-webui/releases" target="_blank">https://github.com/open-webui/open-webui/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 如非必需，禁用直接连接（Direct Connections）功能</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;text-align: justify;"><span data-font-family="等线" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 严格验证外部模型URL，仅添加来自可信来源的模型服务器</span></span></span></p></div></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;font-family: 等线;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-style: italic;">*</span><span textstyle="" style="font-size: 15px;font-style: italic;">以上</span></span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;font-family: 宋体;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;font-style: italic;">漏洞评分为腾讯云安全研究人员根据漏洞情况作出，仅供参考，具体漏洞细节请以原厂商或是相关漏洞平台公示为准。</span></span></span></p><div hm_fix="385:564" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 0.544px;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px 0em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">END</span></strong></p></div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 0.544px;color: rgb(163, 163, 163);font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 5px 1em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 24px 8px 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-indent: 0em;font-variant-numeric: normal;font-variant-east-asian: normal;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关注云鼎实验室，获取更多安全情报</span></span></p></div></div><p><span leaf=""><img data-w="900" alt="图片" class="rich_pages wxw-img" data-ratio="0.6" src="https://wechat2rss.xlab.app/img-proxy/?k=dee947fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D41"/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485126">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0c4e32db&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485126%26idx%3D1%26sn%3D9725c8d9c998e8d681b2254469fa44d1">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 12 Dec 2025 10:17:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年10月企业必修安全漏洞清单</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485122&amp;idx=1&amp;sn=9629a1d89e3ed5b977dbd806305e38e1</link>
      <description>腾讯云安全公布近期安全漏洞清单,建议自查更新,防入侵保业务安全!</description>
      <content:encoded><![CDATA[<p>
<span>云鼎实验室</span> <span>2025-11-14 19:03</span> <span style="display: inline-block;">广东</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=deb596c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FNNSr7XSrt0l1bZia8sPRMSdwHDSISm1koFPb4WFUeTaLEIS8WNqWHYBEMbgVqu08dw3iaP9hVic1XSsmM7OUfh4TA%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>腾讯云安全公布近期安全漏洞清单,建议自查更新,防入侵保业务安全!</p>

<h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div><div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding: 27px;outline: 0px;display: inline-block;width: 663.458px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(78, 132, 216);visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-size: 15px;visibility: visible;"><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重的后果。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">腾讯云安全参考“安全漏洞的危害及影响力、漏洞技术细节披露情况、该漏洞在安全技术社区的讨论热度”等因素，综合评估该漏洞在攻防实战场景的风险。当漏洞综合评估为风险严重、影响面较广、技术细节已披露，且被安全社区高度关注时，就将该漏洞列入必修安全漏洞候选清单。 </span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">腾讯云安全定期发布安全漏洞必修清单，以此指引企业安全运维人员修复漏洞，从而避免重大损失。 </span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(3, 97, 243);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">以下是2025年10月份必修安全漏洞清单</span></span></strong></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">：</span></span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">一、</span></span><strong style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Redis</span></span><b data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">远程</span></span></b></strong></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">代码执行漏洞 </span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">(</span></span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-49844</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">二</span></span></span></strong><strong style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">、</span></span><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Oracle E-Business Suite 远程代码执行漏洞 </span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">(</span></span><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-61882)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">三、</span></span><b data-pm-slice="0 0 []" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Oracle E-Business Suite </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">未授权访问漏洞（</span></span><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-61884）</span></span></span></b></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">四、</span></span></span></strong><b style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">FlowiseAI Flowise </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">任意文件写入远程命令执行漏洞（</span></span><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-61913）</span></span></span></b></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">五、</span></span><b data-pm-slice="0 0 []"><span lang="EN-US" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Windows Server Update Service </span></span></span><span style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">远程代码执行漏洞（</span></span><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-59287）</span></span></span></span></b></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">六、</span></span></span></strong><b style="white-space: normal;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Apache Tomcat </span></span></span><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">远程代码执行漏洞（</span></span><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-55752）</span></span></span></b></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">七、</span></span></span><span style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">Cherry studio</span></span></span><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">命令注入漏洞（</span></span><span lang="EN-US" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-61929）</span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">八、</span></span><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">JumpServer </span></span><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">权限管理错误漏</span></span><span leaf="" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">洞（</span></span><span lang="EN-US" style="user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;clear: both;min-height: 1em;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;font-weight: normal;">CVE-2025-62712）</span></span></span></span></p></div><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 15px;text-align: justify;color: rgb(3, 97, 243);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞介绍及修复建议详见后文</span></strong></span></p></div></div></div></div></div></div><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;" data-pm-slice="8 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;rich_media_title &#34;,&#34;id&#34;:&#34;activity-name&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px 0px 14px; padding: 0px; outline: 0px; font-weight: 500; font-size: 22px; line-height: 1.4; user-select: text; color: rgba(0, 0, 0, 0.9); font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: 0.544px; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 27.75pt;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">一、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Redis</span></span><b data-pm-slice="0 0 []" style="line-height: 1.4;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;clear: both;min-height: 1em;font-weight: bold;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 18px;letter-spacing: 0.544px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px;visibility: visible;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="other" data-w="30" style="-webkit-tap-highlight-color: transparent;margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 25px !important;visibility: visible !important;height: auto !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=ae9f7fd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D0"/></p><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Redis</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-32375(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-49844</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202510-401)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可实现远程代码执行。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Redis</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个开源的内存数据结构存储系统，它可以用作数据库、缓存和消息中间件。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Redis</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持多种数据结构，如字符串、哈希表、列表、集合等，并提供丰富的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">操作这些数据结构。它采用单线程模型处理请求，通过异步</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">I/O</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和多路复用技术实现高性能。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Redis</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">还支持持久化、事务、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Lua</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">脚本执行等高级功能，广泛应用于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Web</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用、实时分析、消息队列等场景。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Lua</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">脚本功能允许用户在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Redis</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器端执行自定义逻辑，提高了操作的原子性和性能。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Redis Lua</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">脚本执行环境中存在释放后重用漏洞，具有已认证的用户权限的攻击者可以通过特制的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Lua</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">脚本操作垃圾回收器，触发内存管理缺陷，最终可能实现远程代码执行。</span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.9</span></span></span></p></td></tr></tbody></table></div></h1></p></div></div></h1><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="other" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012799" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div></div></div></h1><p style="text-align: justify;margin: 0px 0pt 0pt;"><span style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="等线"><span leaf="">Redis </span></span><span style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="等线"><span leaf="">&lt;</span></span><span style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="等线"><span leaf="">6.2.20</span></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">7.0.0 &lt;= Redis &lt; 7.2.11</span></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">7.4.0 &lt;= Redis &lt; 7.4.6</span></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">8.0.0 &lt;= Redis &lt; 8.0.4</span></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">8.2.0 &lt;= Redis &lt; 8.2.2</span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 20px;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div></div></div></div></div></h1><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. 官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/redis/redis/releases/tag" target="_blank">https://github.com/redis/redis/releases/tag</a></span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">/</span></span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. 临时缓解方案：</span></span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 通过ACL（访问控制列表）限制EVAL和EVALSHA命令的执行权限，禁止用户运行Lua脚本；</span></span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 限制对Redis实例的访问权限，仅允许受信任的用户和应用访问。</span></span></span></p></div></div></h1><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">二、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);"> Oracle E-Business Suite </span></span><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;visibility: visible;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="other" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-imgfileid="100012797" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">近期监测到关于Oracle E-Business Suite的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-32376</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-61882，CNNVD编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202510-745</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意代码</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Oracle E-Business Suite是Oracle公司开发的一套全面的企业资源规划(ERP)应用程序套件，旨在帮助企业管理和自动化各种业务流程。该套件包括财务管理、供应链管理、人力资源管理、项目管理等多个模块，为企业提供集成的业务解决方案。Oracle Concurrent Processing是E-Business Suite的一个关键组件，负责管理和执行并发请求，如报表生成、批处理任务等，确保系统资源的有效利用和任务的及时完成</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Oracle Concurrent Processing的BI Publisher集成组件中存在认证绕过缺陷，攻击者可以通过特制的HTTP请求绕过安全机制，获取对Oracle Concurrent Processing的完全控制权限</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级</span></b></p><table style="width:548px;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></p></td></tr></tbody></table></div></h1></p></div></h1></p></div></div></div></h1><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;margin-top: 0px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="other" data-w="234" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012803" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);margin-top: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div></div></div></h1><p style="font-weight: 500;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;padding: 0px;outline: 0px;max-width: 100%;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;text-align: justify;margin: 0pt;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">12.2.3 &lt;= Oracle E-Business Suite &lt;= 12.2.14</span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 20px;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012795" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div></div></div></div></div></h1><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://www.oracle.com/security-alerts/alert-cve-2025-61882.html" target="_blank">https://www.oracle.com/security-alerts/alert-cve-2025-61882.html</a></span></span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">限制对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Oracle E-Business Suite</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的网络访问，仅允许必要的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址和用户访问。</span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">三、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Oracle E-Business Suite </span></span><b data-pm-slice="0 0 []" style="line-height: 1.4;user-select: text;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;visibility: visible;text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">未授权访问漏洞</span></span></b></strong></p></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="other" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-imgfileid="100012800" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Oracle E-Business Suite</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-33661(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-61884</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202510-2334)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可未经授权访问受限页面及敏感数据。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，在</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Oracle E-Business Suite </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Oracle Configurator </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">产品中存在未授权访问漏洞，未经身份验证的远程攻击者可通过</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> HTTP </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">协议访问</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Oracle Configurator</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">进行利用，从而导致对关键数据的未经授权访问或对所有</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Oracle Configurator</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可访问数据的完全访问。</span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">7.5</span></span></span></p></td></tr></tbody></table></div></h1></p></div></div></h1></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="other" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012803" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div><p><span lang="EN-US"><span leaf="" style="font-weight: 500;line-height: 1.4;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;visibility: visible;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;color: rgb(51, 51, 51);box-sizing: border-box !important;overflow-wrap: break-word !important;">12.2.3 &lt;= Oracle E-Business Suite &lt;= 12.2.14</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012802" data-ratio="1" data-s="300,640" data-type="other" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 21px;visibility: visible !important;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;" data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://www.oracle.com/security-alerts/alert-cve-2025-61884.html" target="_blank">https://www.oracle.com/security-alerts/alert-cve-2025-61884.html</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><span lang="EN-US" style="font-weight: 500;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span style="font-weight: 500;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">限制对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Oracle E-Business Suite</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的网络访问，仅允许必要的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址和用户访问。</span></span></span></div></div></div></h1></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">四、</span></span></span></strong><b><span lang="EN-US"><span leaf="" style="clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">FlowiseAI Flowise </span></span></span><span leaf="" style="clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">任意文件写入远程命令执行漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="other" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-imgfileid="100012807" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Flowise</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-32379(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-61913</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202510-1108)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可读取和写入任意文件，可能导致远程命令执行。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Flowise</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个拖放式用户界面工具，用于构建定制的大型语言模型</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(LLM)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">工作流。它提供了一个可视化的开发环境，使用户能够轻松创建、设计和部署复杂的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用程序，而无需编写大量代码。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Flowise</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持多种</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">提供商和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">集成，提供丰富的预构建组件和模板，使用户能够快速构建从简单的聊天机器人到复杂的业务自动化流程等各种</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用。该工具特别适合数据科学家、开发人员和业务分析师使用，降低</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用开发的技术门槛。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Flowise</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">中的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">WriteFileTool</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ReadFileTool</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">组件未限制文件路径访问，允许已认证的攻击者通过这些工具访问文件系统中的任意路径。攻击者可以利用此漏洞读取敏感文件、写入恶意文件，可能实现远程命令执行。</span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="4 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.9</span></span></span></p></td></tr></tbody></table></div></div></h1><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="other" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012818" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><p data-brushtype="text" style="align-items: center;justify-content: flex-start;margin-left: 4px;display: inline-block;-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;">影响版本</span></strong></p></div></div></div></div></div></h1></div><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">Flowise &lt; 3.0.8</span></span><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012805" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p data-role="paragraph" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;" data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/FlowiseAI/Flowise/releases/tag/" target="_blank">https://github.com/FlowiseAI/Flowise/releases/tag/</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">限制对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Flowise</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用程序的网络访问，仅允许受信任的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址访问；</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">实施严格的身份验证和授权机制，限制文件操作权限。</span></span></p></div></div></h1></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><code style="-webkit-tap-highlight-color: transparent;outline: 0px;"></code></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">五、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Windows Server Update Service </span></span><b data-pm-slice="0 0 []" style="line-height: 1.4;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="other" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-imgfileid="100012816" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server Update Service</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-34143(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-59287</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202510-1791)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可通过网络执行任意代码，获取系统控制权限。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server Update Services(WSUS)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是微软提供的服务器角色，用于管理微软产品在企业网络中的更新分发。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">WSUS</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">允许管理员集中控制和分发</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">更新、驱动程序和其他微软软件的更新到网络中的计算机。它提供了一个可扩展的更新管理解决方案，使企业能够有效管理更新部署，减少安全风险，并确保所有系统保持最新状态。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">WSUS</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">集成了</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Active Directory</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和组策略，允许根据计算机和组织单位进行精确的更新部署。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server Update Service</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">中存在不受信任数据的反序列化缺陷，攻击者可以通过特制的序列化数据触发该漏洞，最终远程执行任意代码，获得系统的完全控制权限。</span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;" data-pm-slice="4 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已发现</span></span></span></p></td></tr></tbody></table></div></div></h1><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"></table><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="color: rgb(255, 255, 255);">类别</span></span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="color: rgb(255, 255, 255);">等级</span></span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span></p></td></tr></tbody></table><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="other" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012818" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></div></div></div></h1><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">Windows Server 2012 &lt; 6.2.9200.25728</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">Windows Server 2012 R2 &lt; 6.3.9600.22826</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">Windows Server 2016 &lt; 10.0.14393.8524</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">Windows Server 2019 &lt; 10.0.17763.7922</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">Windows Server 2022 &lt; 10.0.20348.4297</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">Windows Server 2022 23H2 &lt; 10.0.25398.1916</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">Windows Server 2025 &lt; 10.0.26100.6905</span></span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 20px;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012819" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></p></div></div></div></div></div></div></h1><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287" target="_blank">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287</a></span></span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><span lang="EN-US" style="font-weight: 500;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: black;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span style="font-weight: 500;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: black;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">限制对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">WSUS</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器的网络访问，仅允许受信任的客户端和服务器连接。</span></span></span></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">六、</span></span></span></strong><b><span lang="EN-US"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Apache Tomcat </span></span></span><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="other" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-imgfileid="100012822" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache Tomcat</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-55752</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202510-3510)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可绕过安全约束访问受限制的资源，如果同时启用了</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PUT</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求可能导致远程代码执行。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache Tomcat</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个开源的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Web</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Servlet</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">容器，由</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">软件基金会开发和维护。它实现了</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Java Servlet</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JavaServer Pages(JSP)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Java Expression Language</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Java WebSocket</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等技术规范，为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Java Web</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用程序提供运行环境。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Tomcat</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">广泛用于各种规模的企业和应用，从小型个人项目到大型企业级应用。它以其轻量级、高性能、稳定性和可扩展性而闻名，支持多种操作系统和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Java</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本，是</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Java</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">生态系统中最流行的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Web</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器之一。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Apache Tomcat</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">中在修复</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">bug 60013</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">时引入了回归缺陷：重写</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">URL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">时在解码前进行了规范化处理，导致无法识别目录遍历序列</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> (%2e%2e </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，攻击者可通过操纵请求</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">URI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">绕过</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">/WEB-INF/</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">/META-INF/</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等安全约束保护。如果同时启用了</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PUT</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求，则攻击者可上传恶意文件实现远程代码执行，从而完全控制服务器。</span></span></p><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">7.5</span></span></span></p></td></tr></tbody></table><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="other" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012818" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></div></div></div></h1></p></div></h1><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">8.5.6 &lt;= Apache Tomcat &lt;= 8.5.100 (EOL</span></span></span><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">版本</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">9.0.0.M11 &lt;= Apache Tomcat &lt;= 9.0.108</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">10.1.0-M1 &lt;= Apache Tomcat &lt;= 10.1.44</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">11.0.0-M1 &lt;= Apache Tomcat &lt;= 11.0.10</span></span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 20px;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012819" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></p></div></div></div></div></div></div></h1></p></div></h1><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://tomcat.apache.org/" target="_blank">https://tomcat.apache.org/</a></span></span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">禁用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PUT</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求。</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">七、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="line-height: 1.4;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Cherry studio</span></span><span leaf="" style="line-height: 1.4;user-select: text;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">命令注入漏洞</span></span></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="other" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-imgfileid="100012826" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Cherry Studio</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-33523(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-61929</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202510-1408)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可通过用户交互执行任意命令，获取系统控制权限。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Cherry Studio</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个桌面客户端应用程序，支持多种大型语言模型</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">(LLM)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">提供商。它为用户提供了一个统一的界面，用于访问和管理不同</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，如</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">OpenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Anthropic</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Google</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等。该应用程序允许用户通过直观的界面与各种</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">模型交互，保存对话历史，管理</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">密钥，并配置不同的模型参数。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Cherry Studio</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">采用现代桌面应用框架开发，支持</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">macOS</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">和</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Linux</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等主流操作系统，为</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">开发者和爱好者提供了一个便捷的工具来探索和使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">技术。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，由于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Cherry Studio</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">自定义的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> URL </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">协议处理器（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">cherrystudio://</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">）对</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> MCP </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">安装请求缺乏安全验证，当接收到 “</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">cherrystudio://mcp</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">” 类型的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> URL </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">时会调用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">handleMcpProtocolUrl </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">函数进行处理，而该函数未对用户提供的命令内容进行安全校验，远程攻击者可通过构造包含恶意命令的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Base64</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">编码值并直接拼接至</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">URL</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">协议处理器中，当受害者点击该恶意链接时即可触发远程任意代码的执行。</span></span></p><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align: center;"><span style="color: black;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align: center;"><span lang="EN-US" style="color: black;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span></p></td></tr></tbody></table><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="other" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012818" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></div></h1></p></div></h1></p></div></h1><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">Cherry Studio &lt;1.6.6</span></span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 20px;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012819" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></p></div></div></div></div></h1></p></div></h1></p></div></h1><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/CherryHQ/cherry-studio/releases" target="_blank">https://github.com/CherryHQ/cherry-studio/releases</a></span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">避免点击来自不受信任来源的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">&#34;cherrystudio://&#34;</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">链接。</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">八、</span></span></span></strong><b><span lang="EN-US"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">JumpServer </span></span></span><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">权限管理错误漏洞</span></span></b></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="other" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-imgfileid="100012832" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JumpServer</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">漏洞编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-36115(CVE</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-62712</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202510-4209)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可未授权访问敏感系统和权限提升。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JumpServer</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">是一个开源的堡垒主机和运维安全审计系统，专为企业和云环境设计。它提供了一个统一的入口点，用于管理和监控对各种</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IT</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">资源的访问，包括服务器、数据库、网络设备和应用程序。</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JumpServer</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">支持多种认证方式，集成了权限管理、会话管理、审计日志等功能，帮助企业实施最小权限原则并满足合规要求。该系统采用现代化的微服务架构，支持高可用部署，适用于各种规模的组织，特别是那些需要严格控制访问权限和确保运维安全的企业。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">JumpServer</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">API</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">接口</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">/api/v1/authentication/super-connection-token/</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">存在访问控制缺陷，该接口返回由所有用户创建的连接令牌而不是请求者令牌，攻击者可以通过获取的令牌对令牌所有者的受管资产发起连接，从而导致敏感系统的未经授权访问和权限提升。</span></span></p><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012815" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级</span></b></p><table><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.6</span></span></span></p></td></tr></tbody></table><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="other" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012818" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></p></div></div></div></div></h1></p></div></h1></p></div></h1><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">JumpServer &lt; 3.10.20-lts</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;font-size: 10.5pt;font-family: 等线;color: rgb(34, 34, 34);letter-spacing: 0.4pt;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-weight: normal;">4.0.0 &lt;= JumpServer &lt; 4.10.11-lts</span></span></span></p><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-role="outer" label="Powered by 135editor.com" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><h1 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 14px;padding: 0px;outline: 0px;font-weight: 500;font-size: 22px;line-height: 1.4;user-select: text;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="other" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 20px;visibility: visible !important;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" data-imgfileid="100012819" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></p></div></div></div></div></h1></p></div></h1></p></div></h1><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/jumpserver/jumpserver/releases" target="_blank">https://github.com/jumpserver/jumpserver/releases</a></span></span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></p><p style="font-weight: 500;user-select: text;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 0px 0px 16px;padding: 0px;max-width: 100%;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">实施严格的访问控制，仅允许受信任的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址访问。</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 等线;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-style: italic;">*</span><span textstyle="" style="font-size: 15px;font-style: italic;">以上</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 宋体;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 15px;font-style: italic;">漏洞评分为腾讯云安全研究人员根据漏洞情况作出，仅供参考，具体漏洞细节请以原厂商或是相关漏洞平台公示为准。</span></span></span></p><div hm_fix="385:564" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 32px;"><img alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="0.8768115942028986" data-type="gif" data-w="276" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: block;width: 32px !important;visibility: visible !important;height: auto !important;" data-width="100%" data-imgfileid="100012836" src="https://wechat2rss.xlab.app/img-proxy/?k=816b6918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FFIBZec7ucChYUNicUaqntiamEgZ1ZJYzLRasq5S6zvgt10NKsVZhejol3iakHl3ItlFWYc8ZAkDa2lzDc5SHxmqjw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 2px 0em;outline: 0px;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">END</span></strong></p></div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;color: rgb(163, 163, 163);text-align: center;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;outline: 0px;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 5px 1em;outline: 0px;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;text-indent: 0em;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="">关注云鼎实验室，获取更多安全情报</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;min-height: 1em;color: rgb(163, 163, 163);letter-spacing: 0.54px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><img alt="图片" class="rich_pages wxw-img" data-ratio="0.6" data-s="300,640" data-type="other" data-w="900" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.54px;width: 370px;visibility: visible !important;height: auto !important;" data-copyright="0" data-imgfileid="100012835" src="https://wechat2rss.xlab.app/img-proxy/?k=8264a853&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p></div></div></div></h1><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485122">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a0a73f9f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485122%26idx%3D1%26sn%3D9629a1d89e3ed5b977dbd806305e38e1">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 14 Nov 2025 19:03:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年9月企业必修安全漏洞清单</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485090&amp;idx=1&amp;sn=e32957c82555e74c010cc5b7439e268c</link>
