[ { "id": 265151514, "name": "tomcat-cluster-session-sync-exp", "full_name": "threedr3am\/tomcat-cluster-session-sync-exp", "owner": { "login": "threedr3am", "id": 19884279, "avatar_url": "https:\/\/avatars0.githubusercontent.com\/u\/19884279?v=4", "html_url": "https:\/\/github.com\/threedr3am" }, "html_url": "https:\/\/github.com\/threedr3am\/tomcat-cluster-session-sync-exp", "description": "tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484是session持久化的洞,这个是session集群同步的洞!", "fork": false, "created_at": "2020-05-19T05:12:53Z", "updated_at": "2020-05-28T02:09:52Z", "pushed_at": "2020-05-19T05:13:19Z", "stargazers_count": 178, "watchers_count": 178, "forks_count": 31, "forks": 31, "watchers": 178, "score": 0 }, { "id": 265717610, "name": "CVE-2020-9484", "full_name": "masahiro331\/CVE-2020-9484", "owner": { "login": "masahiro331", "id": 20438853, "avatar_url": "https:\/\/avatars1.githubusercontent.com\/u\/20438853?v=4", "html_url": "https:\/\/github.com\/masahiro331" }, "html_url": "https:\/\/github.com\/masahiro331\/CVE-2020-9484", "description": null, "fork": false, "created_at": "2020-05-21T00:41:06Z", "updated_at": "2020-05-26T13:44:01Z", "pushed_at": "2020-05-21T10:15:35Z", "stargazers_count": 13, "watchers_count": 13, "forks_count": 0, "forks": 0, "watchers": 13, "score": 0 }, { "id": 265735756, "name": "CVE-2020-9484", "full_name": "FiveAourThe\/CVE-2020-9484", "owner": { "login": "FiveAourThe", "id": 38708428, "avatar_url": "https:\/\/avatars0.githubusercontent.com\/u\/38708428?v=4", "html_url": "https:\/\/github.com\/FiveAourThe" }, "html_url": "https:\/\/github.com\/FiveAourThe\/CVE-2020-9484", "description": "利用ceye批量检测CVE-2020-9484", "fork": false, "created_at": "2020-05-21T02:30:37Z", "updated_at": "2020-05-24T17:24:32Z", "pushed_at": "2020-05-21T02:30:47Z", "stargazers_count": 4, "watchers_count": 4, "forks_count": 7, "forks": 7, "watchers": 4, "score": 0 }, { "id": 265870392, "name": "CVE-2020-9484", "full_name": "IdealDreamLast\/CVE-2020-9484", "owner": { "login": "IdealDreamLast", "id": 33090510, "avatar_url": "https:\/\/avatars0.githubusercontent.com\/u\/33090510?v=4", "html_url": "https:\/\/github.com\/IdealDreamLast" }, "html_url": "https:\/\/github.com\/IdealDreamLast\/CVE-2020-9484", "description": "用Kali 2.0复现Apache Tomcat Session反序列化代码执行漏洞", "fork": false, "created_at": "2020-05-21T14:30:46Z", "updated_at": "2020-05-28T01:39:07Z", "pushed_at": "2020-05-21T15:13:22Z", "stargazers_count": 27, "watchers_count": 27, "forks_count": 13, "forks": 13, "watchers": 27, "score": 0 } ]