      <description>所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重</description>
      <content:encoded><![CDATA[<p>
<span>腾讯云安全</span> <span>2025-10-24 09:56</span> <span style="display: inline-block;">广东</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1785ccbd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FNNSr7XSrt0lq5OEK3LXfY78Hc8jicn15nhCmmAYFAbibWoiawumypFfo8eXm8z8d1xZOwjrsbVtom3SOZpmY53ogw%2F0%3Fwx_fmt%3Djpeg"/></p>


<div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div><div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding: 27px;outline: 0px;display: inline-block;width: 663.458px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(78, 132, 216);visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-size: 15px;visibility: visible;"><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重的后果。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf=""><span textstyle="" style="letter-spacing: normal;">腾讯云安全参考“安全漏洞的危害及影响力、漏洞技术细节披露情况、该漏洞在安全技术社区的讨论热度”等因素，综合评估该漏洞在攻防实战场景的风险。当漏洞综合评估为风险严重、影响面较广、技术细节已披露，且被安全社区高度关注时，就将该漏洞列入必修安全漏洞候选清单。 </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">腾讯云安全定期发布安全漏洞必修清单，以此指引企业安全运维人员修复漏洞，从而避免重大损失。 </span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(3, 97, 243);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">以下是2025年9月份必修安全漏洞清单</span></span></strong></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">：</span></span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">一、</span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, \&#34;system-ui\&#34;, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">h2o-3 JDBC 反序列化漏洞</span></span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">(</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;data-font-family&#34;:&#34;等线&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">CVE-2025-6507</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">二、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">MCP inspector 远程命令执行漏洞</span></span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">(</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;data-font-family&#34;:&#34;等线&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">CVE-2025-58444</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">三、</span></span><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin-left: 27.75pt; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); text-align: center; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">Spring Cloud Gateway Server WebFlux 存在表达式注入漏洞</span></span></span></strong></span></strong><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">（</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;data-font-family&#34;:&#34;等线&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">CVE-2025-41243</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">) </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">四、</span></span></span></strong><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">Da</span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;letter-spacing: 0.544px;line-height: 1.75em;visibility: visible;clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">ta</span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;letter-spacing: 0.544px;line-height: 1.75em;visibility: visible;clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;" data-font-family="等线"><span leaf="" style="visibility: visible;clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">E</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;letter-spacing: 0.544px;line-height: 1.75em;visibility: visible;clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;" data-font-family="等线"><span leaf="" style="visibility: visible;clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">ase Impala 远程代码执行漏洞 </span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;letter-spacing: 0.544px;line-height: 1.75em;visibility: visible;clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span leaf="" style="visibility: visible;clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">(CVE-2025-58046)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">五、</span></span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">Chrome V8 引擎类型混淆漏洞</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">(</span><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">CVE-2025-10585</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">六、</span></span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">Flowise reset-password 任意用户密码重置漏洞</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">(</span><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">CVE-2025-58434</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;visibility: visible;line-height: 1.75em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 0, 0);font-weight: normal;">七、</span></span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">pRES</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">T</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;" data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;"> SQL注入漏洞</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;justify-content: flex-start;flex-flow: row;vertical-align: top;align-self: flex-start;flex: 0 0 auto;color: rgb(51, 51, 51);letter-spacing: 0.544px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-weight: bold;font-size: 14px;visibility: visible;"><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: normal;">(CVE-2025-58450)</span></span></span></p></div><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 15px;text-align: justify;color: rgb(3, 97, 243);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞介绍及修复建议详见后文</span></strong></span></p></div></div></div></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">一、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">h2o-3 JDBC 反序列化漏洞</span></span></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;visibility: visible;"><img data-imgfileid="100012797" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于h2o-3的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-28652</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE-2025-6507</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">,</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202509-079</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">h2o-3是H2O.ai开发的企业级开源机器学习平台，采用Java/Scala编写底层核心，通过分布式内存计算框架实现高性能数据处理。作为领先的AI开发平台，它集成了20多种机器学习算法，并通过REST API提供多语言支持。平台采用分布式键值存储架构，可横向扩展至数百节点，支持AutoML自动模型选择和超参优化。其特色功能包括：基于Flow技术的交互式Web IDE、MOJO格式的模型部署方案、实时预测服务和批量评分能力，以及完善的Kubernetes/YARN/Mesos调度器集成。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">h2o-3</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">正则表达式过滤器</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">存在</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">缺陷</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，攻击者可以</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">根据</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">MySQL JDBC</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">特性</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">构造</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">特制</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">恶意</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">绕过</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">检测</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">触发</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">J</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">D</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">B</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">C</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">反序列化</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">读取</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">敏感</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">文件</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">或</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><p data-pm-slice="0 0 []"><b><span leaf=""><img data-imgfileid="100012796" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="31" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p style=""><b><span leaf=""><img data-imgfileid="100012796" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="31" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:17.55pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span></p></td></tr></tbody></table><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012799" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div></div><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">h</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">2</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">o</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">-</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">3</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">&lt;</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">3.46.0.8</span></span></p><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012795" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"><a href="https://github.com/h2oai/h2o-3/tags" target="_blank">https://github.com/h2oai/h2o-3/tags</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 配置防火墙或网络规则，仅允许特定IP地址或IP段访问</span></span></span></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">二、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">MCP inspector 远程命令执行漏洞</span></span></span></strong></p></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012800" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">近期监测到关于MCP</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">inspector的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-29623</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-58444</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202509-1046</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">MCP Inspector是用于测试和调试MCP（Model Context Protocol）服务器的开发人员工具，采用模块化架构设计，支持远程MCP服务器连接和调试。它提供直观的界面用于监控和分析MCP协议通信，广泛应用于AI模型开发和调试场景。工具通过代理机制处理MCP服务器通信，支持多种调试功能，包括请求重放、协议分析和性能监控</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于MCP Inspector本地开发工具中的跨站脚本问题，当连接到具有恶意重定向URI的不受信任远程MCP服务器时，攻击者可以利用此漏洞与检查器代理直接交互以触发任意命令执行。</span></span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-imgfileid="100012804" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;mso-bidi-font-size:10.5pt;color:white;mso-themecolor:
  background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">类别</span></span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;mso-bidi-font-size:10.5pt;color:white;mso-themecolor:
  background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">状态</span></span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-imgfileid="100012804" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">8.6</span></span></span></p></td></tr></tbody></table><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012803" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">MCP-inspector</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">&lt; 0.16.6</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012802" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/modelcontextprotocol/inspector/releases" target="_blank">https://github.com/modelcontextprotocol/inspector/releases</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="DengXian"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. 临时缓解方案</span></span></span><span data-font-family="DengXian"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">：</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">仅连接可信MCP服务器</span></span></span></p></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">三、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">Spring Cloud Gateway Server WebFlux 存在表达式注入漏洞</span></span></span></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012807" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">近期监测到关于Spring Cloud Gateway Server Webflux的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-29686</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-41243</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">,</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202509-2486</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">读取</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">环境</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">敏感</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">信息</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">修改</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">系统</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">属性</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Spring Cloud Gateway WebFlux是Spring生态中的响应式API网关组件，基于Project Reactor和Spring WebFlux构建，采用非阻塞异步IO模型处理HTTP请求。它提供动态路由、负载均衡、熔断限流等核心网关功能，支持通过函数式API定义路由规则，并内置过滤器链机制实现请求/响应修改。作为云原生架构的关键组件，它专为微服务场景设计，能与Spring Cloud服务发现无缝集成，适用于高并发、低延迟的API网关需求</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该漏洞源于</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">WebFlux组件对SpEL表达式的安全校验机制存在缺陷</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">当应用使用Spring Cloud Gateway Server WebFlux组件（WebMVC版本不受影响）、包含Spring Boot Actuator依赖项、通过management.endpoints.web.exposure.include=gateway启用网关端点</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">且</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Actuator端点处于可访问且未受保护状态条件时，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">攻击者可构造恶意SpEL表达式，通过Actuator端点注入并执行，进而修改restrictive-property-accessor等系统属性，读取环境变量中的数据库密码、API密钥等敏感信息。</span></span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-imgfileid="100012808" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-imgfileid="100012808" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.6pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">10</span></span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012818" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">3</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">1</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">0</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">&lt;= </span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">Spring Cloud Gateway &lt;=</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">3</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">1</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">1</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">1</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">4</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">0</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">0</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">&lt;</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">=</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">Spring Cloud Gateway</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">&lt;=</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">4</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">1</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">1</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">1</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">4.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">1</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.0 &lt;= </span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">Spring Cloud Gateway &lt;= 4.1.11</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">4</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">2</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">0</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">&lt;= </span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">Spring Cloud Gateway &lt;=</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">4</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">2</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">5</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">4</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">3</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">0</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">&lt;</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">=</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">Spring Cloud Gateway</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">&lt;</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">=</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">4</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">3</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">.</span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">1</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">P</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">S </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">: </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">4</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">0</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">x</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">已</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">停止</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">支持</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);font-style: italic;">其他已停止支持的旧版本同样存在风险</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012805" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://spring.io/security/cve-2025-41243" target="_blank">https://spring.io/security/cve-2025-41243</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">从management.endpoints.web.exposure.include属性中移除gateway配置</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">通过身份验证和访问控制机制保护Actuator端点</span></span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">四、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Data</span></span></span></strong><span data-font-family="等线"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">E</span></span></span><span data-font-family="等线"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">ase Impala 远程代码执行漏洞</span></span></span></p></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012810" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">近期监测到关于Data</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">E</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ase的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-30505</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-58046</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202509-2030</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可远程执行任意代码。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">DataEase 是一款开源数据可视化分析工具，它致力于帮助用户快速连接并整合多种数据源，通过直观的拖拉拽操作方式制作丰富多样的图表，从而高效分析数据、洞察业务趋势，辅助业务决策与优化。其开源特性和强大的功能（如集成Apache Doris实现超大数据量下的秒级响应、提供丰富的业务模板市场以及支持PC、移动和大屏等多种展示终端），使得无论是数据分析师、业务人员还是开发者都能低门槛上手，实现高效的数据可视化分析与协作分享</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Data</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">E</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ase中</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">io.dataease.datasource.type.Impala类的getJdbc方法过滤不足</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">攻击者可以构造恶意JDBC连接字符串，利用JNDI注入并触发RMI反序列化，最终实现远程命令执行。</span></span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-imgfileid="100012811" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-imgfileid="100012811" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012818" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;background:undefined;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">DataEase &lt;</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;background:undefined;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;background:undefined;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf=""> 2.10.12</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012813" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/dataease/dataease/releases" target="_blank">https://github.com/dataease/dataease/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">缓解</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">方案</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">避免开放</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">至</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">公网</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- 利用安全组设置仅对可信地址开放</span></span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">五、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Chrome V8 引擎类型混淆漏洞</span></span></span></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012816" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">近期监测到关于Google Chrome的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-30946</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-10585</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202509-3171</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">造成</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">内存</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">损坏</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可能</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">导致</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码执行</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Google Chrome是基于Chromium的开源网页浏览器，采用多进程架构和V8 JavaScript引擎，支持现代Web标准和高性能渲染。它是全球使用最广泛的浏览器，提供丰富的扩展生态系统和安全沙箱机制。浏览器通过V8引擎执行JavaScript代码，支持WebAssembly等先进技术</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。V8不仅驱动Chrome的脚本执行，也被Node.js等运行时环境采用，具有内存管理优化、并行垃圾回收等特性，是现代Web性能的关键基础。 </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Google Chrome</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">V8</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">引擎</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">中</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">存在</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">类型混淆问题，攻击者可构造</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">恶意</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTML页面</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">并</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">诱导</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">受害者</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">访问</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">触发</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">内存损坏，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配合</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">其他</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">漏洞</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可能</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">导致</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码执行。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><b><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><img data-imgfileid="100012815" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></strong></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align: center;margin-top: 0px;"><b><span style="color: white;"><span leaf=""><span textstyle="" style="font-size: 16px;">类别</span></span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">状态</span></span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已发现</span></span></span></p></td></tr></tbody></table><p style="margin-bottom: 24px;"><b><span leaf=""><img data-imgfileid="100012817" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">评定方式</span></span></span></b></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">等级</span></span></span></b></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012818" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;background:undefined;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">Google Chrome &lt; 140.0.7339.185</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; outline: 0px; font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255); font-size: 16px; border-width: 0px; border-style: none; border-color: initial; margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012819" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html" target="_blank">https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html</a></span></span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">六、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Flowise reset-password 任意用户密码重置漏洞</span></span></span></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012822" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">近期监测到关于Flowise的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-30365</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">（</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-58434</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">,</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202509-1796</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">重置</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">用户</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">密码</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">获取</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">管理员</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">权限</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Flowise是拖放式用户界面工具，用于构建定制化大语言模型流程，采用可视化工作流设计，支持LLM集成和自定义节点。它提供直观的图形界面连接不同AI模型和服务，广泛应用于自动化流程和AI应用开发。平台通过模块化架构实现灵活扩展，支持REST API和WebSocket通信，能够快速构建复杂的AI工作流。Flowise既可作为云服务使用，也支持自托管部署，为开发者提供便捷的LLM集成方案</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Flowise的密码重置端点存在安全缺陷，攻击者可以通过未经验证的forgot-password端点获取有效的密码重置令牌，无需认证即可为任意用户生成重置令牌并直接重置其密码，最终导致完整的账户接管风险。此漏洞同时影响云端服务和自托管部署。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf=""><img data-imgfileid="100012824" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></strong></p><table><tbody><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: transparent;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-width: 1pt;border-color: windowtext;background: rgb(68, 114, 196);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 11pt;color: white;letter-spacing: 0.4pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">类别</span></span></span></strong></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: transparent;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top-width: 1pt;border-top-color: windowtext;border-right-width: 1pt;border-right-color: windowtext;border-bottom-width: 1pt;border-bottom-color: windowtext;border-left: none;background: rgb(68, 114, 196);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;word-break: break-all;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 11pt;color: white;letter-spacing: 0.4pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">状态</span></span></span></strong></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px 0px 24px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important; clear: both; min-height: 1em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><img data-imgfileid="100012820" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">风险等级：</span></span></strong><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br/></span></strong></p><table><tbody><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: transparent;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-width: 1pt;border-color: windowtext;background: rgb(68, 114, 196);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 11.5pt;color: white;letter-spacing: 0.4pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">评定方式</span></span></span></strong></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: transparent;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top-width: 1pt;border-top-color: windowtext;border-right-width: 1pt;border-right-color: windowtext;border-bottom-width: 1pt;border-bottom-color: windowtext;border-left: none;background: rgb(68, 114, 196);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;word-break: break-all;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 11.5pt;color: white;letter-spacing: 0.4pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">等级</span></span></span></strong></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012823" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="margin-bottom: 24px;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;paragraph text-align-type-justify&#34;,&#34;style&#34;:&#34;text-align:justify; margin-top:0pt; margin-bottom:0pt; margin-left:0pt; margin-right:0pt;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:10.5pt; font-family:等线; font-weight:normal; font-style:normal; color:#000000; background:undefined; letter-spacing:0pt; mso-font-width:100%; vertical-align:baseline;&#34;,&#34;data-font-family&#34;:&#34;等线&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Flowise &lt;= 3.0.5</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012821" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;" data-pm-slice="3 3 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外</span></span></span><span data-font-family="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/FlowiseAI/Flowise/releases" target="_blank">https://github.com/FlowiseAI/Flowise/releases</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.临时缓解方案：</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定IP地址或IP段访问</span></span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">七、</span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">pREST</span></span></span></strong><span data-font-family="等线"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);"> SQL注入漏洞</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012826" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">近期监测到关于pREST的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-29617</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-58450</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">,</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202509-1044</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">）</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，最终可</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">获取数据库权限，从而盗取用户数据，造成用户信息泄露</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">pREST是在PostgreSQL数据库之上提供API的应用程序，采用RESTful架构设计，支持快速构建数据库驱动的Web服务。它提供自动化的CRUD端点生成，支持JWT认证和细粒度权限控制，广泛应用于微服务和数据API开发。平台通过中间件处理请求转换和SQL生成，能够将数据库表直接暴露为REST资源，同时保持高性能和低延迟。pREST特别适合需要快速构建数据库API的场景，支持PostgreSQL特有的功能和数据类型。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: left;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于pREST</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">对SQL查询参数的过滤存在缺陷，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">未</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">能</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">对用户输入进行充分的类型检查和转义处理</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">攻击者可以通过特制的HTTP请求注入恶意SQL语句</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，从而盗取用户数据，造成用户信息泄露。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf=""><img data-imgfileid="100012828" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></strong></p><table><tbody><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: transparent;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-width: 1pt;border-color: windowtext;background: rgb(68, 114, 196);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 11pt;color: white;letter-spacing: 0.4pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">类别</span></span></span></strong></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: transparent;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top-width: 1pt;border-top-color: windowtext;border-right-width: 1pt;border-right-color: windowtext;border-bottom-width: 1pt;border-bottom-color: windowtext;border-left: none;background: rgb(68, 114, 196);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;word-break: break-all;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 11pt;color: white;letter-spacing: 0.4pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">状态</span></span></span></strong></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;"><img data-imgfileid="100012825" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;font-weight: bold;">风险等级：</span></span></p><table><tbody><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: transparent;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-width: 1pt;border-color: windowtext;background: rgb(68, 114, 196);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 11.5pt;color: white;letter-spacing: 0.4pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">评定方式</span></span></span></strong></p></td><td data-colwidth="274" width="274" valign="top" style="-webkit-tap-highlight-color: transparent;padding: 0cm 5.4pt;outline: 0px;word-break: break-all;hyphens: auto;border-top-width: 1pt;border-top-color: windowtext;border-right-width: 1pt;border-right-color: windowtext;border-bottom-width: 1pt;border-bottom-color: windowtext;border-left: none;background: rgb(68, 114, 196);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;word-break: break-all;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 11.5pt;color: white;letter-spacing: 0.4pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">等级</span></span></span></strong></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;outline: 0px;height: 16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.3</span></span></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012827" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;" data-pm-slice="3 3 []"><span data-font-family="等线"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">pREST</span></span><span data-font-family="等线"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">&lt;</span></span><span data-font-family="等线"><span leaf="" style="font-size: 10.5pt;font-family: 等线;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">2.0.0-rc3</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012829" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;" data-pm-slice="3 3 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/prest/prest/releases" target="_blank">https://github.com/prest/prest/releases</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定IP地址或IP段访问</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 等线;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-style: italic;">*</span><span textstyle="" style="font-size: 15px;font-style: italic;">以上</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 宋体;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 15px;font-style: italic;">漏洞评分为腾讯云安全研究人员根据漏洞情况作出，仅供参考，具体漏洞细节请以原厂商或是相关漏洞平台公示为准。</span></span></span></p><div hm_fix="385:564" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 32px;"><img data-imgfileid="100012836" alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="0.8768115942028986" data-type="gif" data-w="276" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: block;width: 32px !important;visibility: visible !important;" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=816b6918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FFIBZec7ucChYUNicUaqntiamEgZ1ZJYzLRasq5S6zvgt10NKsVZhejol3iakHl3ItlFWYc8ZAkDa2lzDc5SHxmqjw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 2px 0em;outline: 0px;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">END</span></strong></p></div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;color: rgb(163, 163, 163);text-align: center;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div data-role="paragraph" data-color="#1e9be8" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div data-id="86318" data-tools="135编辑器" data-color="#3d8ed1" data-custom="#3d8ed1" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;outline: 0px;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 5px 1em;outline: 0px;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;text-indent: 0em;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="">关注云鼎实验室，获取更多安全情报</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;min-height: 1em;color: rgb(163, 163, 163);letter-spacing: 0.54px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><img data-imgfileid="100012835" alt="图片" class="rich_pages wxw-img" data-ratio="0.6" data-s="300,640" data-type="jpeg" data-w="900" style="-webkit-tap-highlight-color:transparent;outline:0px;letter-spacing:0.54px;width:393px;visibility:visible !important;height:236px;" data-copyright="0" src="https://wechat2rss.xlab.app/img-proxy/?k=8264a853&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485090">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a1fdbb72&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485090%26idx%3D1%26sn%3De32957c82555e74c010cc5b7439e268c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Oct 2025 09:56:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年8月企业必修安全漏洞清单</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485088&amp;idx=1&amp;sn=726d198b93728d5b4637883929f3d6db</link>
      <description>所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重</description>
      <content:encoded><![CDATA[<p>
<span>腾讯云安全</span> <span>2025-09-17 18:02</span> <span style="display: inline-block;">广东</span>
</p>




<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=e2e1fa34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FNNSr7XSrt0kbRd1HHQVVvTkNVGgb9NFic90Y2xfriamAXe4fFbd0ia89lq30ibjwUHbuabHmc6HXKKACfCtJVu1mPA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div><div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding: 27px;outline: 0px;display: inline-block;width: 663.458px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(78, 132, 216);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-size: 15px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 13px;visibility: visible;"></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-size: 15px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 13px;visibility: visible;"></span></p><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重的后果。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf=""><span textstyle="" style="letter-spacing: normal;">腾讯云安全参考“安全漏洞的危害及影响力、漏洞技术细节披露情况、该漏洞在安全技术社区的讨论热度”等因素，综合评估该漏洞在攻防实战场景的风险。当漏洞综合评估为风险严重、影响面较广、技术细节已披露，且被安全社区高度关注时，就将该漏洞列入必修安全漏洞候选清单。 </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">腾讯云安全定期发布安全漏洞必修清单，以此指引企业安全运维人员修复漏洞，从而避免重大损失。 </span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(3, 97, 243);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">以下是2025年8月份必修安全漏洞清单</span></span></strong></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span></p></div><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;" data-pm-slice="6 4 []"><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">一、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">Cursor</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">远程代码执行漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-54135</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span><span lang="EN-US"><o:p></o:p></span></b></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">二、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">1Panel</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">远程命令注入漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-54424</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span><span lang="EN-US"><o:p></o:p></span></b></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">三、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">Stirling-PDF </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">服务端请求伪造漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-55150</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span><span lang="EN-US"><o:p></o:p></span></b></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">四、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">DataEase JNDI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">注入漏洞</span></span></b><b><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-57773</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span><span lang="EN-US"><o:p></o:p></span></b></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">五、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">FlowiseAI Flowise </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">远程代码执行漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-8943</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span><span lang="EN-US"><o:p></o:p></span></b></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">六、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">HTTP/2 MadeYouReset </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">拒绝服务漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-8671</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span><span lang="EN-US"><o:p></o:p></span></b></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">七、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">Microsoft Windows </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">文件资源管理器欺骗漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-50154</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span><span lang="EN-US"><o:p></o:p></span></b></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">八、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CrushFTP AS2 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">身份认证绕过漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-54309</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span><span lang="EN-US"><o:p></o:p></span></b></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">九、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">Docker Desktop Engine API </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">未授权访问漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-9074</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span><span lang="EN-US"><o:p></o:p></span></b></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">十、</span></span></span></b><b><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">Cherry Studio </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">命令注入漏洞（</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">CVE-2025-54074</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;font-weight: normal;">）</span></span></b></p></div></div><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 15px;text-align: justify;color: rgb(3, 97, 243);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞介绍及修复建议详见后文</span></strong></span></p></div></div></div></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">一、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Cursor</span></span><span leaf="" style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">远程代码执行漏洞</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"></o:p></span></strong></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;visibility: visible;"><img data-imgfileid="100012797" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Cursor的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-25245</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-54135</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202508-284</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可通过特制的输入绕过安全限制，在受影响的系统上执行任意操作系统命令。 </span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Cursor是一款基于Visual Studio Code的现代化代码编辑器，由Cursor团队开发，专为AI辅助编程设计。它深度集成了GPT-4等大型语言模型，提供智能代码补全、错误检测和自动重构功能。支持50+种编程语言，具有实时协作和云端同步能力，被全球数百万开发者使用。其扩展市场包含上千个插件，可满足各种开发需求。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据官方描述，在Cursor AI代码编辑器中，由于未限制敏感文件的创建权限，导致攻击者可通过间接提示注入在用户工作区静默创建恶意 MCP 配置文件（如.cursor/mcp.json），从而绕过审批机制。</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">并且</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">当在该文件中定义恶意MCP服务器配置时，由于Cursor Agent以开发者权限运行且自动执行新配置，从而可触发无感远程任意代码的执行</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span><span lang="EN-US"><o:p></o:p></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-imgfileid="100012796" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="31" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b><span lang="EN-US"><o:p></o:p></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-imgfileid="100012796" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="31" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b><span lang="EN-US"><o:p></o:p></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:17.55pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">8.6</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012799" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">Cursor &lt; 1.3</span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span lang="EN-US"><o:p></o:p></span></p><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012795" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://cursor.com/en/home" target="_blank">https://cursor.com/en/home</a></span></span><o:p></o:p></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">关闭</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Cursor</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Auto-Run Mode</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">设置</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">仅连接可信的</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">MCP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器</span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">二、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">1Panel远程命令注入漏洞</span></span></span></strong></p></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012800" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于1Panel的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-25075</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-54424</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202508-111</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可绕过证书验证机制，最终在受影响的系统上执行任意命令。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1Panel是由1Panel团队开发的开源服务器管理面板，采用Go语言编写。它集成了Docker、Kubernetes、MySQL、PostgreSQL等主流服务的管理功能，支持一键部署应用、SSL证书管理和性能监控。作为轻量级替代方案，它比传统面板如cPanel/Plesk更高效，特别适合云服务器环境，全球超过50万服务器使用。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该漏洞</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">源于</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1Panel</span></span></span><span style="white-space:pre-wrap;font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Agent端 TLS认证策略为tls.RequireAnyClientCert，仅要求提供证书但不验证其可信性</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">攻击者可通过自签名证书绕过TLS校验，并伪造CN字段为panel_client绕过应用层校验进行未授权命令执行接口调用，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">命令</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-imgfileid="100012804" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b><span lang="EN-US"><o:p></o:p></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><p style=""><b><span leaf=""><img data-imgfileid="100012804" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b><span lang="EN-US"><o:p></o:p></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012803" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1Panel &lt; 2.0.6</span></span></span></p><p><span lang="EN-US"><o:p></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012802" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/1Panel-dev/1Panel/releases" target="_blank">https://github.com/1Panel-dev/1Panel/releases</a></span></span><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">限制管理面板的访问，只允许来自可信</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址的连接</span></span><span lang="EN-US"><o:p></o:p></span></p></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">三、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">Stirling-PDF </span></span></span><span leaf="" style="clear: both;min-height: 1em;font-weight: bold;color: rgb(34, 34, 34);-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">服务端请求伪造漏洞</span></span></strong><span lang="EN-US"><o:p></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012807" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Stirling-PDF的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-25908</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-55150</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202508-971</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可通过构造特定的HTTP请求实现服务器端请求伪造，访问内部网络资源。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Stirling-PDF 是一款功能全面、基于 Docker 并支持本地托管的开源 PDF 处理工具，它提供了超过 50 种 PDF 操作功能，包括页面编辑、格式转换、安全管理以及 OCR 文字识别等，所有处理均在用户本地环境完成，确保了数据的绝对隐私和安全。其开源特性允许开发者自由定制和扩展，而多语言支持和企业级功能使其既能满足个人用户的日常文档处理需求，也适用于中小企业、开发团队及对数据安全有严格要求的组织场景</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该漏洞源于</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Stirling-PDF</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTML转PDF功能中的清理器</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">存在</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">缺陷</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">攻击者可以</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">通过</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">发送</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">特制的</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">绕过安全过滤机制，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">利用该漏洞进行远程服务器请求伪造、内网资源访问等操作。</span></span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-imgfileid="100012808" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b><span lang="EN-US"><o:p></o:p></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-imgfileid="100012808" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b><span lang="EN-US"><o:p></o:p></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.6pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.6pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">8.6</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012806" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;">Stirling-PDF &lt; 1.1.0</span></span></p><p><span lang="EN-US"><o:p></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012805" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:10.5pt;font-weight:normal;font-style:normal;color:#0563C1;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:10.5pt;font-weight:normal;font-style:normal;text-decoration:underline;color:#0563C1;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;&#34;,&#34;data-font-family&#34;:&#34;default&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;text-decoration: none;"><a href="https://github.com/Stirling-Tools/Stirling-PDF/releases" target="_blank">https://github.com/Stirling-Tools/Stirling-PDF/releases</a></span></span></span><o:p></o:p></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">限制</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">PDF</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">转换服务的网络访问权限</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">四、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">DataEase JNDI</span></span><b data-pm-slice="0 0 []" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">注入漏洞</span></span></b><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></strong></p></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012810" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于DataEase的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-27483</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-57773</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202508-2933</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可通过反序列化攻击在受影响的系统上写入任意文件，可能导致代码执行。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">DataEase 是一款开源数据可视化分析工具，它致力于帮助用户快速连接并整合多种数据源，通过直观的拖拉拽操作方式制作丰富多样的图表，从而高效分析数据、洞察业务趋势，辅助业务决策与优化。其开源特性和强大的功能（如集成Apache Doris实现超大数据量下的秒级响应、提供丰富的业务模板市场以及支持PC、移动和大屏等多种展示终端），使得无论是数据分析师、业务人员还是开发者都能低门槛上手，实现高效的数据可视化分析与协作分享</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于DataEase中DB2参数过滤不足，攻击者可以</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">通过</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">发送</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">特制</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">J</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">I</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">触发</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">反序列化</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">通过AspectJWeaver组件在系统上写入任意文件</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，可能导致代码执行</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p data-pm-slice="0 0 []"><b><span leaf=""><img data-imgfileid="100012811" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">漏洞状态：</span></b><span lang="EN-US"><o:p></o:p></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><p><b><span leaf=""><img data-imgfileid="100012811" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf="">风险等级：</span></b><span lang="EN-US"><o:p></o:p></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012806" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">DataEase &lt; 2.10.12</span></span><o:p></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012805" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;text-align: justify;margin: 0pt;" data-pm-slice="0 0 []"><span data-font-family="宋体"><span leaf="" style="font-size: 10.5pt;font-weight: normal;font-style: normal;color: rgb(5, 99, 193);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;text-decoration: none;"><a href="https://github.com/dataease/dataease/releases" target="_blank">https://github.com/dataease/dataease/releases</a></span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;text-align: justify;margin: 0pt;" data-pm-slice="0 0 []"><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案： </span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">利用安全组设置仅对可信地址开放</span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">五、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">FlowiseAI Flowise 远程代码执行漏洞</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012816" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Flowise</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-26486</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-8943</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202508-1511</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可在未经身份验证的情况下执行操作系统命令，实现远程代码执行。 </span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Flowise 是一款开源的低代码/无代码可视化工具，它基于 LangChain.js 构建，允许用户通过简单的拖放组件方式快速构建和部署自定义的大型语言模型应用程序，如聊天机器人、智能客服、文档问答系统等。其核心优势在于大幅降低了AI应用开发的门槛，即使非技术用户也能通过直观的界面设计复杂的工作流，无需编写代码。Flowise 提供了丰富的预置组件库，支持集成多种主流LLM、向量数据库，以及外部API工具，并具备实时测试、版本控制和多部署选项（如Docker、云平台）等功能。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Flowise的自定义MCP功能设计缺陷，该功能允许执行操作系统命令来启动本地MCP服务器。由于Flowise</span></span></span><span style="white-space:pre-wrap;font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">3.0.1之前的</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">版本</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">默认安装不启用身份验证，且缺乏基于角色的访问控制，未经身份验证的网络攻击者可以</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">利用</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">漏洞</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行未沙箱化的操作系统命令。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><img data-imgfileid="100012815" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></strong></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">类别</span></span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">状态</span></span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><span leaf=""><img data-imgfileid="100012817" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;font-weight: bold;">风险等级：</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">评定方式</span></span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">等级</span></span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012818" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Flowise &lt; 3.0.1</span></span><o:p></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012819" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;text-align: justify;margin: 0pt;" data-pm-slice="0 0 []"><span data-font-family="宋体"><span leaf="" style="font-size: 10.5pt;font-weight: normal;font-style: normal;color: rgb(5, 99, 193);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;text-decoration: none;"><a href="https://github.com/FlowiseAI/Flowise/releases" target="_blank">https://github.com/FlowiseAI/Flowise/releases</a></span></span></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;text-decoration:underline;color:#0563C1;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-decoration:underline;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;color: rgb(5, 99, 193);"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">六、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">HTTP/2 MadeYouReset 拒绝服务漏洞</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012822" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于HTTP/2的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-26283</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-8671</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202508-1338</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可通过触发服务器端流重置导致资源耗尽，最终实现拒绝服务攻击。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTTP/2是互联网工程任务组（IETF）在2015年标准化的协议（RFC 7540），作为HTTP/1.1的替代方案，它被Nginx、Apache、Cloudflare等主流Web服务广泛采用，全球约75%的网站支持HTTP/2。该协议通过二进制分帧、头部压缩（HPACK算法）和服务器推送等核心特性，显著提升了Web性能，解决了HTTP/1.1的队头阻塞和低效问题。</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">H</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">TTP/2的多路复用（Multiplexing）特性允许在单个TCP连接上并行传输多个请求和响应，避免了传统浏览器为突破连接限制而创建多个TCP连接的开销，从而降低了延迟并提高了连接利用率。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞是由于HTTP/2 协议规范与服务器实现之间的不匹配导致的，当攻击者发送恶意 RST_STREAM 控制帧重置数据流时，协议层会立即释放流资源并停止计数，但服务器后台仍继续处理这些 &#34;已终止&#34; 的请求，这种状态同步失效导致单个连接即可突破 SETTINGS_MAX_CONCURRENT_STREAMS 限制，从而导致服务器资源被大量 &#34;僵尸请求&#34; 耗尽，最终引发服务瘫痪。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><b><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><img data-imgfileid="100012824" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></strong></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align: center;margin-top: 0px;"><b><span style="color: white;"><span leaf=""><span textstyle="" style="font-size: 16px;">类别</span></span></span></b><span lang="EN-US" style="color: white;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">状态</span></span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><span leaf=""><img data-imgfileid="100012820" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;font-weight: bold;">风险等级：</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">评定方式</span></span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">等级</span></span></span></b><span lang="EN-US" style="color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">中</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">中</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">7.5</span></span></span><span lang="EN-US"><o:p></o:p></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012823" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">使用</span></span><span lang="EN-US" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTTP/2</span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">协议的组件</span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012821" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></strong></p></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请评估业务是否受</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> HTTP/2 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">协议影响后，酌情升级</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> Apache Tomcat</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Netty</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">H2O</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Varnish Cache </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">等使用</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> HTTP/2 </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">协议的组件至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">七、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">Microsoft Windows 文件资源管理器欺骗</span></span></span></strong><span data-font-family="等线"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="letter-spacing: normal;color: rgb(0, 82, 255);">漏洞</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012826" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Windows文件资源管理器的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-26165</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-50154</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202508-1163</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可在未经授权的情况下访问敏感信息，实现网络欺骗攻击。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows是由Microsoft开发的一系列图形用户界面操作系统，它从基于MS-DOS的图形环境起步，逐步发展成为全球个人计算机领域应用最广泛的操作系统。Windows以其直观的图形用户界面、强大的多任务处理能力、广泛的硬件兼容性和丰富的软件生态系统而著称，广泛应用于个人电脑、服务器、嵌入式设备等多种平台。</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows文件资源管理器(explorer.exe)是Windows Shell的核心组件，自Windows 95以来一直是系统默认文件管理器。它集成了搜索、预览、共享和云存储功能，支持多种文件格式和插件扩展。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该漏洞源于Windows文件资源管理器</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">存在</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">缺陷</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，攻击者可通过构造特殊恶意对象（如恶意的快捷方式）在无任何用户交互的情况下，诱使文件资源管理器自动发起NTLM身份验证请求，从而窃取用户的NTLMv2哈希凭证。获取NTLM哈希后，攻击者可实施离线暴力破解或发起中继攻击，进一步利用这些凭证获取系统未授权访问权限。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><img data-imgfileid="100012828" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></strong></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">类别</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">状态</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">未发现</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><span leaf=""><img data-imgfileid="100012825" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;font-weight: bold;">风险等级：</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">评定方式</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf=""><span textstyle="" style="font-size: 16px;">等级</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">中</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">7.5</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012827" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 for x64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 for 32-bit Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 1607 for x64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 1607 for 32-bit Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 1809 for 32-bit Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 1809 for x64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 21H2 for 32-bit Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 21H2 for x64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 21H2 for ARM64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 22H2 for 32-bit Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 22H2 for ARM64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 10 Version 22H2 for x64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 11 Version 22H2 for x64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 11 Version 22H2 for ARM64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 11 Version 23H2 for x64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 11 Version 23H2 for ARM64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 11 Version 24H2 for x64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows 11 Version 24H2 for ARM64-based Systems</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2008 R2 for x64-based Systems Service Pack 1</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2008 for x64-based Systems Service Pack 2</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2008 for 32-bit Systems Service Pack 2</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2012 (Server Core installation)</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2012</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2012 R2 (Server Core installation)</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2012 R2</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2016 (Server Core installation)</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2016</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2019 (Server Core installation)</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2019</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2022 (Server Core installation)</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2022</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2022, 23H2 Edition (Server Core installation)</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2025</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Windows Server 2025 (Server Core installation)</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.5em;"><span lang="EN-US"><o:p></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012829" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:21px;visibility:visible !important;height:21px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div><p><span lang="EN-US"><o:p></o:p></span></p></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;text-align: justify;margin: 0pt;" data-pm-slice="0 0 []"><span data-font-family="宋体"><span leaf="" style="font-size: 10.5pt;font-weight: normal;font-style: normal;color: rgb(5, 99, 193);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-50154" target="_blank">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-50154</a></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><o:p></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">八、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><span data-font-family="等线"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">CrushFTP AS2 身份认证绕过漏洞</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012832" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于CrushFTP文件传输服务器的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-23557</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-54309</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202507-2381</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可在未经身份验证的情况下获取管理员访问权限，完全控制FTP服务器。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">CrushFTP是一款由CrushFTP LLC开发的企业级跨平台文件传输服务器软件，它支持包括FTP、FTPS、SFTP、HTTP、HTTPS及WebDAV在内的多种协议，并通过SSL/TLS加密、用户认证与目录权限控制等安全特性保障数据传输的安全可靠。其名称“Crush”源于内置的流式ZIP压缩与解压缩技术，可显著提升大文件传输效率，同时提供基于Web的直观管理界面，支持远程监控、实时日志审计和自动化任务调度，适用于企业、教育机构及个人用户的安全文件共享与协作场景。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">在所有平台的CrushFTP中，当系统未启用 DMZ 代理功能时，由于对AS2协议（企业级文件传输协议）的验证处理不当，导致未经身份验证的远程攻击者可通过构造恶意请求直接获取管理员权限。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><img data-imgfileid="100012833" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></strong></strong></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(255, 255, 255);">类别</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(255, 255, 255);">状态</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已发现</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><span leaf=""><img data-imgfileid="100012830" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;font-weight: bold;">风险等级：</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(255, 255, 255);">评定方式</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(255, 255, 255);">等级</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012834" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div><p><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">10.0.0 &lt;= CrushFTP &lt; 10.8.5</span></span><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">11.0.0 &lt;= CrushFTP &lt; 11.3.4_23</span></span><o:p></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012831" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div><p><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;text-align: justify;margin: 0pt;" data-pm-slice="0 0 []"><span data-font-family="宋体"><span leaf="" style="font-size: 10.5pt;font-weight: normal;font-style: normal;color: rgb(5, 99, 193);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;text-decoration: none;"><a href="https://www.crushftp.com/download/" target="_blank">https://www.crushftp.com/download/</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;text-align: justify;margin: 0pt;" data-pm-slice="0 0 []"><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">配置防火墙或网络规则，仅允许特定</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">地址或</span></span><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IP</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">段访问</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">如无必要，避免开放至公网</span></span><span lang="EN-US"><o:p></o:p></span></p><p data-pm-slice="4 5 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">九、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><span data-font-family="等线"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Docker Desktop Engine API 未授权访问漏洞</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012832" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Docker Desktop的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-27405</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-9074</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202508-2370</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可从容器内部访问Docker Engine API，可能导致主机系统被完全控制。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Docker Desktop是Docker官方为开发者在 Windows 和 macOS 系统上提供的桌面应用程序，它集成了 Docker Engine、Docker CLI、Docker Compose 等核心工具与直观的图形界面（GUI），旨在简化容器化应用的开发、测试和部署流程。其支持跨平台运行（Windows 依赖 WSL 2 或 Hyper-V，macOS 原生支持），并提供资源管理、镜像拉取构建、多容器编排、本地 Kubernetes 集成及安全扫描等功能，显著降低了容器技术的使用门槛，确保了开发环境的一致性。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，该漏洞源于Docker Desktop默认配置中未正确隔离容器网络，允许容器内访问Docker Engine API(192.168.65.7:2375)。攻击者可以利用此漏洞执行特权操作，包括控制其他容器、创建新容器、管理镜像，在某些配置下甚至能挂载主机文件系统</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">逃逸容器访问宿主机上的资源等</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(255, 0, 0);">注：该漏洞只影响 Windows/Mac 上的 Docker Desktop，Linux 上的 Docker Desktop 不易受该漏洞影响。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><img data-imgfileid="100012833" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></strong></strong></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">安全补丁</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">漏洞细节</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">PoC</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">在野利用</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">未发现</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><span leaf=""><img data-imgfileid="100012830" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;font-weight: bold;">风险等级：</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">威胁等级</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高危</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">影响面</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">攻击者价值</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">利用难度</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">低</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">漏洞评分</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">9.3</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012834" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div><p><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Docker Desktop &lt; 4.44.3</span></span><o:p></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012831" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div><p><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;text-align: justify;margin: 0pt;" data-pm-slice="0 0 []"><span data-font-family="宋体"><span leaf="" style="font-size: 10.5pt;font-weight: normal;font-style: normal;color: rgb(5, 99, 193);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;text-decoration: none;"><a href="https://docs.docker.com/desktop/release-notes/" target="_blank">https://docs.docker.com/desktop/release-notes/</a></span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;"><span lang="EN-US"><o:p></o:p></span></p><p data-pm-slice="4 3 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">十、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><span data-font-family="等线"><span leaf="" style="font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Cherry Studio 命令注入漏洞</span></span></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012832" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">漏洞概述</span></span></strong></strong></p></div></div></div></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于Cherry Studio的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-26294</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE编号：CVE-2025-54074</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">C</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">N</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">V</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">D</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202508-1375</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，可通过恶意MCP服务器在客户端执行任意命令，完全控制系统。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Cher</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;" data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">ry Studio 是一款开源的跨平台 AI 助手客户端，支持 Windows、macOS 和 Linux 系统，集成了多模型对话、知识库管理</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;" data-font-family="等线"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">、AI 绘画、翻译等全方位功能。它聚合了 OpenAI、Gemini、Anthropic 及硅基流动等主流云服务与本地模型（如 Ollama），允许用户灵活切换和并行调用不同模型，并内置 300 多个预配置 AI 助手覆盖写作、编程、设计等场景，同时支持自定义助手创建和知识库构建，所有数据处理均在本地完成以保障数据隐私与安全。</span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;" data-font-family="等线"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述，</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;" data-font-family="等线"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该漏洞</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;" data-font-family="等线"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">源于应用程序在HTTP Streamable模式下</span></span></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;" data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">与MC</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">P服务器交互时存在的代码缺陷，未能对服务器提供的OAuth元数据进行充分的安全验证和过滤</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">攻击者可</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">搭建</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">恶意MCP服务器</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">并</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">诱导受害者建立连接，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">实现操作系统命令注入</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 0px;"><span leaf=""><img data-imgfileid="100012833" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;font-weight: bold;">漏洞状态：</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">安全补丁</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">漏洞细节</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">PoC</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">在野利用</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">未发现</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><span leaf=""><img data-imgfileid="100012830" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/><span textstyle="" style="font-size: 16px;font-weight: bold;">风险等级：</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">威胁等级</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高危</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">影响面</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">攻击者价值</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">利用难度</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">低</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">漏洞评分</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">7.7</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012834" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">影响版本</span></span></strong></strong></p></div></div></div><p><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.2.5 &lt;= Cherry Studio &lt; 1.5.2</span></span><o:p></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012831" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color:transparent;margin-top:5px;outline:0px;vertical-align:inherit;width:20px;visibility:visible !important;height:20px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="color: rgb(0, 0, 0);">修复建议</span></span></strong></strong></p></div></div></div><p><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;text-align: justify;margin: 0pt;" data-pm-slice="0 0 []"><span data-font-family="宋体"><span leaf="" style="font-size: 10.5pt;font-weight: normal;font-style: normal;color: rgb(5, 99, 193);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;text-decoration: none;"><a href="https://github.com/CherryHQ/cherry-studio/releases/" target="_blank">https://github.com/CherryHQ/cherry-studio/releases/</a></span></span></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;text-align: justify;margin: 0pt;" data-pm-slice="0 0 []"><span data-font-family="等线"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2.</span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">仅连接可信的</span></span><span lang="EN-US"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">MCP</span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">服务器</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span lang="EN-US"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">- </span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">禁用</span></span><span lang="EN-US"><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">HTTP Streamable</span></span></span><span leaf="" style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background: rgb(255, 255, 255);font-size: 16px;line-height: 1.75em;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">模式</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: 等线;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;"></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 等线;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-style: italic;">*</span><span textstyle="" style="font-size: 15px;font-style: italic;">以上</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;font-family: 宋体;color: rgb(51, 51, 51);letter-spacing: 0.4pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 15px;font-style: italic;">漏洞评分为腾讯云安全研究人员根据漏洞情况作出，仅供参考，具体漏洞细节请以原厂商或是相关漏洞平台公示为准。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;vertical-align: inherit;"><b><span lang="EN-US"><o:p></o:p></span></b></p><div hm_fix="385:564" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 32px;"><img data-imgfileid="100012836" alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="0.8768115942028986" data-type="gif" data-w="276" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: block;width: 32px !important;visibility: visible !important;" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=816b6918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FFIBZec7ucChYUNicUaqntiamEgZ1ZJYzLRasq5S6zvgt10NKsVZhejol3iakHl3ItlFWYc8ZAkDa2lzDc5SHxmqjw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 2px 0em;outline: 0px;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">END</span></strong></p></div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;color: rgb(163, 163, 163);text-align: center;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div data-role="paragraph" data-color="#1e9be8" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div data-id="86318" data-tools="135编辑器" data-color="#3d8ed1" data-custom="#3d8ed1" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;outline: 0px;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;padding: 5px 1em;outline: 0px;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;text-indent: 0em;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="">关注云鼎实验室，获取更多安全情报</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;outline: 0px;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;min-height: 1em;color: rgb(163, 163, 163);letter-spacing: 0.54px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><img data-imgfileid="100012835" alt="图片" class="rich_pages wxw-img" data-ratio="0.6" data-s="300,640" data-type="jpeg" data-w="900" style="-webkit-tap-highlight-color:transparent;outline:0px;letter-spacing:0.54px;width:368px;visibility:visible !important;height:221px;" data-copyright="0" src="https://wechat2rss.xlab.app/img-proxy/?k=8264a853&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485088">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e8937d9e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485088%26idx%3D1%26sn%3D726d198b93728d5b4637883929f3d6db">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2025 18:02:00 +0800</pubDate>
    </item>
    <item>
      <title>熵裂·弥合丨腾讯2025上半年漏洞态势报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485086&amp;idx=1&amp;sn=bc3971f9aa5ad6196a727c8fcd5e6dab</link>
      <description>一、总结摘要「熵」——热力学第二定律的混沌量度  ，在物理宇宙中刻画着系统从有序走向无序的必然。当我们将这一</description>
      <content:encoded><![CDATA[<p>
<span>腾讯云安全</span> <span>2025-08-25 17:43</span> <span style="display: inline-block;">广东</span>
</p>

<p>一、总结摘要「熵」——热力学第二定律的混沌量度  ，在物理宇宙中刻画着系统从有序走向无序的必然。当我们将这一</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4f883ecc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FNNSr7XSrt0nW4iafBFRSRFTFo0cVrxlkMpSM6N96NQ0Pkxzg1xZPDO0ZdGJryJf1Y8GshWlSJCdDDLZrupDkGoA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100012989" class="rich_pages wxw-img" data-ratio="0.43203125" data-s="300,640" data-type="png" data-w="1280" style="width:100%;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0nW4iafBFRSRFTFo0cVrxlkMjqqGekSthCDrdrJ8jib3WdXbZodgYQ51jkarUFeYfZyrVoVQ1Szcd8Q/0?wx_fmt=png&amp;from=appmsg" data-cropx2="2617.8562728380025" data-cropy2="1130.543239951279" data-backw="565" data-backh="244" src="https://wechat2rss.xlab.app/img-proxy/?k=e6df2f35&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FNNSr7XSrt0nW4iafBFRSRFTFo0cVrxlkM53j29t6c7d6hHI5kzmniakGa0ze42e5xC0CngCIWkoaxHlBwiaYcd2Pg%2F640%3Fwx_fmt%3Djpeg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;" data-pm-slice="9 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;" data-pm-slice="4 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="161893"><div style="margin: 10px auto;"><div style="margin: 10px auto;display: flex;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><div style="border: 1px solid #0e65d2;padding: 3px;box-sizing:border-box;"><div style="background: linear-gradient(to right,#e2eeff,#ffffff);padding: 5px 10px;box-sizing:border-box;"><div style="display: flex;justify-content: space-between;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><p style="font-size: 16px;color: #135cb7;text-align: left;"><strong data-brushtype="text"><span leaf="">一、总结摘要</span></strong></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.75em -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="3 3 []"><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">「熵」——热力学第二定律的混沌量度  ，在物理宇宙中刻画着系统从有序走向无序的必然。当我们将这一定律投射至数字世界：2025年AI技术的爆炸式迭代，正以惊人的速率加剧着网络安全的「熵增」进程  ——漏洞生态呈现前所未有的无序扩散</span><span leaf="">：</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">1️⃣ </span><strong style="margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;border: 0px;font-style: inherit;font-variant: inherit;font-weight: 600;font-stretch: inherit;font-size: inherit;line-height: inherit;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;font-optical-sizing: inherit;font-size-adjust: inherit;font-kerning: inherit;font-feature-settings: inherit;font-variation-settings: inherit;vertical-align: baseline;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">微观混沌</span></span></strong></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="3 3 []"><span data-font-family="default"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin-right: 8px; margin-left: 8px; outline: 0px; font-size: 15px; line-height: 2em; visibility: visible; font-family: PingFangSC-light; margin-bottom: 8px;&#34;,&#34;data-pm-slice&#34;:&#34;3 3 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;data-font-family&#34;:&#34;default&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">单个AI大模型的参数暴露可能衍生<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">百万级攻击向量。</span></span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2️⃣ </span><strong style="margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;border: 0px;font-style: inherit;font-variant: inherit;font-weight: 600;font-stretch: inherit;font-size: inherit;line-height: inherit;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;font-optical-sizing: inherit;font-size-adjust: inherit;font-kerning: inherit;font-feature-settings: inherit;font-variation-settings: inherit;vertical-align: baseline;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">宏观失控</span></span></strong></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin-right: 8px; margin-left: 8px; outline: 0px; font-size: 15px; line-height: 2em; visibility: visible; font-family: PingFangSC-light; margin-bottom: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;data-font-family&#34;:&#34;default&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">从CVE体系崩塌到地缘黑客战争，漏洞管理机制全球范围面临挑战。</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3️⃣ </span><strong style="margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;border: 0px;font-style: inherit;font-variant: inherit;font-weight: 600;font-stretch: inherit;font-size: inherit;line-height: inherit;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;font-optical-sizing: inherit;font-size-adjust: inherit;font-kerning: inherit;font-feature-settings: inherit;font-variation-settings: inherit;vertical-align: baseline;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">防御</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;border: 0px;font-style: inherit;font-variant: inherit;font-weight: 600;font-stretch: inherit;font-size: inherit;line-height: inherit;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;font-optical-sizing: inherit;font-size-adjust: inherit;font-kerning: inherit;font-feature-settings: inherit;font-variation-settings: inherit;vertical-align: baseline;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin-right: 8px; margin-left: 8px; outline: 0px; font-size: 15px; line-height: 2em; visibility: visible; font-family: PingFangSC-light; margin-bottom: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;data-font-family&#34;:&#34;default&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">悖论</span></span></span></strong></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin-right: 8px; margin-left: 8px; outline: 0px; font-size: 15px; line-height: 2em; visibility: visible; font-family: PingFangSC-light; margin-bottom: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;data-font-family&#34;:&#34;default&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">安全团队如同逆熵而行的麦克斯韦妖，在算法生成的攻击风暴中徒手重建秩序。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">此刻，「熵」已不仅是物理学概念，更是丈量数字世界脆弱性的标尺。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-right: 8px;margin-left: 8px;outline: 0px;font-size: 15px;line-height: 2em;font-family: PingFangSC-light;margin-bottom: 16px;"><strong><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> 关键发现 </span></span></strong><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.75em -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">AI</span></span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">组件成新靶点</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">  ：</span>大模型支撑框架漏洞占比达高危漏洞的 15%，相比去年下半年，出现了较大幅度增长，说明AI组件的漏洞引发了行业漏洞研究者的关注；</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.75em -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">新捕获零日漏洞激增</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">  ：</span>腾讯云捕获在野0day攻击 285 起，较 2024H2 增长 148%，这些漏洞主要集中在一些国产应用框架或系统，这说明的很多企业缺乏有效的安全投入和暴露面管理能力，当真实0day攻击来临时，实际处于裸奔状态。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.75em -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">只有</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">极少数</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">漏洞</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">需</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">企业</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">立即</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">响应</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">  ：</span></span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">上半年</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">腾讯</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">共</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">累计</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">捕获</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">2</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">0</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">W</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">+</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">漏洞</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">情报</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">，腾讯漏洞库（TVD）新增25931个漏洞，</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">经过</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">分析</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">+</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">人工</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">研判</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">，</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">结合</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">企业</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">真实</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">业务</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">组件</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">使用</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">场景</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">，</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">真正</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">需要</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">企业</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">立即</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">响应</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">的</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">漏洞</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">实际</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">不到</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">2</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">%</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.75em -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">攻击响应窗口收紧</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">  ：</span></span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">上半年</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">高关注度</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">/</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">高危</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">漏洞</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">进行</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">持续</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">追踪</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">分析</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">，</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">我们</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">发现</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">20%广泛使用的组件</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">高危</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">漏洞</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">会在</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">披露24小时内出现利用</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">，</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">这</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">意味着</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">留给</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">企业</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">发现</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">和</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">响应</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">时间</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">之际</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">不到</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">1</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">天</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">，</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">企业</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">需</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">维度</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">完备</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">的</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">资产</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">组件</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">库</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">，</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">并</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">完成</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">漏洞</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">情报</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">覆盖</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">，</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">同时</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">需</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">进一步</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">提升</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">情报</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">监测</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">到</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">风险</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">修复</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">的</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">响应</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">效率</span></span><span data-font-family="default"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">。</span></span></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="161893"><div style="margin: 10px auto;"><div style="margin: 10px auto;display: flex;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><div style="border: 1px solid #0e65d2;padding: 3px;box-sizing:border-box;"><div style="background: linear-gradient(to right,#e2eeff,#ffffff);padding: 5px 10px;box-sizing:border-box;"><div style="display: flex;justify-content: space-between;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><p style="font-size: 16px;color: #135cb7;text-align: left;"><strong data-brushtype="text"><span leaf="">二、2025 CVE危机深度解析：企业漏洞管理指南热点事件回顾</span></strong></p></div></div></div></div></div></div></div></div><p><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></div><h3 style="-webkit-tap-highlight-color: transparent;margin-right: 8px;margin-left: 8px;outline: 0px;font-size: 15px;line-height: 2em;font-family: PingFangSC-light;margin-bottom: 16px;"><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 18px;"> </span><span textstyle="" style="font-size: 16px;">热点事件回顾</span><span textstyle="" style="font-size: 18px;"> </span></span></span><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></h3><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">2025</span></span><span data-font-family="default"><span leaf="">上半年</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">是</span></span><span data-font-family="default"><span leaf="">对网络安全领域而言是动荡不安的</span></span><span data-font-family="default"><span leaf="">。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">1月，DeepSeek 的 ClickHouse 内部数据库对外暴露</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">，</span>允许攻击者对数据库进行完全控制，此次暴露包含超过一百万行的日志流，其中含有聊天记录、密钥、后端细节以及其他高度敏感的信息。DeepSeek 随后迅速采取了措施，修复了该</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">2月，</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Lazarus集团加密货币盗窃，从Bybit窃取15亿美元加密货币</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">，</span>利用Safe{Wallet}漏洞，资金转换为比特币并分布到多个区块链地址。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">3月，</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Oracle Cloud  被漏洞攻击导致600万记录泄漏</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">，</span>影响14万租户，黑客可能利用了CVE-2021-35587 漏洞（Oracle Fusion Middleware 访问管理组件漏洞）绕过身份验证，入侵了Oracle Cloud 服务器，泄露了600万记录，影响14万租户。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">4月，</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">CVE程序的联邦合同到期未续签</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">，</span>系统几乎崩溃，MITRE警告潜在网络安全中断</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">尽管最终合同获得了为期11个月的延长，但该事件</span></span><span data-font-family="default"><span leaf="">引发了行业对CVE系统未来运营的担忧。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">5 月，</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">关键行业的供应链上游持续成为攻击目标</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">，</span></span></span><span data-font-family="default"><span leaf="">日本大型半导体及化工材料制造商力森诺科于5月20日遭受了严重的勒索软件攻击，攻击导致公司及集团部分内部部分系统无法使用，业务运营受到显著影响。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">6月，</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Anthropic公司Model Context Protocol（MCP，模型上下文协议）框架核心调试工具MCP Inspector</span></span></span><span data-font-family="default"><span leaf="">被</span></span><span data-font-family="default"><span leaf="">曝</span></span><span data-font-family="default"><span leaf="">存在高危远程代码执行（Remote Code Execution，RCE）漏洞</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">编号</span></span><span data-font-family="default"><span leaf="">CVE-2025-49596</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">当受害者访问特制的恶意网站时，攻击者可通过浏览器向本地 MCP 服务器发送恶意请求，触发任意代码执行，进而窃取数据、植入后门或在内网中横向移动</span></span><span data-font-family="default"><span leaf="">。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">CVE 项目的停摆风波的背后，给企业安全漏洞管理带来哪些启发？作为普通企业，应该如何提前布局，防范CVE项目停摆对漏洞管理带来的影响？ </span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">爆发的趋势下，对</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">安全漏洞管理会带来怎样的冲击？企业又该如何做好应对呢？</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">本次报告，我们将就</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">2025</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">年</span></span><span data-font-family="default"><span leaf="">上半年</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">漏洞态势以及上述安全问题进行总结分析，提供漏洞管理视角的思考与实践建议。</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;" data-pm-slice="4 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="161893"><div style="margin: 10px auto;"><div style="margin: 10px auto;display: flex;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><div style="border: 1px solid #0e65d2;padding: 3px;box-sizing:border-box;"><div style="background: linear-gradient(to right,#e2eeff,#ffffff);padding: 5px 10px;box-sizing:border-box;"><div style="display: flex;justify-content: space-between;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><p style="font-size: 16px;color: #135cb7;text-align: left;"><strong data-brushtype="text"><span leaf="">三、漏洞态势全景：以数据观漏洞发展态势</span></strong></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div><h3 style="-webkit-tap-highlight-color: transparent;margin-right: 8px;margin-left: 8px;outline: 0px;font-size: 15px;line-height: 2em;font-family: PingFangSC-light;margin-bottom: 16px;"><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> 2025 上半年漏洞态势分析 </span></span></span><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h3><p style="margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-imgfileid="100012993" class="rich_pages wxw-img" data-ratio="0.17954378219278883" data-s="300,640" data-type="png" data-w="2718" style="margin-left:0px;margin-top:0px;width:100%;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mv9vewGOD4PCzqEvZ6j1A6e0t3B3aVZZMzuMic0eHMeiaOe03a50UmUl4B8c0w3qdibEwLXJhOz4E2w/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="562" data-cropsely2="101" data-backw="562" data-backh="101" src="https://wechat2rss.xlab.app/img-proxy/?k=2f61dafc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mv9vewGOD4PCzqEvZ6j1A6e0t3B3aVZZMzuMic0eHMeiaOe03a50UmUl4B8c0w3qdibEwLXJhOz4E2w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">上半年</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">腾讯</span></span><span data-font-family="default"><span leaf="">云</span></span><span data-font-family="default"><span leaf="">：</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">累计共捕获漏洞情报</span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);"> </span><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">205,769 </span></span></span><span data-font-family="default"><span leaf="">条，经过AI算法和人工判断，识别关键高危情报漏洞 </span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">628</span></span></span><span data-font-family="default"><span leaf=""> 个；</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="">累积收录</span></span><span style="white-space:pre-wrap;font-size:11pt;font-weight:bold;font-style:normal;text-decoration:underline;color:#FF0000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">25</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">,931 </span></span></span><span data-font-family="default"><span leaf="">个漏洞到腾讯漏洞库（TVD），</span></span><span data-font-family="default"><span leaf="">其中</span></span><span data-font-family="default"><span leaf="">高危、严重漏洞数量为 <span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">10</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">,</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">528</span> 个，占总量的</span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="font-weight: bold;"> </span><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">40.60%</span>。</span></span></p></li></ul><h4 style="-webkit-tap-highlight-color: transparent;margin-right: 8px;margin-left: 8px;outline: 0px;font-size: 15px;line-height: 2em;font-family: PingFangSC-light;margin-bottom: 16px;"><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> 漏洞整体</span></span></span><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">统计</span></span></span><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">情报 </span></span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="text-align:justify;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:3pt;margin-right:0pt;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">与NVD CVE官方漏洞库的数量对比</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">，</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">无</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">CVE</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">编号</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">漏洞</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">占比</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">达</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">5</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">%</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">，</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">这些</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">漏洞</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">以</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">国产</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">软件</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">为主</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-font-family="default"><span leaf="">。</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img data-imgfileid="100012994" class="rich_pages wxw-img" data-ratio="0.6896551724137931" data-s="300,640" data-type="png" data-w="580" style="margin-left:0px;margin-top:0px;width:100%;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mv9vewGOD4PCzqEvZ6j1A6oaxfVicfia4vJC7dmCtrrX5ic2Abtn8ER2yVwTcSMkpwf4dxY6Hnlrrzg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="385" data-backw="558" data-backh="385" src="https://wechat2rss.xlab.app/img-proxy/?k=c80462df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mv9vewGOD4PCzqEvZ6j1A6oaxfVicfia4vJC7dmCtrrX5ic2Abtn8ER2yVwTcSMkpwf4dxY6Hnlrrzg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">通过对每月漏洞情况进行分析，我们发现</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">，</span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">高危/严重数量占总漏洞数的比例达到了<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">40%</span></span></span><span data-font-family="default" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">，</span>在1月份，</span></span><span data-font-family="default"><span leaf="">整体漏洞数量及高危漏洞数量均处于高峰期，2月</span></span><span data-font-family="default"><span leaf="">漏洞漏洞处于低峰值。</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img data-imgfileid="100012972" class="rich_pages wxw-img" data-ratio="0.3853211009174312" data-s="300,640" data-type="png" data-w="2616" style="margin-left:0px;margin-top:0px;width:100%;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mx7iblhoFEtwoDa1fnicgDDTEvvusn3VwUmTlB4pu2IXTbkaicuBT62qkLSK9ZhCpo6S9JOE85oZAQQ/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="562" data-cropsely2="216" src="https://wechat2rss.xlab.app/img-proxy/?k=d96d0230&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mx7iblhoFEtwoDa1fnicgDDTEvvusn3VwUmTlB4pu2IXTbkaicuBT62qkLSK9ZhCpo6S9JOE85oZAQQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">通过</span></span><span data-font-family="default"><span leaf="">将</span></span><span data-font-family="default"><span leaf="">这些漏洞</span></span><span data-font-family="default"><span leaf="">结合</span></span><span data-font-family="default"><span leaf="">外部</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">进行进一步分析，我们发现：</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img data-imgfileid="100012973" class="rich_pages wxw-img" data-ratio="0.39466895958727427" data-s="300,640" data-type="png" data-w="2326" style="margin-left:0px;margin-top:0px;width:100%;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mx7iblhoFEtwoDa1fnicgDDTpyK4sD0LZRpwyVfw7sia3qyyRMtUGqlK8nBOlZklwvwicibJnxvOnuMdA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="562" data-cropsely2="222" src="https://wechat2rss.xlab.app/img-proxy/?k=60423d27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mx7iblhoFEtwoDa1fnicgDDTpyK4sD0LZRpwyVfw7sia3qyyRMtUGqlK8nBOlZklwvwicibJnxvOnuMdA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">业务场景的0day（如企业使用的CMS、管理系统等）是通用框架</span></span><span style="white-space:pre-wrap;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">0day</span></span><span style="white-space:pre-wrap;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">漏洞的近2倍，意味着</span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">部分</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">商业化的CMS或管理系统安全性不一定比通用主流框架安全</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">性</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">好</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">；</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">上半年，漏洞相关情报虽有<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;"> </span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">20w+</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;"> </span>之多，但经过AI+人工研判过滤，影响到企业主流系统及业务应用的重点高危漏洞约</span></span><span style="white-space:pre-wrap;font-size:11pt;font-weight:bold;font-style:normal;color:#FF0000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">600</span></span></span><span style="white-space:pre-wrap;font-size:11pt;font-weight:bold;font-style:normal;color:#FF0000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">个；</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">实际</span></span><span data-font-family="default"><span leaf="">环境</span></span><span data-font-family="default"><span leaf="">下</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">如果进一步结合企业业务组件使用情况，</span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">企业上半年真正需要关注或修复的漏洞，其实不到 600 个，</span></span></span><span data-font-family="default"><span leaf="">但难点在于，</span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">如何在不遗漏重要情报的情况下，从茫茫</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">漏洞</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">数据</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">中筛选出与自身业务相关的漏洞信息。</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></li></ul><h4 style="-webkit-tap-highlight-color: transparent;margin-right: 8px;margin-left: 8px;outline: 0px;font-size: 15px;line-height: 2em;font-family: PingFangSC-light;margin-bottom: 16px;"><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 18px;"> </span><span textstyle="" style="font-size: 16px;">在野</span></span></span><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">漏洞</span></span></span><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">利用</span></span></span><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">情况</span><span textstyle="" style="font-size: 18px;"> </span></span></span></h4><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">依托腾讯云与端的多维数据，过去半年捕获了进行在野攻击的通用框架类0day漏洞 </span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">43</span></span></span><span style="white-space:pre-wrap;font-size:11pt;font-weight:bold;font-style:normal;color:#FF0000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">个，识别具体业务场景 0day 漏洞<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;"> </span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">2</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">8</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">5</span></span></span><span style="white-space:pre-wrap;font-size:11pt;font-weight:bold;font-style:normal;color:#FF0000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">例</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="&#34;PingFang SC&#34;, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">较 2024H2 增长<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;"> 148%.</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">上半年 CISA KEV公开已知被公开利用的漏洞有<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;"> </span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">134</span></span></span><span style="white-space:pre-wrap;font-size:11pt;font-weight:bold;font-style:normal;color:#FF0000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">个，</span></span><span data-font-family="default"><span leaf="">对比</span></span><span data-font-family="default"><span leaf="">2</span></span><span data-font-family="default"><span leaf="">4</span></span><span data-font-family="default"><span leaf="">年</span></span><span data-font-family="default"><span leaf="">H</span></span><span data-font-family="default"><span leaf="">1</span></span><span data-font-family="default"><span leaf="">（</span></span><span data-font-family="default"><span leaf="">1</span></span><span data-font-family="default"><span leaf="">1</span></span><span data-font-family="default"><span leaf="">0</span></span><span data-font-family="default"><span leaf="">个</span></span><span data-font-family="default"><span leaf="">）</span></span><span data-font-family="default"><span leaf="">增加</span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">近22%</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">，</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">上半年</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">外部</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">漏洞</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">利用</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">风险</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">呈现</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">了</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">较大</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">增长</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">态势</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">。</span></span></span></p></li></ul><h3 style="-webkit-tap-highlight-color: transparent;margin-right: 8px;margin-left: 8px;outline: 0px;font-size: 15px;line-height: 2em;font-family: PingFangSC-light;margin-bottom: 16px;"><span data-font-family="default"><span leaf="" style="color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 18px;"> </span><span textstyle="" style="font-size: 16px;">2025 腾讯漏洞态势总结</span><span textstyle="" style="font-size: 18px;"> </span></span></span><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h3><h4 style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">高危漏洞分布</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">情况</span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">AI</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">开源</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">组件</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">成为新兴攻击焦点</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">腾讯</span></span><span data-font-family="default"><span leaf="">云</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">2</span></span><span data-font-family="default"><span leaf="">4</span></span><span data-font-family="default"><span leaf="">年</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">已经</span></span><span data-font-family="default"><span leaf="">围绕</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">大模型</span></span><span data-font-family="default"><span leaf="">生态</span></span><span data-font-family="default"><span leaf="">建立</span></span><span data-font-family="default"><span leaf="">了</span></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">清单</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">针对</span></span><span data-font-family="default"><span leaf="">大模型</span></span><span data-font-family="default"><span leaf="">相关</span></span><span data-font-family="default"><span leaf="">生产</span></span><span data-font-family="default"><span leaf="">链条</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">数百个</span></span><span data-font-family="default"><span leaf="">供应链</span></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">形成了</span></span><span data-font-family="default"><span leaf="">系统化</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">通过</span></span><span data-font-family="default"><span leaf="">上半年</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">分析</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">我们</span></span><span data-font-family="default"><span leaf="">发现</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">频率</span></span><span data-font-family="default"><span leaf="">相比</span></span><span data-font-family="default"><span leaf="">去年</span></span><span data-font-family="default"><span leaf="">有较大</span></span><span data-font-family="default"><span leaf="">幅度</span></span><span data-font-family="default"><span leaf="">增加</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">如</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">llama_index、vLLM</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">LiteLLM 等新兴 AI 生态漏洞多次出现，显示攻击面正逐步延伸至 LLM 应用链条</span></span><span data-font-family="default"><span leaf="">。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">广泛使用的软件漏洞PoC</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">响应</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">加速</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">，</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">在</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">漏洞</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">发布后几小时可能被黑产</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">掌握</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">在广泛使用的软件（如浏览器、移动操作系统、网络边界设备VPN/防火墙、邮件服务器）中</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">一个功能齐全的利用代码（PoC）在补丁发布后的几小时内就可能出现在地下论坛或由攻击团伙掌握</span></span><span data-font-family="default"><span leaf="">，攻击者通过补丁比对 (Patch Diffing) 来逆向工程漏洞并开发出利用代码的速度极快。如针对Fortinet、Ivanti等边界设备的多个漏洞，其大规模扫描和利用活动在补丁发布的24小时内就已开始</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">若</span></span><span data-font-family="default"><span leaf="">使用</span></span><span data-font-family="default"><span leaf="">到</span></span><span data-font-family="default"><span leaf="">这些</span></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">需</span></span><span data-font-family="default"><span leaf="">进行</span></span><span data-font-family="default"><span leaf="">重点</span></span><span data-font-family="default"><span leaf="">关注</span></span><span data-font-family="default"><span leaf="">。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">攻击面持续扩大，</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">无需</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">认证漏洞占比超六成 ，63%的漏洞无需身份验证即可利用</span> </span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">通过</span></span><span data-font-family="default"><span leaf="">上半年</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">重点</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">预警</span></span><span data-font-family="default"><span leaf="">数据</span></span><span data-font-family="default"><span leaf="">进行</span></span><span data-font-family="default"><span leaf="">分析</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">我们</span></span><span data-font-family="default"><span leaf="">发现</span></span><span data-font-family="default"><span leaf="">有</span></span><span data-font-family="default"><span leaf="">超过</span></span><span data-font-family="default"><span leaf="">6</span></span><span data-font-family="default"><span leaf="">3</span></span><span data-font-family="default"><span leaf="">%</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">无需</span></span><span data-font-family="default"><span leaf="">用户</span></span><span data-font-family="default"><span leaf="">身份</span></span><span data-font-family="default"><span leaf="">验证</span></span><span data-font-family="default"><span leaf="">即可</span></span><span data-font-family="default"><span leaf="">被</span></span><span data-font-family="default"><span leaf="">利用</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">如Citrix认证绕过、</span></span><span data-font-family="default"><span leaf="">国内</span></span><span data-font-family="default"><span leaf="">部分</span></span><span data-font-family="default"><span leaf="">OA</span></span><span data-font-family="default"><span leaf="">系统</span></span><span data-font-family="default"><span leaf="">SQL注入</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">攻击门槛</span></span><span data-font-family="default"><span leaf="">变</span></span><span data-font-family="default"><span leaf="">低</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">针对</span></span><span data-font-family="default"><span leaf="">这些</span></span><span data-font-family="default"><span leaf="">系统</span></span><span data-font-family="default"><span leaf="">或</span></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">控制</span></span><span data-font-family="default"><span leaf="">好访问对外访问</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">同时</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">也</span></span><span data-font-family="default"><span leaf="">同时</span></span><span data-font-family="default"><span leaf="">需</span></span><span data-font-family="default"><span leaf="">建立</span></span><span data-font-family="default"><span leaf="">好</span></span><span data-font-family="default"><span leaf="">及时</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">响应</span></span><span data-font-family="default"><span leaf="">能力</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">WAF</span></span><span data-font-family="default"><span leaf="">侧</span></span><span data-font-family="default"><span leaf="">能</span></span><span data-font-family="default"><span leaf="">提前</span></span><span data-font-family="default"><span leaf="">有一些</span></span><span data-font-family="default"><span leaf="">应对</span></span><span data-font-family="default"><span leaf="">动作</span></span><span data-font-family="default"><span leaf="">。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">权限体系脆弱性暴露</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">，</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">危害</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">可能</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">放大</span></span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">单个</span></span><span data-font-family="default"><span leaf="">中</span></span><span data-font-family="default"><span leaf="">危</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">往往</span></span><span data-font-family="default"><span leaf="">不会</span></span><span data-font-family="default"><span leaf="">引起</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">警觉</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">而</span></span><span data-font-family="default"><span leaf="">当</span></span><span data-font-family="default"><span leaf="">两个</span></span><span data-font-family="default"><span leaf="">不同</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">组合</span></span><span data-font-family="default"><span leaf="">起来</span></span><span data-font-family="default"><span leaf="">后</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">有时</span></span><span data-font-family="default"><span leaf="">往往</span></span><span data-font-family="default"><span leaf="">能</span></span><span data-font-family="default"><span leaf="">实现</span></span><span data-font-family="default"><span leaf="">较大</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">影响力</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">如Linux UDisks+PAM组合提权（CVE-2025-6018 + CVE-2025-6019）</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">组合</span></span><span data-font-family="default"><span leaf="">使用</span></span><span data-font-family="default"><span leaf="">可实现普通用户→root权限完整提权链，攻击者可横向移动至高权限环境。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">云原生工具</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">的</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">权限控制缺陷</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">日益</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(0, 82, 255);">突出</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 24px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">随着</span></span><span data-font-family="default"><span leaf="">云原生</span></span><span data-font-family="default"><span leaf="">生态</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">蓬勃</span></span><span data-font-family="default"><span leaf="">发展</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">云原生</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">生态</span></span><span data-font-family="default"><span leaf="">工具</span></span><span data-font-family="default"><span leaf="">权限</span></span><span data-font-family="default"><span leaf="">配置</span></span><span data-font-family="default"><span leaf="">及</span></span><span data-font-family="default"><span leaf="">管理</span></span><span data-font-family="default"><span leaf="">问题</span></span><span data-font-family="default"><span leaf="">开始</span></span><span data-font-family="default"><span leaf="">变得</span></span><span data-font-family="default"><span leaf="">日益突出</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">如Teleport认证绕过、Apache CloudStack</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">暴露</span></span><span data-font-family="default"><span leaf="">了</span></span><span data-font-family="default"><span leaf="">多云环境安全管理短板</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">使用</span></span><span data-font-family="default"><span leaf="">多云</span></span><span data-font-family="default"><span leaf="">或</span></span><span data-font-family="default"><span leaf="">混合云</span></span><span data-font-family="default"><span leaf="">时</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">针对</span></span><span data-font-family="default"><span leaf="">这些</span></span><span data-font-family="default"><span leaf="">云</span></span><span data-font-family="default"><span leaf="">原</span></span><span data-font-family="default"><span leaf="">生</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">也许</span></span><span data-font-family="default"><span leaf="">及时</span></span><span data-font-family="default"><span leaf="">关注</span></span><span data-font-family="default"><span leaf="">响应</span></span><span data-font-family="default"><span leaf="">。</span></span></p><h4 style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">高危</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">可利用</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">漏洞</span></span></span><span style="white-space: pre-wrap;font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Top</span></span></span><span style="white-space: pre-wrap;font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">风险</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">组件</span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h4><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">Google Chrome（35例）</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">Windows（22例）</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">Linux Kernel（16例）</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">Gitlab、Dataease、ColdFusion 等也在高频列中</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p></li></ul><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">Chrome、Windows、Linux Kernel 由于广泛的使用量，成为上半年漏洞较多的组件，</span></span><span data-font-family="default"><span leaf="">这</span></span><span data-font-family="default"><span leaf="">说明</span></span><span data-font-family="default"><span leaf="">日常</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">系统</span></span><span data-font-family="default"><span leaf="">补丁</span></span><span data-font-family="default"><span leaf="">更新</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">终端</span></span><span data-font-family="default"><span leaf="">应用</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">监测</span></span><span data-font-family="default"><span leaf="">和</span></span><span data-font-family="default"><span leaf="">推</span></span><span data-font-family="default"><span leaf="">修</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">工作</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">可以</span></span><span data-font-family="default"><span leaf="">帮助</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">规避</span></span><span data-font-family="default"><span leaf="">大量</span></span><span data-font-family="default"><span leaf="">高频</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">。 </span></span></p><h4 style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">精选必修漏洞（共 3</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">1</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);"> 个）</span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 16px 0px 24px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">2025 年H1 </span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">我们</span></span><span data-font-family="default"><span leaf="">整理</span></span><span data-font-family="default"><span leaf="">了</span></span><span data-font-family="default"><span leaf="">一份</span></span><span data-font-family="default"><span leaf="">必修漏洞清单</span></span><span data-font-family="default"><span leaf="">（</span></span><span data-font-family="default"><span leaf="">详见</span></span><span data-font-family="default"><span leaf="">附录A：腾讯安全每月必修漏洞合集）</span></span><span data-font-family="default"><span leaf="">，</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">我们</span></span><span data-font-family="default"><span leaf="">从中</span></span><span data-font-family="default"><span leaf="">精选</span></span><span data-font-family="default"><span leaf="">了</span></span><span data-font-family="default"><span leaf="">3</span></span><span data-font-family="default"><span leaf="">1</span></span><span data-font-family="default"><span leaf="">个</span></span><span data-font-family="default"><span leaf="">重点</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">这些</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">大部分</span></span><span data-font-family="default"><span leaf="">已经</span></span><span data-font-family="default"><span leaf="">公开了</span></span><span data-font-family="default"><span leaf="">PoC</span></span><span data-font-family="default"><span leaf="">并</span></span><span data-font-family="default"><span leaf="">出现了</span></span><span data-font-family="default"><span leaf="">在野</span></span><span data-font-family="default"><span leaf="">利用</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">可</span></span><span data-font-family="default"><span leaf="">对照</span></span><span data-font-family="default"><span leaf="">是否</span></span><span data-font-family="default"><span leaf="">使用到</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">并</span></span><span data-font-family="default"><span leaf="">加快</span></span><span data-font-family="default"><span leaf="">修复</span></span><span data-font-family="default"><span leaf="">进度</span></span><span data-font-family="default"><span leaf="">。</span></span><span data-font-family="default"><span leaf="">如需进一步了解修复方案、漏洞利用难度、在野攻击情况、PoC/EXP 情况等信息，请参见 附录</span></span><span data-font-family="default"><span leaf="">1</span></span><span data-font-family="default"><span leaf="">：</span></span><span data-font-family="default"><span leaf="">精选必修漏洞</span></span><span data-font-family="default"><span leaf="">列表</span></span><span data-font-family="default"><span leaf="">。</span></span></p><h4 style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">重保季场景常见国产组件的漏洞（共 5</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">4</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);"> 个）</span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 0px 0px 24px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">在本类别中，所选漏洞源自 2025 年度出现的国产软件漏洞。在重保场景下，国产软件漏洞受到业界的高度关注，并已成为外部攻击者的主要攻击目标。这些漏洞对企业网络安全构成严重威胁，故企业需将其视为优先事项，及时采取措施予以修复，旨在确保业务的安全性与稳定性得到充分保障</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">详情</span></span><span data-font-family="default"><span leaf="">参见</span></span><span data-font-family="default"><span leaf="">附录</span></span><span data-font-family="default"><span leaf="">2</span></span><span data-font-family="default"><span leaf="">：</span></span><span data-font-family="default"><span leaf="">重</span></span><span data-font-family="default"><span leaf="">保季场景常见国产组件的漏洞</span></span><span data-font-family="default"><span leaf="">列表</span></span><span data-font-family="default"><span leaf="">。 </span></span></p><h4 style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">高活跃度的历史漏洞（共 18 个）</span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 0px 0px 24px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">根据近半年的数据监测结果，部分历史漏洞仍然存在较为活跃的利用行为。建议相关资产的客户高度重视，及时排查并确认相关漏洞是否已完成修复，切实提升漏洞管理和防护工作的优先级</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">详情参见附录</span></span><span data-font-family="default"><span leaf="">3</span></span><span data-font-family="default"><span leaf="">：</span></span><span data-font-family="default"><span leaf="">高活跃度的历史漏洞</span></span><span data-font-family="default"><span leaf="">列表</span></span><span data-font-family="default"><span leaf="">。 </span></span></p><h4 style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px 16.8pt;text-indent: -16.8pt;"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">AI</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">&amp;</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">云</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">原生</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">&amp;</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">国产</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">组件</span></span></span><span style="white-space: pre-wrap;font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">TO</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">P</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">漏洞（共 11 个）</span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">通过</span></span><span data-font-family="default"><span leaf="">对</span></span><span data-font-family="default"><span leaf="">上半年</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">情报分析</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">我们</span></span><span data-font-family="default"><span leaf="">发现</span></span><span data-font-family="default"><span leaf="">不少</span></span><span data-font-family="default"><span leaf="">热门</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">集中</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">云</span></span><span data-font-family="default"><span leaf="">原生</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">国产</span></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">领域</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">这些</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">利用</span></span><span data-font-family="default"><span leaf="">较为</span></span><span data-font-family="default"><span leaf="">简单</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">实际</span></span><span data-font-family="default"><span leaf="">影响</span></span><span data-font-family="default"><span leaf="">及</span></span><span data-font-family="default"><span leaf="">危害</span></span><span data-font-family="default"><span leaf="">较大</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">如</span></span><span data-font-family="default"><span leaf="">用户</span></span><span data-font-family="default"><span leaf="">用到</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">可</span></span><span data-font-family="default"><span leaf="">对照</span></span><span data-font-family="default"><span leaf="">高</span></span><span data-font-family="default"><span leaf="">优先级</span></span><span data-font-family="default"><span leaf="">进行</span></span><span data-font-family="default"><span leaf="">修复</span></span><span data-font-family="default"><span leaf="">。</span></span><span data-font-family="default"><span leaf="">详情参见附录</span></span><span data-font-family="default"><span leaf="">4</span></span><span data-font-family="default"><span leaf="">：</span></span><span data-font-family="default"><span leaf="">AI&amp;云原生&amp;国产组件 TOP漏洞</span></span><span data-font-family="default"><span leaf="">列表</span></span><span data-font-family="default"><span leaf="">。</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;" data-pm-slice="4 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="161893"><div style="margin: 10px auto;"><div style="margin: 10px auto;display: flex;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><div style="border: 1px solid #0e65d2;padding: 3px;box-sizing:border-box;"><div style="background: linear-gradient(to right,#e2eeff,#ffffff);padding: 5px 10px;box-sizing:border-box;"><div style="display: flex;justify-content: space-between;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><p style="font-size: 16px;color: #135cb7;text-align: left;"><strong data-brushtype="text"><span leaf="">四、AI引爆漏洞管理革命：攻防升级进行时</span></strong></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></div><h4 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> </span></span><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">AI带来的双重冲击 </span></span><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> </span></span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">上半年</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">随着</span></span><span data-font-family="default"><span leaf="">AI大模型的快速普及和应用</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">对</span></span><span data-font-family="default"><span leaf="">攻防</span></span><span data-font-family="default"><span leaf="">领域</span></span><span data-font-family="default"><span leaf="">带来</span></span><span data-font-family="default"><span leaf="">提效</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">同时</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">自身</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">也</span></span><span data-font-family="default"><span leaf="">给</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">带来</span></span><span data-font-family="default"><span leaf="">了</span></span><span data-font-family="default"><span leaf="">新的</span></span><span data-font-family="default"><span leaf="">攻击面。</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img data-imgfileid="100012974" class="rich_pages wxw-img" data-ratio="0.6946502057613169" data-s="300,640" data-type="png" data-w="1215" style="margin-left:0px;margin-top:0px;width:100%;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mx7iblhoFEtwoDa1fnicgDDTVqhY5Wa9KPyicHARgd4wVU21ia6nicl221dRCGJTAAj2qUhMCNsRdh4JA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="562" data-cropsely2="390" src="https://wechat2rss.xlab.app/img-proxy/?k=a7938186&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mx7iblhoFEtwoDa1fnicgDDTVqhY5Wa9KPyicHARgd4wVU21ia6nicl221dRCGJTAAj2qUhMCNsRdh4JA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><span style="font-size:11pt;font-family:微软雅黑;font-weight:bold;font-style:normal;color:#000000;background:#FCFCFC;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><h4 style="text-align: left;line-height: 1.7;margin: 0pt;"><span data-font-family="default"><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> 热门AI组件漏洞 </span></span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">腾讯安全持续监控</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">应用漏洞，发现如下</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">组件漏洞出现了较为广泛的利用，风险修复优先级较高，建议客户及时开展自查，对漏洞进行修复和防护。</span></span></p><table style="max-width:100% !important;box-sizing:border-box;min-width:174px;"><tbody><tr style="height:27px;"><td data-colwidth="149" style="border: 1px solid rgb(203, 205, 209);background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">腾讯云安全编号</span></span></strong></span></p></td><td style="border-top: 1px solid rgb(203, 205, 209);border-right: 1px solid rgb(203, 205, 209);border-bottom: 1px solid rgb(203, 205, 209);border-image: initial;border-left: none;background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">漏洞名</span></span></strong></span></p></td></tr><tr><td data-colwidth="149" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-39961</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Anyscale Ray </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">命令执行漏洞（CVE-2024-57000/CVE-2023-48022）</span></span></p></td></tr><tr><td data-colwidth="149" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-11026</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Langflow </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞（CVE-2025-3248）</span></span></p></td></tr><tr><td data-colwidth="149" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-40423</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">LlamaIndex SQL</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">注入导致命令执行漏洞（CVE-2024-11958）</span></span></p></td></tr><tr><td data-colwidth="149" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-7278</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">FlowiseAI Flowise </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">文件上传漏洞（CVE-2025-26319）</span></span></p></td></tr><tr><td data-colwidth="149" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-16486</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">vLLM PyNcclPipe pickle</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">反序列化漏洞   (CVE-2025-47277)</span></span></p></td></tr><tr><td data-colwidth="149" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-41101</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Dify </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">任意密码重置漏洞（CVE-2024-12776）</span></span></p></td></tr><tr><td data-colwidth="149" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-11492</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">BentoML </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞（CVE-2025-32375）</span></span></p></td></tr></tbody></table><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">这些</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">分布</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">大模型供应链模型训练的各个阶段，对模型的影响也</span></span><span data-font-family="default"><span leaf="">不尽相同</span></span><span data-font-family="default"><span leaf="">。</span></span></p><table style="max-width:100% !important;box-sizing:border-box;min-width:277px;"><tbody><tr style="height:27px;"><td data-colwidth="109" style="border: 1px solid #cbcdd1;background: #2972f4;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">层级</span></span></strong></span></p></td><td data-colwidth="118" style="border-top: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-image: initial;border-left: none;background: #2972f4;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">风险组件案例</span></span></strong></span></p></td><td style="border-top: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-image: initial;border-left: none;background: #2972f4;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">漏洞类型</span></span></strong></span></p></td><td style="border-top: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-image: initial;border-left: none;background: #2972f4;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">影响范围</span></span></strong></span></p></td></tr><tr><td data-colwidth="109" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">训练框架</span></span></p></td><td data-colwidth="118" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Ray</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">（CVE-2024-57000）</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">命令执行</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">千节点GPU集群</span></span></p></td></tr><tr><td data-colwidth="109" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">推理引擎</span></span></p></td><td data-colwidth="118" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">vLLM</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">（CVE-2025-47277）</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Pickle</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">反序列化</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">模型服务权限失控</span></span></p></td></tr><tr><td data-colwidth="109" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">应用中间件</span></span></p></td><td data-colwidth="118" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Langflow</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">（CVE-2025-3248）</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">RCE</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">链构造</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">业务逻辑被劫持</span></span></p></td></tr></tbody></table><h4 style="text-align: left;line-height: 1.7;margin: 0pt 0pt 16px;"><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> 现在</span></span></span><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">企业</span></span></span><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">在</span></span></span><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">安全</span></span></span><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">运营</span></span></span><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">层面</span></span></span><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">存在</span></span></span><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">的</span></span></span><span style="white-space: pre-wrap;font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">AI</span></span></span><span style="white-space: pre-wrap;font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;" data-font-family="default"><span leaf="" style="font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">防御盲区 </span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">  </span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1、 </span><span data-font-family="default"><span leaf="">缺乏</span></span><span data-font-family="default"><span leaf="">大模型</span></span><span data-font-family="default"><span leaf="">运行</span></span><span data-font-family="default"><span leaf="">环境</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">专项</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">情报；</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2、 </span><span data-font-family="default"><span leaf="">供应链层级未纳入传统漏洞扫描工具（如SAST/DAST无法检测模型文件风险）；</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3、 </span><span data-font-family="default"><span leaf="">未</span></span><span data-font-family="default"><span leaf="">建立   AI-SBOM（软件物料清单）</span></span><span data-font-family="default"><span leaf="">/</span></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">列表</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">动态</span></span><span data-font-family="default"><span leaf="">追踪模型依赖链；</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">4、 </span><span data-font-family="default"><span leaf="">MCP</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">大模型</span></span><span data-font-family="default"><span leaf="">相关</span></span><span data-font-family="default"><span leaf="">协议</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">业务</span></span><span data-font-family="default"><span leaf="">应用</span></span><span data-font-family="default"><span leaf="">场景</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">快速</span></span><span data-font-family="default"><span leaf="">落地</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">带来</span></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">应用</span></span><span data-font-family="default"><span leaf="">执行</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">不可控性；</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">5、 </span><span data-font-family="default"><span leaf="">缺乏</span></span><span data-font-family="default"><span leaf="">对</span></span><span data-font-family="default"><span leaf="">大模型</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">Prompt</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">拦截</span></span><span data-font-family="default"><span leaf="">与</span></span><span data-font-family="default"><span leaf="">防御。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><h4 style="text-align: left;line-height: 1.7;margin: 0pt 0pt 16px;"><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> 防御破局点 </span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(26, 26, 26);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1、 </span><span data-font-family="default"><span leaf="">构建 AI 组件SBOM（软件物料清单）或生态组件列表，开展持续风险情报监测；</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2、 </span><span data-font-family="default"><span leaf="">了解并识别AI运行的基础环境，逐步引入 AI-SPM/暴露面，以识别AI运行底层的传统安全风险；</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3、 </span><span data-font-family="default"><span leaf="">部署LLM防火墙（检测异常指令序列），如WAF LLM，构建基础应用及内容安全护栏，防范Prompt注入等典型风险；</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">4、 </span><span data-font-family="default"><span leaf="">应用 MCP或大模型安全网关，构建以统一身份为核心的访问控制，有效释放权限类的安全风险；</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 8px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">5、 </span><span data-font-family="default"><span leaf="">建立 AI 安全评估和红蓝对抗机制，更深入检测大模型存在的逻辑、架构等安全问题。</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;" data-pm-slice="4 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="161893"><div style="margin: 10px auto;"><div style="margin: 10px auto;display: flex;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><div style="border: 1px solid #0e65d2;padding: 3px;box-sizing:border-box;"><div style="background: linear-gradient(to right,#e2eeff,#ffffff);padding: 5px 10px;box-sizing:border-box;"><div style="display: flex;justify-content: space-between;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><p style="font-size: 16px;color: #135cb7;text-align: left;"><strong data-brushtype="text"><span leaf="">五、2025 H2未来漏洞趋势预测</span></strong></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">基于上半年数据以及一些新兴技术（如AI大模型），我们预测下半年漏洞攻防将会更加激烈，漏洞管理的复杂度将会进入一个新的高度。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">主要表现在如下几个方面：</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">大模型接入及应用日益广泛，大模型自身风险需关注</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">随着大模型在</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">业务</span></span><span data-font-family="default"><span leaf="">场景</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">广泛</span></span><span data-font-family="default"><span leaf="">部署</span></span><span data-font-family="default"><span leaf="">与</span></span><span data-font-family="default"><span leaf="">应用</span></span><span data-font-family="default"><span leaf="">，伴随的是大模型从部署、训练到使用等各个环节</span></span><span data-font-family="default"><span leaf="">引入</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">各类</span></span><span data-font-family="default"><span leaf="">风险，从<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">底</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">层支撑组件的漏洞管理</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="font-weight: bold;">（</span>如llama_index、vLLM、Vite、Ollama等），到数据训练阶段的数据</span></span><span data-font-family="default"><span leaf="">溯源</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">脱敏</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">访问</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">存储</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">再到模型</span></span><span data-font-family="default"><span leaf="">自身</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">（</span></span><span data-font-family="default"><span leaf="">Prompt注入、模型越狱等</span></span><span data-font-family="default"><span leaf="">）</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">模型Agent/应用安全</span></span></span><span data-font-family="default"><span leaf="">（</span></span><span data-font-family="default"><span leaf="">Cur</span></span><span data-font-family="default"><span leaf="">sor</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">RCE</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">MCP</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">应用</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">）</span></span><span data-font-family="default"><span leaf="">，这些问题目前仍然没有一劳永逸的解决方案，往往需要企业结合业务实际需求，提前做好传统大模型组件的漏洞收敛以及大模型的安全评估工作。</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span><o:p></o:p></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">供应链安全风险从未消失，只是以不同的方式潜伏在不同类型的业务组件中</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">去年的xz utils投毒风险</span></span><span data-font-family="default"><span leaf="">事件</span></span><span data-font-family="default"><span leaf="">后</span></span><span data-font-family="default"><span leaf="">，攻击者针对</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">Python</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">的</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">PyPI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">和</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">JavaScript</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">的</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">npm</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">等主流软件包仓库的投毒攻击</span></span><span data-font-family="default"><span leaf="">从</span></span><span data-font-family="default"><span leaf="">未停歇。根据腾讯漏洞</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">团队针对软件源投毒情报的分析，大量旨在窃取开发者机密信息（API密钥、密码等）或攻击加密货币钱包的恶意软件包被发现，其中，模仿知名软件包名称的“域名仿冒（Typosquatting）”和伪装成AI相关库的手法依然是主流，企业</span></span><span data-font-family="default"><span leaf="">个人</span></span><span data-font-family="default"><span leaf="">在部署大模型或使用大模型支撑业务的过程中，由于</span></span><span data-font-family="default"><span leaf="">Pypi</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">NPM</span></span><span data-font-family="default"><span leaf="">丰富</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">生态</span></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">支撑</span></span><span data-font-family="default"><span leaf="">能力</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">员工</span></span><span data-font-family="default"><span leaf="">往往</span></span><span data-font-family="default"><span leaf="">容易</span></span><span data-font-family="default"><span leaf="">将</span></span><span data-font-family="default"><span leaf="">大量</span></span><span data-font-family="default"><span leaf="">存在</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">软件</span></span><span data-font-family="default"><span leaf="">包</span></span><span data-font-family="default"><span leaf="">安装</span></span><span data-font-family="default"><span leaf="">，从而导致高配置机器被用于挖矿或业务敏感信息泄露风险，未来针对投毒情报的监测、自动化工具（SCA等）的应用，也需企业纳入风险管理的日程。</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span><o:p></o:p></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">基于</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">人工智能（AI）</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">的</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">漏洞</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">攻击</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">靠</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">从概念验证阶段全面进入攻击工具化的实战阶段</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">2025年下半年</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">我们预测</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">驱动的自动化渗透工具雏形</span></span><span data-font-family="default"><span leaf="">将</span></span><span data-font-family="default"><span leaf="">出现</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">这些工具将能做到</span></span><span data-font-family="default"><span leaf="">更</span></span><span data-font-family="default"><span leaf="">自主发现与关联</span></span><span data-font-family="default"><span leaf="">——</span></span><span data-font-family="default"><span leaf="">通过API持续扫描目标资产，AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">将不再是简单利用单个已知漏洞（N-day），而是能自主发现并关联多个低危漏洞（例如</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">一个信息泄露漏洞 + 一个服务端请求伪造（SSRF）漏洞 + 一个权限配置错误），形成一个高影响力的攻击链</span></span><span data-font-family="default"><span leaf="">。</span></span><span data-font-family="default"><span leaf="">因而</span></span><span data-font-family="default"><span leaf="">防御方必须超越传统的漏洞修复和被动响应模式，转向以情报</span></span><span data-font-family="default"><span leaf="">驱动</span></span><span data-font-family="default"><span leaf="">、AI辅助</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">运营</span></span><span data-font-family="default"><span leaf="">体系</span></span><span data-font-family="default"><span leaf="">。</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;" data-pm-slice="4 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="161893"><div style="margin: 10px auto;"><div style="margin: 10px auto;display: flex;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><div style="border: 1px solid #0e65d2;padding: 3px;box-sizing:border-box;"><div style="background: linear-gradient(to right,#e2eeff,#ffffff);padding: 5px 10px;box-sizing:border-box;"><div style="display: flex;justify-content: space-between;"><div style="width: 100%;max-width:100% !important;box-sizing:border-box;" data-width="100%"><p style="font-size: 16px;color: #135cb7;text-align: left;"><strong data-brushtype="text"><span leaf="">六、企业漏洞治理建议</span></strong></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">针对</span></span><span data-font-family="default"><span leaf="">不断</span></span><span data-font-family="default"><span leaf="">变化</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">防御环境</span></span><span data-font-family="default"><span leaf="">与</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">挑战</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">我们</span></span><span data-font-family="default"><span leaf="">建议</span></span><span data-font-family="default"><span leaf="">主动防御</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">弹性</span></span><span data-font-family="default"><span leaf="">响应</span></span><span data-font-family="default"><span leaf="">两个</span></span><span data-font-family="default"><span leaf="">维度</span></span><span data-font-family="default"><span leaf="">去</span></span><span data-font-family="default"><span leaf="">开展</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">治理</span></span><span data-font-family="default"><span leaf="">工作</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">具体</span></span><span data-font-family="default"><span leaf="">来说</span></span><span data-font-family="default"><span leaf="">：</span></span></p><h4 style="text-align: left;line-height: 1.7;margin: 0pt 0pt 16px;"><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> 1. </span></span><span data-font-family="default"><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">构建主动防御能力（事前预防与保护）</span></span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">主动防御的目标是尽可能地加固身份认证与授权的各个环节，让攻击者难以假冒、盗用或滥用身份。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">加强 AI 生态组件安全</span></span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">构建大模型基础生态运营及基础组件列表或SBOM，围绕这些组件优先构建大模型生态漏洞情报，关注新出现的各类 AI 手段与攻击方法。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">关注云原生边界</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">及工具安全</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">实施云态势安全风险管理（CSPM），同步关注云原生工具（如Teleport、Apache CloudStack）相关漏洞，限制横向渗透。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">强化默认安全机制</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">如</span></span><span data-font-family="default"><span leaf="">默认</span></span><span data-font-family="default"><span leaf="">启用</span></span><span data-font-family="default"><span leaf="">强多因素认证 (Strong MFA)</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">全面推行抗钓鱼的多因素认证，使用Google Authenticator等</span></span><span data-font-family="default"><span leaf="">更</span></span><span data-font-family="default"><span leaf="">强健</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">鉴权</span></span><span data-font-family="default"><span leaf="">技术。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">使用凭证保险库</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">云</span></span><span data-font-family="default"><span leaf="">移</span></span><span data-font-family="default"><span leaf="">+</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">时代</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">越来越多的</span></span><span data-font-family="default"><span leaf="">服务</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">应用</span></span><span data-font-family="default"><span leaf="">（</span></span><span data-font-family="default"><span leaf="">如</span></span><span data-font-family="default"><span leaf="">在线</span></span><span data-font-family="default"><span leaf="">翻译</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">各类</span></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">Agent</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">）</span></span><span data-font-family="default"><span leaf="">都在</span></span><span data-font-family="default"><span leaf="">以</span></span><span data-font-family="default"><span leaf="">API</span></span><span data-font-family="default"><span leaf="">密钥</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">密码</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">方式</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">提供</span></span><span data-font-family="default"><span leaf="">服务</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">将密码、API密钥等敏感凭证从代码和配置文件中移除，存入专门的加密保险库（如HashiCorp Vault, 腾讯SSM），由应用程序在运行时动态获取</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">是</span></span><span data-font-family="default"><span leaf="">提升</span></span><span data-font-family="default"><span leaf="">基础</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">防护</span></span><span data-font-family="default"><span leaf="">能力</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">关键</span></span><span data-font-family="default"><span leaf="">抓手</span></span><span data-font-family="default"><span leaf="">。 </span></span></p><h4 style="text-align: left;line-height: 1.7;margin: 0pt 0pt 16px;"><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;"> 2. </span></span><span data-font-family="default"><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">建立</span></span></span><span data-font-family="default"><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">弹性</span></span></span><span data-font-family="default"><span leaf="" style="text-align: left;font-style: normal;vertical-align: baseline;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;widows: 1;letter-spacing: 1px;visibility: visible;line-height: 2em;font-family: PingFangSC-light;color: rgb(255, 255, 255);font-size: 16px;background-color: rgb(1, 82, 217);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 16px;">响应措施（事中检测与事后响应）</span></span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></h4><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">弹性</span></span><span data-font-family="default"><span leaf="">响应</span></span><span data-font-family="default"><span leaf="">的核心思想是：承认防御体系总有被突破的可能。当身份被盗用时，我们必须能快速检测、</span></span><span data-font-family="default"><span leaf="">即</span></span><span data-font-family="default"><span leaf="">时</span></span><span data-font-family="default"><span leaf="">响应，并将业务从被破坏的状态快速恢复。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">弹性</span></span><span data-font-family="default"><span leaf="">响应</span></span><span data-font-family="default"><span leaf="">相关</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">措施</span></span><span data-font-family="default"><span leaf="">包括</span></span><span data-font-family="default"><span leaf="">但不限于</span></span><span data-font-family="default"><span leaf="">：</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">部署</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">暴露</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">面管理（</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">EM</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">）工具，侦测外泄资产、凭证与可被利用的漏洞</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">核心目的：</span></span><span data-font-family="default"><span leaf="">随着</span></span><span data-font-family="default"><span leaf="">云</span></span><span data-font-family="default"><span leaf="">移</span></span><span data-font-family="default"><span leaf="">时代</span></span><span data-font-family="default"><span leaf="">防护</span></span><span data-font-family="default"><span leaf="">边界</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">消失</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">身份</span></span><span data-font-family="default"><span leaf="">认证</span></span><span data-font-family="default"><span leaf="">账号</span></span><span data-font-family="default"><span leaf="">以及</span></span><span data-font-family="default"><span leaf="">API</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">小程序</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">外部</span></span><span data-font-family="default"><span leaf="">资产</span></span><span data-font-family="default"><span leaf="">暴露面</span></span><span data-font-family="default"><span leaf="">越来</span></span><span data-font-family="default"><span leaf="">越多</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">这些</span></span><span data-font-family="default"><span leaf="">资产</span></span><span data-font-family="default"><span leaf="">针对</span></span><span data-font-family="default"><span leaf="">一些</span></span><span data-font-family="default"><span leaf="">相对</span></span><span data-font-family="default"><span leaf="">较</span></span><span data-font-family="default"><span leaf="">新</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">攻击</span></span><span data-font-family="default"><span leaf="">利用</span></span><span data-font-family="default"><span leaf="">（</span></span><span data-font-family="default"><span leaf="">如</span></span><span data-font-family="default"><span leaf="">AT</span></span><span data-font-family="default"><span leaf="">O</span></span><span data-font-family="default"><span leaf="">-</span></span><span data-font-family="default"><span leaf=""> Account</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">Take-Over、</span></span><span data-font-family="default"><span leaf="">API</span></span><span data-font-family="default"><span leaf="">数据</span></span><span data-font-family="default"><span leaf="">泄漏</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">小程序</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">）</span></span><span data-font-family="default"><span leaf="">通过</span></span><span data-font-family="default"><span leaf="">传统</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">E</span></span><span data-font-family="default"><span leaf="">DR</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">NDR</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">漏</span></span><span data-font-family="default"><span leaf="">扫</span></span><span data-font-family="default"><span leaf="">较难</span></span><span data-font-family="default"><span leaf="">发现</span></span><span data-font-family="default"><span leaf="">。</span></span><span data-font-family="default"><span leaf="">借助</span></span><span data-font-family="default"><span leaf="">暴露面</span></span><span data-font-family="default"><span leaf="">管理</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">可以</span></span><span data-font-family="default"><span leaf="">实现</span></span><span data-font-family="default"><span leaf="">专门的</span></span><span data-font-family="default"><span leaf="">模块</span></span><span data-font-family="default"><span leaf="">集成</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">如</span></span><span data-font-family="default"><span leaf="">针对</span></span><span data-font-family="default"><span leaf="">AT</span></span><span data-font-family="default"><span leaf="">O</span></span><span data-font-family="default"><span leaf="">攻击</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">可以</span></span><span data-font-family="default"><span leaf="">实现</span></span><span data-font-family="default"><span leaf="">专门</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">身份</span></span><span data-font-family="default"><span leaf="">认证</span></span><span data-font-family="default"><span leaf="">凭据</span></span><span data-font-family="default"><span leaf="">监测</span></span><span data-font-family="default"><span leaf="">。它是对EDR（终端检测与响应）和NDR（网络检测与响应）的</span></span><span data-font-family="default"><span leaf="">重要</span></span><span data-font-family="default"><span leaf="">补充。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">参考</span></span><span data-font-family="default"><span leaf="">措施</span></span><span data-font-family="default"><span leaf="">： </span></span><span data-font-family="default"><span leaf="">利用</span></span><span data-font-family="default"><span leaf="">暴露</span></span><span data-font-family="default"><span leaf="">面</span></span><span data-font-family="default"><span leaf="">管理</span></span><span data-font-family="default"><span leaf="">能力</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">查询</span></span><span data-font-family="default"><span leaf="">来自</span></span><span data-font-family="default"><span leaf="">暗网、</span></span><span data-font-family="default"><span leaf="">互联网</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">社区等失陷数据情报</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">与内部登录日志进行实时比对，发现潜在风险</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">利用</span></span><span data-font-family="default"><span leaf="">暴露</span></span><span data-font-family="default"><span leaf="">面</span></span><span data-font-family="default"><span leaf="">管理</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">识别</span></span><span data-font-family="default"><span leaf="">日常</span></span><span data-font-family="default"><span leaf="">运营</span></span><span data-font-family="default"><span leaf="">中</span></span><span data-font-family="default"><span leaf="">出现</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">可</span></span><span data-font-family="default"><span leaf="">利用</span></span><span data-font-family="default"><span leaf="">高危</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">。</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">自动化响应与编排 (SOAR)</span></span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">+</span></span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">AI</span></span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">辅助</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">研判</span></span></span><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">核心任务：将发现的威胁</span></span><span data-font-family="default"><span leaf="">及</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">事件</span></span><span data-font-family="default"><span leaf="">，通过预设的剧本（Playbook）进行自动化处理，</span></span><span data-font-family="default"><span leaf="">针对</span></span><span data-font-family="default"><span leaf="">特定</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">环节</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">引入</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">进行</span></span><span data-font-family="default"><span leaf="">信息</span></span><span data-font-family="default"><span leaf="">富</span></span><span data-font-family="default"><span leaf="">化</span></span><span data-font-family="default"><span leaf="">及</span></span><span data-font-family="default"><span leaf="">关联</span></span><span data-font-family="default"><span leaf="">分析</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">提供</span></span><span data-font-family="default"><span leaf="">更多</span></span><span data-font-family="default"><span leaf="">上</span></span><span data-font-family="default"><span leaf="">下</span></span><span data-font-family="default"><span leaf="">文</span></span><span data-font-family="default"><span leaf="">辅助</span></span><span data-font-family="default"><span leaf="">研判</span></span><span data-font-family="default"><span leaf="">信息</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">帮助</span></span><span data-font-family="default"><span leaf="">运营</span></span><span data-font-family="default"><span leaf="">人员</span></span><span data-font-family="default"><span leaf="">缩短从发现到响应的时间（MTTR）。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">参考</span></span><span data-font-family="default"><span leaf="">措施： </span></span><span data-font-family="default"><span leaf="">利用</span></span><span data-font-family="default"><span leaf="">SOAR</span></span><span data-font-family="default"><span leaf="">+</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">能力</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">自动触发</span></span><span data-font-family="default"><span leaf="">响应</span></span><span data-font-family="default"><span leaf="">动作</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">典型</span></span><span data-font-family="default"><span leaf="">案例</span></span><span data-font-family="default"><span leaf="">如</span></span><span data-font-family="default"><span leaf="">：</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1、 </span><span data-font-family="default"><span leaf="">一旦检测到某个身份疑似被盗用</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">强制该用户重新进行MFA验证、临时禁用该账户、将其正在访问的会话断开。</span></span><span data-font-family="default"><span leaf="">同时</span></span><span data-font-family="default"><span leaf="">可</span></span><span data-font-family="default"><span leaf="">自动收集与该可疑身份相关的所有日志、设备快照等信息，为后续的人工调查提供证据；</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2、 </span><span data-font-family="default"><span leaf="">针对</span></span><span data-font-family="default"><span leaf="">提供</span></span><span data-font-family="default"><span leaf="">方</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">裸</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">信息</span></span><span data-font-family="default"><span leaf="">（</span></span><span data-font-family="default"><span leaf="">原始</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">）</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">利用</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">对</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">源</span></span><span data-font-family="default"><span leaf="">链接</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">内容</span></span><span data-font-family="default"><span leaf="">按照</span></span><span data-font-family="default"><span leaf="">内部</span></span><span data-font-family="default"><span leaf="">响应</span></span><span data-font-family="default"><span leaf="">预警</span></span><span data-font-family="default"><span leaf="">格式</span></span><span data-font-family="default"><span leaf="">分析</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">概述</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">原理</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">利用</span></span><span data-font-family="default"><span leaf="">链</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">影响</span></span><span data-font-family="default"><span leaf="">版本</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">修复</span></span><span data-font-family="default"><span leaf="">版本</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">信息</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">并</span></span><span data-font-family="default"><span leaf="">结合</span></span><span data-font-family="default"><span leaf="">内部</span></span><span data-font-family="default"><span leaf="">产品</span></span><span data-font-family="default"><span leaf="">规则</span></span><span data-font-family="default"><span leaf="">特征</span></span><span data-font-family="default"><span leaf="">基于</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">生成</span></span><span data-font-family="default"><span leaf="">检测</span></span><span data-font-family="default"><span leaf="">响应</span></span><span data-font-family="default"><span leaf="">模板</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">实现</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">+</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">驱动的</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">极速</span></span><span data-font-family="default"><span leaf="">响应</span></span><span data-font-family="default"><span leaf="">。</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">● </span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">风险预案与快速响应</span></span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">核心</span></span><span data-font-family="default"><span leaf="">任务</span></span><span data-font-family="default"><span leaf="">：</span></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">时代</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">到来</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">给</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">带来</span></span><span data-font-family="default"><span leaf="">了</span></span><span data-font-family="default"><span leaf="">诸多</span></span><span data-font-family="default"><span leaf="">不确定性</span></span><span data-font-family="default"><span leaf="">和</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">防护</span></span><span data-font-family="default"><span leaf="">挑战</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">传统</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">基于</span></span><span data-font-family="default"><span leaf="">IS</span></span><span data-font-family="default"><span leaf="">O</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">2</span></span><span data-font-family="default"><span leaf="">7</span></span><span data-font-family="default"><span leaf="">0</span></span><span data-font-family="default"><span leaf="">0</span></span><span data-font-family="default"><span leaf="">1</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">以及</span></span><span data-font-family="default"><span leaf="">NIST</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">IPDRR</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">防护</span></span><span data-font-family="default"><span leaf="">体系</span></span><span data-font-family="default"><span leaf="">及</span></span><span data-font-family="default"><span leaf="">模型</span></span><span data-font-family="default"><span leaf="">均</span></span><span data-font-family="default"><span leaf="">已经</span></span><span data-font-family="default"><span leaf="">无法</span></span><span data-font-family="default"><span leaf="">有效</span></span><span data-font-family="default"><span leaf="">覆盖</span></span><span data-font-family="default"><span leaf="">新的</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">在此</span></span><span data-font-family="default"><span leaf="">背景</span></span><span data-font-family="default"><span leaf="">之下</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">我们</span></span><span data-font-family="default"><span leaf="">建议</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">应急预案</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">以</span></span><span data-font-family="default"><span leaf="">应对</span></span><span data-font-family="default"><span leaf="">业务</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">应用</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">后</span></span><span data-font-family="default"><span leaf="">出现</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">各类</span></span><span data-font-family="default"><span leaf="">高</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">场景</span></span><span data-font-family="default"><span leaf="">。</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">参考</span></span><span data-font-family="default"><span leaf="">措施</span></span><span data-font-family="default"><span leaf="">：</span></span><span data-font-family="default"><span leaf="">针对</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">代码</span></span><span data-font-family="default"><span leaf="">执行</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">组件</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">0</span></span><span data-font-family="default"><span leaf="">day</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">场景</span></span><span data-font-family="default"><span leaf="">构建</span></span><span data-font-family="default"><span leaf="">防护</span></span><span data-font-family="default"><span leaf="">预</span></span><span data-font-family="default"><span leaf="">案</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">如</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">内存</span></span><span data-font-family="default"><span leaf="">隔离</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">沙箱</span></span><span data-font-family="default"><span leaf="">环境</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">以</span></span><span data-font-family="default"><span leaf="">防范</span></span><span data-font-family="default"><span leaf="">层出</span></span><span data-font-family="default"><span leaf="">不穷</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">Prom</span></span><span data-font-family="default"><span leaf="">pt</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">RCE</span></span><span data-font-family="default"><span leaf="">注入</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">Agent</span></span><span data-font-family="default"><span leaf="">客户端</span></span><span data-font-family="default"><span leaf="">等</span></span><span data-font-family="default"><span leaf="">攻击</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">以</span></span><span data-font-family="default"><span leaf="">避免</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">业务</span></span><span data-font-family="default"><span leaf="">在</span></span><span data-font-family="default"><span leaf="">应用</span></span><span data-font-family="default"><span leaf="">AI</span></span><span data-font-family="default"><span leaf="">能力</span></span><span data-font-family="default"><span leaf="">后</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">安全</span></span><span data-font-family="default"><span leaf="">处于</span></span><span data-font-family="default"><span leaf="">被动</span></span><span data-font-family="default"><span leaf="">局面</span></span><span data-font-family="default"><span leaf="">。</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">从</span></span><span data-font-family="default"><span leaf="">CVE停摆后可能导致的漏洞信息失控扩散，</span></span><span data-font-family="default"><span leaf="">到</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">时代</span></span><span data-font-family="default"><span leaf="">漏洞</span></span><span data-font-family="default"><span leaf="">攻击面</span></span><span data-font-family="default"><span leaf="">的非线性增长，2025年上半年，漏洞生态持续呈现着无序性爆发趋势，</span></span><span data-font-family="default"><span leaf="">几乎</span></span><span data-font-family="default"><span leaf="">可</span></span><span data-font-family="default"><span leaf="">用</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">“</span></span><span data-font-family="default"><span leaf="">熵</span></span><span data-font-family="default"><span leaf="">裂</span></span><span data-font-family="default"><span leaf="">”</span></span><span style="white-space: pre-wrap;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">来</span></span><span data-font-family="default"><span leaf="">形容</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">对于企业而言，</span></span><span data-font-family="default"><span leaf="">为</span></span><span data-font-family="default"><span leaf="">了</span></span><span data-font-family="default"><span leaf="">弥合</span></span><span data-font-family="default"><span leaf="">环境</span></span><span data-font-family="default"><span leaf="">变化</span></span><span data-font-family="default"><span leaf="">带来</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">安全裂缝</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">唯有构建主动防御、弹性响应的防御机制，</span></span><span data-font-family="default"><span leaf="">做好</span></span><span data-font-family="default"><span leaf="">准备</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">才能</span></span><span data-font-family="default"><span leaf="">持续保障业务安全</span></span><span data-font-family="default"><span leaf="">。</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-size:10pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><div data-tools="135编辑器" data-id="93344" data-color="#00a3df" data-custom="#00a3df" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: 微软雅黑;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;border-width: 0px;border-style: none;border-color: initial;" data-pm-slice="0 0 []"><div data-width="100%" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;vertical-align: top;border-bottom: 1px dashed rgb(0, 163, 223);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(0, 163, 223);border-top-right-radius: 0px;border-left-width: 0px;width: 677px;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 10px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><div data-width="96%" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;width: 630.073px;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px 0px;border-color: rgb(0, 163, 223);border-radius: 0px;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;color: rgb(0, 163, 223);"><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;clear: both;min-height: 1em;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="font-weight: bold;">关于报告数据源</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;"><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span data-font-family="default"><span leaf="">本</span></span><span data-font-family="default"><span leaf="">文</span></span><span data-font-family="default"><span leaf="">中</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">数据</span></span><span data-font-family="default"><span leaf="">源</span></span><span data-font-family="default"><span leaf="">主要</span></span><span data-font-family="default"><span leaf="">来源</span></span><span data-font-family="default"><span leaf="">于</span></span><span data-font-family="default"><span leaf="">腾讯云安全自研漏洞</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">监测平台，</span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">覆盖全球</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">1</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">0</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">0</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">0</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">+</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">原始漏洞发布渠道，</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">通过</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">动态</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">采集</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">来自暗网、互联网等不同渠道发布的不同语种漏洞上下文信息</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">，</span></span></span><span data-font-family="default"><span leaf="">借助</span></span><span data-font-family="default"><span leaf="">AI</span></span><span style="white-space:pre-wrap;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span data-font-family="default"><span leaf="">对</span></span><span data-font-family="default"><span leaf="">这些</span></span><span data-font-family="default"><span leaf="">信息进行</span></span><span data-font-family="default"><span leaf="">二次</span></span><span data-font-family="default"><span leaf="">分析</span></span><span data-font-family="default"><span leaf="">、</span></span><span data-font-family="default"><span leaf="">入库</span></span><span data-font-family="default"><span leaf="">和</span></span><span data-font-family="default"><span leaf="">智能</span></span><span data-font-family="default"><span leaf="">研判</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">从而</span></span><span data-font-family="default"><span leaf="">形成</span></span><span data-font-family="default"><span leaf="">基准</span></span><span data-font-family="default"><span leaf="">情报库</span></span><span data-font-family="default"><span leaf="">，</span></span><span data-font-family="default"><span leaf="">这些</span></span><span data-font-family="default"><span leaf="">基准</span></span><span data-font-family="default"><span leaf="">情报</span></span><span data-font-family="default"><span leaf="">最后</span></span><span data-font-family="default"><span leaf="">通过</span></span><span data-font-family="default"><span leaf="">人工</span></span><span data-font-family="default"><span leaf="">快速</span></span><span data-font-family="default"><span leaf="">研判</span></span><span data-font-family="default"><span leaf="">形成情报基础元数据库。</span></span></p></div></div></div></div><p style="margin-bottom: 8px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-top: 0px;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">关于腾讯云安全</span></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;line-height: 2;letter-spacing: 1px;visibility: visible;" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-variant-emoji: normal;letter-spacing: 0.544px;line-height: 25.6px;widows: 1;visibility: visible;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">腾讯云安全团队，是一支专注于云领域前沿安全技术研究与创新、安全漏洞研究和处置、云架构和解决方案规划设计和云安全防御能力构建的团队。</span></span><span style="font-size:10pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">基于腾讯安全积累的海量威胁数据以及多年攻防对抗及安全运营经验，我们不仅帮助企业解决漏洞优先级排序难题，还致力于提供漏洞情报、暴露面管理、防御验证以及各类云原生安全产品，帮助所有企业安全团队以更快、更高效的速度获取、检测、防御、修复各类漏洞风险。</span></span><span style="font-size:10pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf="">我们深知，在行业中，防御者需要更优质、更快速地获取安全威胁态势数据。因此，我们致力于为市场提供这样的服务。我们提供关于漏洞管理、漏洞利用以及主要趋势的关键洞察，这些洞察可以通过我们的数据集推断出来，从而支持从业者</span></span><span data-font-family="default"><span leaf="">更</span></span><span data-font-family="default"><span leaf="">好</span></span><span data-font-family="default"><span leaf="">的</span></span><span data-font-family="default"><span leaf="">开展</span></span><span data-font-family="default"><span leaf="">企业</span></span><span data-font-family="default"><span leaf="">风险</span></span><span data-font-family="default"><span leaf="">管理</span></span><span data-font-family="default"><span leaf="">。</span></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-size:10pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="margin: 0px 0px 16px;padding: 0px;border: 0px;font: 400 15px / 1.6 -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, Roboto, Ubuntu, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, &#34;Source Han Sans CN&#34;, sans-serif;vertical-align: baseline;word-break: break-all;overflow-wrap: break-word;white-space: break-spaces;color: rgb(0, 0, 0);letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">了解</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">更多</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">腾讯</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">漏洞</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">情报</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">服务</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">请</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">联系</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">vul</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">n</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">_</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">i</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">n</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">t</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">e</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">l</span></span></span><span data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">@tencent.com</span></span></span></p></div></div></div></div></div></div></div></div></div></div></div><div data-role="outer" data-lazy-bgimg="https://mmbiz.qpic.cn/mmbiz_png/7QRTvkK2qC4bpSQicpqMN82g7At53DQLBRLQ2ABo8ekbheKN2wEibo9BJyYFx8DOk9K3GBEgrB2dXU02wK4fOfnA/640?wx_fmt=jpeg" data-fail="0" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 0.544px;background-size: auto;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/7QRTvkK2qC4bpSQicpqMN82g7At53DQLBRLQ2ABo8ekbheKN2wEibo9BJyYFx8DOk9K3GBEgrB2dXU02wK4fOfnA/640?wx_fmt=jpeg&amp;tp=webp&amp;wxfrom=15&amp;wx_lazy=1&#34;);font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;background-position: left top;background-repeat: repeat;"><div data-tools="135编辑器" data-id="101592" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;line-height: 1.5em;"><h2 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">参考链接</span></span></span><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></h2><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">CVE漏洞库：</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;text-decoration:underline;color:#1E6FFF;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><a href="https://www.cve.org/" target="_blank">https://www.cve.org/</a></span></span><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">卡巴斯基季度分析报告：</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;text-decoration:underline;color:#1E6FFF;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">Vulnerability landscape analysis for Q1 2025 | Securelist</span></span><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">Fortinet 2025 全球</span></span><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">安全</span></span><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">威胁</span></span><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">报告</span></span><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">：</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;text-decoration:underline;color:#1E6FFF;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">Fortinet 2025 Global Threat Landscape Report</span></span><span style="font-size:9pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:9pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><h2 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">附录A：腾讯安全每月必修漏洞合集</span></span></span><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></h2><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;text-decoration:underline;color:#1E6FFF;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><a class="normal_text_link album" target="_blank" style="color: rgb(30, 111, 255);" href="https://mp.weixin.qq.com/mp/appmsgalbum?__biz=MzkzNTI4NjU1Mw==&amp;action=getalbum&amp;album_id=2587721104576970755#wechat_redirect" textvalue="" linktype="text" data-linktype="2"><a href="https://mp.weixin.qq.com/mp/appmsgalbum?__biz=MzkzNTI4NjU1Mw==&amp;action=getalbum&amp;album_id=2587721104576970755#wechat_redirect" target="_blank">https://mp.weixin.qq.com/mp/appmsgalbum?__biz=MzkzNTI4NjU1Mw==&amp;action=getalbum&amp;album_id=2587721104576970755#wechat_redirect</a></a></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#262626;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><h4 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">附录</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">1</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">:</span></span><span style="white-space:pre-wrap;font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">精选必修漏洞</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">列表</span></span></h4><table style="max-width:100% !important;box-sizing:border-box;min-width:178px;"><tbody><tr style="height:27px;"><td data-colwidth="153" style="border: 1px solid rgb(203, 205, 209);background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">腾讯云安全编号</span></span></strong></span></p></td><td style="border-top: 1px solid rgb(203, 205, 209);border-right: 1px solid rgb(203, 205, 209);border-bottom: 1px solid rgb(203, 205, 209);border-image: initial;border-left: none;background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">漏洞名</span></span></strong></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-4244</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Weblogic Server T3/IIOP </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程命令执行漏洞（CVE-2025-21535）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-37498</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Redis </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞（CVE-2024-46981）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-38322</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">FortiOS</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">和FortiProxy 认证绕过漏洞（CVE-2024-55591）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-15734</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Fortinet</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">多款产品 身份认证绕过漏洞 (CVE-2025-22252)</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-5768</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Palo Alto Networks PAN-OS Management </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">权限绕过漏洞（CVE-2025-0108）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-8767</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Vite </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">任意文件读取漏洞（CVE-2025-30208）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-10018</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Vite </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">任意文件读取漏洞（CVE-2025-31486）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-11706</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Vite </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">任意文件读取漏洞（CVE-2025-32395）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-8798</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Kubernetes Ingress-nginx </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞（CVE-2025-1974）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-7626</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Apache Tomcat </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞（CVE-2025-24813）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-17316</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Apache Commons BeanUtils </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞(CVE-2025-48734)</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-18703</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Apache Kafka Client </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">任意文件读取漏洞（CVE-2025-27817）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-8557 </span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Next.js </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">中间件授权绕过漏洞（CVE-2025-29927）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-10575</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Ivanti</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">多款产品 远程代码执行漏洞（CVE-2025-22457）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-15482</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Ivanti Endpoint Manager Mobile</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">代码执行漏洞   (CVE-2025-4428)</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-3272</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Ivanti</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">多款产品 远程代码执行漏洞（CVE-2025-0282）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-14480</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Kibana </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">原型污染远程代码执行漏洞（CVE-2025-25014）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-17050</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">vBulletin replaceAdTemplate </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞(CVE-2025-48827)</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-15174</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">kkfileview fileUpload </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">文件上传漏洞(CVE-2025-4538)</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-17818</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">DataEase </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞（CVE-2025-49002）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-17815</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">DataEase Redshift JDBC</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞(CVE-2025-48999)</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-18865</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">GeoServer XML</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">外部实体注入漏洞（CVE-2025-30220）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-42406</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Gogs </span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">远程代码执行漏洞（CVE-2024-56731）</span></span></p></td></tr><tr><td data-colwidth="153" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-18806</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">Windows SMB Client</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">权限提升漏洞（CVE-2025-33073）</span></span></p></td></tr></tbody></table><h4 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span></h4><h4 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">附录</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">2</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">: </span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">重保季场景常见国产组件的漏洞</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">列表</span></span></h4><table style="max-width:100% !important;box-sizing:border-box;min-width:185px;"><tbody><tr style="height:27px;"><td data-colwidth="160" style="border: 1px solid rgb(203, 205, 209);background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">腾讯云安全编号</span></span></strong></span></p></td><td style="border-top: 1px solid rgb(203, 205, 209);border-right: 1px solid rgb(203, 205, 209);border-bottom: 1px solid rgb(203, 205, 209);border-image: initial;border-left: none;background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">漏洞名</span></span></strong></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-5646</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">泛微e-office   upload.php 文件上传漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-11945</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">泛微e-cology 远程代码执行漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-18667</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">泛微e-office SignatureDel.php   SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-19751</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">泛微e-cology SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-19163</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">契约锁电子签章系统 远程代码执行漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-7297</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">宝兰德BES 远程代码执行漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-3028</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">蓝凌EIS智慧协同平台 SQL注入漏洞(CVE-2025-22214)</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20463</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20464</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">万户ezOFFICE 多个SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-32801</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20465</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">万户ezEIP 多个SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2025-20723</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">用友NC importTemplate 接口存在XML实体注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-3253</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20454</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20468</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-19894</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20469</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-19896</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-18664</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20470</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20471</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-11421</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-27761     </span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-9663</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-3299</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20472</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20473</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20474</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">用友NC 多个SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-17485</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">用友U8 Cloud console.loadRes.d 任意文件读取漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-17277</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-16354</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2024-33495</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20475</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">用友U8 CRM 多个SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-13226</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20476</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-19906</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">宏景人力资源管理系统 多个SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-12284</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">时空智友企业流程化管控系统 indexService.notice SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20477</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">时空智友企业流程化管控系统 startUpdateStudio XML实体注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20478</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">时空智友企业流程化管控系统 updater.getStudioFile 任意文件读取漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-8548</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-19902</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">金和OA C6 多个SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-19901</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">信呼OA   openkqjAction SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-13136</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">信呼OA uploawAction.php SQL注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-6894</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">亿赛通电子文档安全管理系统 SQL注入漏洞（CVE-2025-1841）</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-6896</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">亿赛通电子文档安全管理系统 SQL注入漏洞（CVE-2025-1840）</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-3037</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">大华智能物联综合管理平台   GetClassValue 远程代码执行</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-17278</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">灵当CRM Playforrecord.php 任意文件读取漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-6225</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20462</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">灵当CRM 多个文件上传漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20466</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">美特CRM fileUpAndDown 反序列化漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-20467</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">美特CRM   getFile 任意文件读取与反序列化漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-8900</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">锐捷-EWEB timeout.php 命令注入漏洞</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-6138</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">百易云资产管理运营系统   SQL注入漏洞（CVE-2025-1464）</span></span></p></td></tr><tr><td data-colwidth="160" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">TVD-2025-6443</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">IBOS</span></span><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">企业协同管理软件   main/api/OrgUser SQL注入漏洞</span></span></p></td></tr></tbody></table><h4 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">附录</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">3</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">: </span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">高活跃度的历史漏洞</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">列表</span></span></h4><table style="max-width:100% !important;box-sizing:border-box;min-width:166px;"><tbody><tr style="height:27px;"><td data-colwidth="141" style="border: 1px solid rgb(203, 205, 209);background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">腾讯云安全编号</span></span></strong></span></p></td><td style="border-top: 1px solid rgb(203, 205, 209);border-right: 1px solid rgb(203, 205, 209);border-bottom: 1px solid rgb(203, 205, 209);border-image: initial;border-left: none;background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">漏洞名</span></span></strong></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2015-10778</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Redis</span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">未授权访问漏洞</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2015-15196</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Redis </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">主从复制导致RCE漏洞</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2023-23460</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">XXL-JOB </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">默认 accessToken 身份绕过远程代码执行漏洞</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2022-23011</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Fastjson </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">相关漏洞利用/探测过程</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2021-23017</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Apache log4j2 </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">远程代码执行漏洞（CVE-2021-44228）</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2025-6744</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Memos SSRF</span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">漏洞</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2023-17905</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Jeecg-Boot JimuReport queryFieldBySql </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">模板注入漏洞(CVE-2023-4450)</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2016-7662</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Apache Shiro</span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">默认Key远程命令执行漏洞(CVE-2016-4437)</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2021-10036</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">PbootCMS</span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">存在命令执行漏洞（CNVD-2021-33224）</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2021-21307</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Jenkins </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">未授权/弱口令 访问导致RCE</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2023-22932</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Apache ActiveMQ</span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">远程代码执行漏洞(CVE-2023-46604)</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2024-19603</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">nacos derby </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">远程代码执行漏洞</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2021-27100</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Alibaba Sentinel</span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">服务器端请求伪造漏洞(CVE-2021-44139）</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2023-11634</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Apache RocketMQ </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">远程代码执行漏洞(CVE-2023-33246)</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2019-5088</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">PostgreSQL </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">操作系统命令注入漏洞</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2019-15222</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Apache Flink </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">任意Jar包上传导致远程代码执行漏洞</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2018-23804</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Node-RED</span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">未授权远程命令执行漏洞</span></span></p></td></tr><tr><td data-colwidth="141" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">TVD-2017-13637</span></span></p></td><td style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">Weblogic XMLDecoder </span></span><span style="font-size: 13px;line-height: 130%;color: black;letter-spacing: 1px;font-family: 等线;"><span leaf="">反序列化漏洞(CVE-2017-10271)</span></span></p></td></tr></tbody></table><h4 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">附录</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">4</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">: </span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">云</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">原生</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">&amp;</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">AI</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">&amp;</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">国产</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">系统</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">领域</span></span><span style="white-space:pre-wrap;font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">TOP漏洞</span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#1A1A1A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">列表</span></span></h4><table style="max-width:100% !important;box-sizing:border-box;width:537px;"><tbody><tr style="height:27px;"><td data-colwidth="103" style="border: 1px solid rgb(203, 205, 209);background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">风险领域</span></span></strong></span></p></td><td data-colwidth="102" style="border-top: 1px solid rgb(203, 205, 209);border-right: 1px solid rgb(203, 205, 209);border-bottom: 1px solid rgb(203, 205, 209);border-image: initial;border-left: none;background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">攻防热度</span></span></strong></span></p></td><td data-colwidth="134" style="border-top: 1px solid rgb(203, 205, 209);border-right: 1px solid rgb(203, 205, 209);border-bottom: 1px solid rgb(203, 205, 209);border-image: initial;border-left: none;background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">漏洞名</span></span></strong></span></p></td><td data-colwidth="198" style="border-top: 1px solid rgb(203, 205, 209);border-right: 1px solid rgb(203, 205, 209);border-bottom: 1px solid rgb(203, 205, 209);border-image: initial;border-left: none;background: rgb(41, 114, 244);box-sizing: border-box;padding: 5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;"><strong><span style="color: white;letter-spacing: 1px;font-size: 14px;font-family: 等线;"><span leaf="">防护建议</span></span></strong></span></p></td></tr><tr><td data-colwidth="103" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"></span><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">云原生组件 </span></span></p></td><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★★★</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">K8s   Ingress RCE (CVE-2025-1974)</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">1. </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">Releases   · kubernetes/ingress-nginx · GitHub</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">2. </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">临时缓解方案：</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">- </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">对Admission   Controller进行访问控制。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">- </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">在不影响业务的情况下，关闭Ingress-nginx的验证注册控制器功能。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">1) </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">对于使用Helm安装的Ingress-nginx，重新安装并设置Helm属性为&#34;controller.admissionWebhooks.enabled=false&#34;</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">2) </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">对于手动安装的Ingress-nginx，删除名为ingress-nginx-admission的ValidatingWebhook配置。编辑ingress-nginx-controller的Deployment 或 Daemonset，从控制器容器的参数列表中删除&#34;--validating-webhook&#34;</span></span></p></td></tr><tr><td rowspan="5" data-colwidth="103" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"></span><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">国产化系统 </span></span></p></td><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★★★</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">泛微e-cology 远程代码执行漏洞（TVD-2025-11945）</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本泛微ECOLOGY安全补丁包下载</span></span></p></td></tr><tr><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★★☆</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">泛微e-cology SQL注入漏洞（TVD-2025-19751）</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本泛微ECOLOGY安全补丁包下载</span></span></p></td></tr><tr><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★★★</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">契约锁电子签章系统远程代码执行漏洞（TVD-2025-19163）</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">契约锁安全补丁</span></span></p></td></tr><tr><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★★★</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">宝兰德BES远程代码执行漏洞（TVD-2025-7297）</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请联系官方人员获取补丁，并评估业务是否受影响后，升级至安全版本。北京宝兰德软件股份有限公司</span></span></p></td></tr><tr><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★☆</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">用友NC   importTemplate 接口存在XML实体注入漏洞（TVD-2025-20723）</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请联系官方人员获取补丁，并评估业务是否受影响后，升级至安全版本。</span></span><span style="font-family: 等线;"><span leaf="">用友安全中心</span></span></p></td></tr><tr><td rowspan="5" data-colwidth="103" style="border-right: 1px solid #cbcdd1;border-bottom: 1px solid #cbcdd1;border-left: 1px solid #cbcdd1;border-image: initial;border-top: none;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf=""> AI</span></span><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">基础设施 </span></span></p></td><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★★★</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">Anyscale   Ray </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">命令执行漏洞（CVE-2024-57000/CVE-2023-48022）</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方暂未发布漏洞补丁及修复版本，请持续关注官方动态。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">临时缓解方案：</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">- </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">避免将Anyscale   Ray开放至公网</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">- </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">利用安全组设置仅对可信地址开放</span></span></p></td></tr><tr><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★★☆</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">Langflow </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">远程代码执行漏洞（CVE-2025-3248）</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf=""><a href="https://github.com/langflow-ai/langflow/releases/" target="_blank">https://github.com/langflow-ai/langflow/releases/</a></span></span></p></td></tr><tr><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★★</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">LlamaIndex   SQL</span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">注入导致命令执行漏洞（CVE-2024-11958）</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">Releases   · run-llama/llama_index · GitHub</span></span></p></td></tr><tr><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★★</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">FlowiseAI Flowise </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">文件上传漏洞（CVE-2025-26319）</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;background: #e5efff;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">1. </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">Releases ·   FlowiseAI/Flowise · GitHub</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">2. </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">缓解措施：</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">- </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">如非必要，不对公网开放相关服务。 </span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">- </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">使用防火墙、安全组白名单等措施，对相关服务进行访问限制。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">- </span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">通过 WAF 等安全设备设置访问策略，设置⽩名单访问或避免 /api/v1/attachments 接口对外暴露。</span></span></p></td></tr><tr><td data-colwidth="102" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 14px;line-height: 130%;color: black;font-family: 等线;"><span leaf="">★★★☆</span></span></p></td><td data-colwidth="134" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">vLLM   PyNcclPipe pickle</span></span><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">反序列化漏洞 (CVE-2025-47277)</span></span></p></td><td data-colwidth="198" style="border-top: none;border-left: none;border-bottom: 1px solid #cbcdd1;border-right: 1px solid #cbcdd1;padding:5px 10px;"><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本。</span></span></p><p style="text-align: left;"><span style="font-size: 13px;line-height: 130%;font-family: 等线;"><span leaf="">Releases ·   vllm-project/vllm · GitHub</span></span></p></td></tr></tbody></table></div></div></div><div data-role="outer" data-lazy-bgimg="https://mmbiz.qpic.cn/mmbiz_png/7QRTvkK2qC4bpSQicpqMN82g7At53DQLBRLQ2ABo8ekbheKN2wEibo9BJyYFx8DOk9K3GBEgrB2dXU02wK4fOfnA/640?wx_fmt=jpeg" data-fail="0" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-size: auto;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/7QRTvkK2qC4bpSQicpqMN82g7At53DQLBRLQ2ABo8ekbheKN2wEibo9BJyYFx8DOk9K3GBEgrB2dXU02wK4fOfnA/640?wx_fmt=jpeg&amp;tp=webp&amp;wxfrom=15&amp;wx_lazy=1&#34;);font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;background-position: left top;background-repeat: repeat;" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="101592" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;line-height: 1.5em;"><div hm_fix="385:564" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;flex-direction: column;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;width: 32px;"><img data-width="100%" alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="0.8768115942028986" data-type="gif" data-w="276" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;display: block;visibility: visible !important;width: 32px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=04d5857b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FFIBZec7ucChYUNicUaqntiamEgZ1ZJYzLRasq5S6zvgt10NKsVZhejol3iakHl3ItlFWYc8ZAkDa2lzDc5SHxmqjw%2F640%3Fwx_fmt%3Dgif%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1"/></p><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px 0em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 1.5px;color: rgb(52, 110, 183);"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">END</span></strong></p></div></div></div></div><div data-role="paragraph" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(163, 163, 163);text-align: center;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><div data-role="paragraph" data-color="#1e9be8" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-id="86318" data-tools="135编辑器" data-color="#3d8ed1" data-custom="#3d8ed1" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: transparent;margin: 10px auto 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-indent: 0em;line-height: 1.5em;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;align-items: center;display: flex;justify-content: center;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 5px 1em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(51, 51, 51);border-radius: 20px;color: rgb(255, 255, 255);letter-spacing: 1.5px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">更多精彩内容点击下方扫码关注哦~</span></p></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 10px 8px 15px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-variant-numeric: normal;font-variant-east-asian: normal;text-align: center;color: rgb(163, 163, 163);letter-spacing: 0.54px;min-height: 1em;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;letter-spacing: 0.54px;text-indent: 0em;caret-color: red;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关注云鼎实验室，获取更多安全情报</span></span></p><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;"><img data-copyright="0" alt="图片" class="rich_pages wxw-img" data-ratio="0.6" data-s="300,640" data-type="jpeg" data-w="900" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;letter-spacing: 0.54px;width: 673px !important;visibility: visible !important;" data-backw="561" data-backh="337" src="https://wechat2rss.xlab.app/img-proxy/?k=e243880e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FNNSr7XSrt0mfEkibaEU8uriaORBdj9W37EhEIZlIFuzudKVafyia4vTv1q1usxN57bsdeAY4icwcKw9qJ1W4COeR4Q%2F640%3Fwx_fmt%3Djpeg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1"/></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485086">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=caa053a6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkzNTI4NjU1Mw%3D%3D%26mid%3D2247485086%26idx%3D1%26sn%3Dbc3971f9aa5ad6196a727c8fcd5e6dab">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 25 Aug 2025 17:43:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年7月企业必修安全漏洞清单</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&amp;mid=2247485084&amp;idx=1&amp;sn=28aa909a2b6ab85eae2888baf7634a5f</link>
      <description>所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重</description>
      <content:encoded><![CDATA[<p>
<span>云鼎实验室</span> <span>2025-08-14 17:19</span> <span style="display: inline-block;">广东</span>
</p>




<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f0348321&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FNNSr7XSrt0mMatgYJCtGztW2T5vnQqsje08NvBvRYCE8uJEgibiankxEiaLX6ibYgPiaOpwHXzNLg7DRtNFcnNdeTww%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div><div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;visibility: visible;"><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding: 27px;outline: 0px;display: inline-block;width: 663.458px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(78, 132, 216);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: -28px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-right: 5px;padding-bottom: 5px;padding-left: 5px;outline: 0px;display: inline-block;width: 316.219px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 0px 1px 1px;border-color: rgb(62, 62, 62) rgb(78, 132, 216) rgb(78, 132, 216);visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 2px;outline: 0px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 304.885px;height: 5px;background-color: rgb(78, 132, 216);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><br/></span></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-size: 15px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 13px;visibility: visible;"></span></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-size: 15px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 13px;visibility: visible;"></span></p><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);letter-spacing: 0.544px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">所谓必修漏洞，就是运维人员必须修复、不可拖延、影响范围较广的漏洞，被黑客利用并发生入侵事件后，会造成十分严重的后果。</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><br/></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;text-align: left;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf=""><span textstyle="" style="letter-spacing: normal;">腾讯云安全参考“安全漏洞的危害及影响力、漏洞技术细节披露情况、该漏洞在安全技术社区的讨论热度”等因素，综合评估该漏洞在攻防实战场景的风险。当漏洞综合评估为风险严重、影响面较广、技术细节已披露，且被安全社区高度关注时，就将该漏洞列入必修安全漏洞候选清单。 </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">腾讯云安全定期发布安全漏洞必修清单，以此指引企业安全运维人员修复漏洞，从而避免重大损失。 </span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(3, 97, 243);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">以下是2025年7月份必修安全漏洞清单</span></span></strong></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="letter-spacing: normal;">：</span></span></span></p><p data-pm-slice="0 0 []" style="line-height: 1.75em;margin-top: 8px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">一、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">Microsoft SharePoint </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2025-53770</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">）</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="line-height: 1.75em;margin-top: 8px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">二、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> Redis hyperloglog </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">命令远程代码执行漏洞（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2025-32023</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">）</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="line-height: 1.75em;margin-top: 8px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">三、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> NVIDIA Container Toolkit </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">容器逃逸漏洞（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2025-23266) </span></span><o:p></o:p></span></p><p style="line-height: 1.75em;margin-top: 8px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">四、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> Apache Jackrabbit XXE</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2025-53689</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">）</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="line-height: 1.75em;margin-top: 8px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">五、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> Git </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞 </span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">(CVE-2025-48384)</span></span><o:p></o:p></span></p><p style="line-height: 1.75em;margin-top: 8px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">六、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> Linux Kernel </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">拒绝服务漏洞 </span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">(CVE-2025-38089)</span></span><o:p></o:p></span></p><p style="line-height: 1.75em;margin-top: 8px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">七、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> Dify</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞 </span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">(CVE-2025-3466)</span></span><o:p></o:p></span></p><p style="line-height: 1.75em;margin-top: 8px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">八、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">Jenkins Git Parameter</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">插件远程代码执行漏洞 </span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">(CVE-2025-53652)</span></span><o:p></o:p></span></p><p style="line-height: 1.75em;margin-top: 8px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">九、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;"> mcp-remote </span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">操作系统命令注入漏洞（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2025-6514</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">）</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;visibility: visible;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><br/></span></span></p></div></div><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 15px;text-align: justify;color: rgb(3, 97, 243);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 14px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞介绍及修复建议详见后文</span></strong></span></p></div><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-bottom: -40px;outline: 0px;text-align: right;justify-content: flex-end;display: flex;flex-flow: row;transform: translate3d(40px, 0px, 0px);visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(45deg);visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 26px;height: 26px;vertical-align: top;overflow: hidden;border-left: 1px solid rgb(78, 132, 216);border-bottom-left-radius: 0px;visibility: visible;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><br/></span></p></div></div></div></div></div></div></div></div></div></div></div></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">一、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;letter-spacing: 0.544px;visibility: visible;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">Microsoft SharePoint 远程代码执行漏洞</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><o:p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"></o:p></span></strong></p><div data-width="100%" style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;width: 677px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;margin-right: auto;margin-left: auto;padding-top: 1em;outline: 0px;justify-content: center;display: -webkit-flex;visibility: visible;"><p data-bgless="spin" data-bglessp="280" data-bgopacity="70%" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 0.8em;height: 7px;background-color: rgba(68, 139, 255, 0.3);overflow: hidden;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><br/></span></p></div></div></div></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;visibility: visible;"><img data-imgfileid="100012797" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;visibility: visible;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">M</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">icro</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">soft</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 官方发布了关于</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SharePoint </span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，漏洞编号：</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-23630</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"> (CVE编号：</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-53770</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，CNNVD编号：</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202507-2530</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者，</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终可</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">执行</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">任意</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">代码</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">SharePoint是微软开发的协作平台，用于企业信息存储、共享与流程管理。它提供文档库、任务列表、日程安排等功能，支持团队成员在线协作编辑文档、分配任务，还能通过搜索功能快速获取信息。其分为云端服务（如Microsoft 365中的SharePoint）和本地部署版本（SharePoint Server），可集成Office套件及其他第三方应用，满足企业知识管理、流程自动化等需求</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">漏洞</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">为</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">身份验证绕过与反序列化漏洞的串联利用</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">由于</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">身份</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">验证</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">存在</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">缺陷</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">攻击者</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可以</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">通过</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">构造</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">特制</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">请求</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">绕过身份验证访问敏感接口/_layouts/15/ToolPane.aspx</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">利用该接口上传恶意文件窃取服务器的加密密钥</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">随后利用这些密钥生成合法签名的__VIEWSTATE载荷，通过ASP.NET的ViewState反序列化机制执行恶意序列化数据，最终在服务器上实现远程代码执行。</span></span></span></p><p style="margin-bottom: 0px;" data-pm-slice="3 8 []"><b data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 0px;&#34;,&#34;data-pm-slice&#34;:&#34;3 8 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf=""><img data-imgfileid="100012833" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">漏洞状态：</span></span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(255, 255, 255);">类别</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(255, 255, 255);">状态</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">安全补丁</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞细节</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">PoC</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已公开</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">在野利用</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">已发现</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 0px;"><b data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf=""><img data-imgfileid="100012833" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></span><span leaf=""><span textstyle="" style="font-size: 16px;">风险等级：</span></span></b></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(255, 255, 255);">评定方式</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(255, 255, 255);">等级</span></span></span></b><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">威胁等级</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高危</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">影响面</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">攻击者价值</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">高</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">利用难度</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">低</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:17.55pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞评分</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 17.55pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 14px;">9.8</span></span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="font-size: 16px;border-width: 0px;border-style: none;border-color: initial;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;visibility: visible;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><br/></span></span></p><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div data-role="outer" label="Powered by 135editor.com"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012799" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div></div><p><span style="font-size:12pt;font-family:宋体;font-weight:normal;font-style:normal;color:#222222;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></div><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">Microsoft SharePoint </span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">Enterprise</span></span><span style="white-space:pre-wrap;font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">Server 2016 &lt; 16.0.5508.100</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">1</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">Microsoft SharePoint Server 2019 &lt; 16.0.10417.20037</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">Microsoft SharePoint Server Subscription Edition &lt; 16.0.18526.20508</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align: justify;margin: 0pt 0pt 0px;"><span style="font-size: 12pt;font-family: 宋体;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="宋体"><span leaf=""><br/></span></span></p><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012795" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div></div></div><p><span style="font-size:12pt;font-family:宋体;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/" target="_blank">https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/</a></span></span></span><span style="white-space:pre-wrap;font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="DengXian"></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">.</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">临时缓解方案：</span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="DengXian"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 在 SharePoint 中配置反恶意软件扫描接口 (AMSI) 集成，启用完整模式以获得最佳保护，并在所有 SharePoint 服务器上部署 Defender</span></span></span><span style="white-space:pre-wrap;font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Antivirus，这将阻止未经身份验证的攻击者利用此漏洞</span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;"> 部署Defender for Endpoint来检测和阻止漏洞利用后活动</span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="DengXian"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-</span></span></span><span style="white-space:pre-wrap;font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">应用上述最新安全更新或启用AMSI后，客户必须轮换SharePoint服务器ASP.NET 机器密钥并在所有SharePoint服务器上重新启动 IIS</span></span></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">二、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;color: rgb(34, 34, 34);"><span textstyle="" style="color: rgb(0, 82, 255);">Redis hyperloglog 命令远程代码执行漏洞</span></span></span></strong></p><div data-width="100%" style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;width: 677px;"><div style="-webkit-tap-highlight-color: transparent;margin-right: auto;margin-left: auto;padding-top: 1em;outline: 0px;justify-content: center;display: -webkit-flex;"><p data-bgless="spin" data-bglessp="280" data-bgopacity="70%" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 0.8em;height: 7px;background-color: rgba(68, 139, 255, 0.3);overflow: hidden;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br/></span></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012800" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到关于</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">R</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">edi</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">s</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的风险公告，</span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">漏洞编号为</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-21810</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"> (CVE</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">2025-32023</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD编号</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202507-709</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span></span></span><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，最终可</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">远程执行任意代码</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">Redis是开源的高性能键值存储系统，支持内存存储与持久化，具备丰富数据结构（如字符串、列表、有序集合、HyperLogLog等）和高级特性（事务、Lua脚本、发布订阅等）。它以内存操作为核心，单节点读写速度可达10万+次/秒，通过主从复制、哨兵模式或集群架构实现高可用与扩展性，广泛应用于缓存、消息队列、分布式锁、实时统计等场景，同时支持多种编程语言客户端，具备灵活的配置和强大的生态系统</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">据描述</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">该漏洞源于Redis在解析HyperLogLog数据结构时存在代码实现缺陷，经过身份验证的本地用户可通过构造恶意字符串，在执行HyperLogLog相关操作时触发堆栈或堆内存的越界写入，</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">导致远程代码执行。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><img data-imgfileid="100012804" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/>漏洞状态：</span></strong></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;width:548px;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">安全补丁</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">漏洞细节</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">PoC</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align: center;margin-bottom: 0px;"><span style="font-size: 10pt;color: black;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size: 10pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">在野利用</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align: center;margin-bottom: 0px;"><span style="font-size: 10pt;color: black;"><span leaf="">未发现</span></span><span lang="EN-US" style="font-size: 10pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;outline: 0px;margin-top: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><img data-imgfileid="100012801" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/>风险等级：</span></strong></strong></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">威胁等级</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高危</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">影响面</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">攻击者价值</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">利用难度</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">中</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">漏洞评分</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">7.0</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-tap-highlight-color: transparent;outline: 0px;"><br/></span></span></p><div data-tplid="92935" data-tools="135编辑器" data-pm-slice="0 0 []" style="margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tplid&#34;:&#34;92935&#34;,&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;border-width: 0px;border-style: none;border-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;margin-top: 0px;"><img data-imgfileid="100012803" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div></div><p><span style="font-size:12pt;font-family:宋体;font-weight:bold;font-style:normal;color:#222222;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></div><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">2.8 &lt;= Redis &lt; 6.2.19</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">7.2.</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">0</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf=""> &lt;= Redis &lt; 7.2.10</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">7.4.</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">0</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf=""> &lt;= Redis &lt; 7.4.5</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">8.0.</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">0</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf=""> &lt;= Redis &lt; 8.0.3</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p><span leaf=""> </span></o:p></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;margin-top: 0px;"><img data-imgfileid="100012802" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=475616d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgppKsWWD2v5KKg5WV1ibGa2aQqoicqDfqzAAZtNibAV2jQAAnIkWwibkECkg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></p></div></div></div><p><span style="font-size:12pt;font-family:宋体;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></div><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">1.</span></span></span><span style="white-space:pre-wrap;font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，酌情升级至安全版本。</span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">【备注】：建议您在升级前做好数据备份工作，避免出现意外。</span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#333333;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);"><a href="https://github.com/redis/redis/releases" target="_blank">https://github.com/redis/redis/releases</a></span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;text-decoration:underline;color:#0563C1;background:#FFFFFF;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="DengXian"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">2. 临时缓解方案</span></span></span><span data-font-family="DengXian"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">：</span></span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span data-font-family="DengXian"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">-</span></span></span><span style="white-space:pre-wrap;font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="DengXian"></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">阻止用户执行hyperloglog操作</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可以使用ACL限制HLL命令来实现。</span></span></span></p></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;border-width: 0px;border-style: none;border-color: initial;line-height: 1.75em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(51, 51, 51);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><br/></span></p></div><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin-left: 27.75pt;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;margin-bottom: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">三、</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);"> </span></span></span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-weight: bold;font-size: 12pt;color: rgb(34, 34, 34);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 12pt;"><span textstyle="" style="color: rgb(0, 82, 255);">NVIDIA Container Toolkit 容器逃逸漏洞</span></span></span></strong></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012807" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="30" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab0cfc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYUyZ7AOL3one41I6gqD2FtlJX2bnKQunF2Xm0FAciaaTgsV6iaq9Z7X2CYKVuvCAmYXr4w8RowkosXRR2fZZvumA%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞概述</span></strong></p></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;" data-pm-slice="0 0 []"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">腾讯云安全近期监测到</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">NVIDIA</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">官方发布了关于</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">NVIDIA Container Toolkit</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">的</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">风险公告，漏洞编号为</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">TVD-2025-23458</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">(CVE</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">编号：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CVE-2025-23266</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD编号</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">：</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">CNNVD-202507-2344</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;color: rgb(0, 82, 255);">)</span><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。成功利用此漏洞的攻击者</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">可</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">获取</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">root</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">权限</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。 </span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">NVIDIA Container Toolkit是NVIDIA官方推出的工具链，用于在容器环境中高效、安全地使用GPU资源。它通过标准化、自动化的方式，将GPU设备、驱动库（如CUDA、cuDNN）与容器生态无缝集成，支持Docker、Containerd等多种容器运行时，实现GPU的“直通”访问，避免虚拟化带来的性能损耗，是构建GPU加速应用的核心方案。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;outline: 0px;line-height: 1.75em;"><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">NVIDIA Container Toolkit注册的createContainer钩子会默认继承容器镜像的环境变量，且其工作目录被设置为容器的根文件系统；攻击者通过构建恶意Dockerfile即可诱导该钩子从容器文件系统加载预置的恶意共享库到宿主机的特权进程中，从而绕过容器隔离并获得宿主机root权限，</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">最终</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">实现容器逃逸</span></span></span><span data-font-family="等线"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: black;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">。</span></span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><img data-imgfileid="100012808" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/>漏洞状态：</span></strong></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;width:548px;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">类别</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">状态</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">安全补丁</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">漏洞细节</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">PoC</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">已公开</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">在野利用</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 20.25pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">未发现</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;outline: 0px;margin-top: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><img data-imgfileid="100012809" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="512" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3e21e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpctyZ81h7UIw8chftfeznx7jLATIbpichqGjibViaIfHNIFcLjcicCzrnoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/>风险等级：</span></strong></strong></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border: 1pt solid windowtext;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">评定方式</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><b><span style="font-size:10.0pt;color:white;mso-themecolor:background1;"><span leaf="">等级</span></span></b><span lang="EN-US" style="font-size:10.0pt;color:white;mso-themecolor:background1;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">威胁等级</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高危</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">影响面</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:18.65pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">攻击者价值</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.65pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">高</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:18.3pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">利用难度</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 18.3pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">低</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;height:16.4pt;"><td data-colwidth="274" width="274" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">漏洞评分</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td><td data-colwidth="274" width="274" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;background: white;padding: 0cm 5.4pt;height: 16.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:10.0pt;color:black;mso-color-alt:windowtext;"><span leaf="">9.0</span></span><span lang="EN-US" style="font-size:10.0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span leaf=""><br/></span></p><div style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;"><div style="-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;align-items: center;display: -webkit-flex;justify-content: flex-start;" data-pm-slice="2 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;border-width: 0px;border-style: none;border-color: initial;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;padding-top: 10px;padding-bottom: 10px;outline: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;width: 25px;"><img data-imgfileid="100012806" alt="图片" class="rich_pages wxw-img" data-ratio="0.9700854700854701" data-s="300,640" data-type="png" data-w="234" style="-webkit-tap-highlight-color: transparent;margin-top: 5px;outline: 0px;vertical-align: inherit;width: 25px !important;visibility: visible !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/NNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="25" data-cropsely2="25" src="https://wechat2rss.xlab.app/img-proxy/?k=785e8e85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FNNSr7XSrt0mI3Hn04TDicQGeRhYXPRSgpyMmKHz3l49YYK3IFIpeUDAZH9ywjHBPia1R5aGb9LIdQb0yYtqAPqAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></p><div style="-webkit-tap-highlight-color: transparent;margin-left: 4px;outline: 0px;display: inline-block;"><p data-brushtype="text" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;color: rgb(63, 62, 63);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">影响版本</span></strong></p></div></div></div><p><span style="font-size:12pt;font-family:宋体;font-weight:normal;font-style:normal;color:#222222;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p></div><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">NVIDIA Container Toolkit &lt;= 1.17.7</span></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" lang="EN-US"><o:p></o:p></span></p><p style="text-align:justify;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf="">NVIDIA GPU Operator</span></span><span style="white-space:pre-wrap;font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;letter-spacing:0.4pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"></span><span style="font-size:10.5pt;font-family:等线;font-weight:normal;font-style:normal;color:#222222;letter-sp