セキュリティ

SHIRASAGI に複数の脆弱性

セキュリティ 元記事

予習

この記事のキーワード — タップで意味
×3
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×1
理工学部
りこうがくぶ
department of science and engineering
×1
アクセス権
アクセスけん
right of access; access permission; access right
×1
認可
にんか
approval; license; licence; permission
×2
及び
および
and; as well as
N1
 独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は9月10日、SHIRASAGIにおける複数脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。東京電機大学理工学部遠隔制御研究室の外崎青波氏、野口義氏報告を行っている。影響を受けるシステムは以下の通り

・CVE-2026-81635 SHIRASAGI v1.14.0からv1.20.2まで

・CVE-2026-82582 SHIRASAGI v1.20.2およびそれ以前

 SHIRASAGI Projectが提供するSHIRASAGIには、下記影響を受ける可能性がある複数脆弱性存在する。

・クロスサイトスクリプティング(CVE-2026-81635) →当該製品使用しているサイトにアクセスしたユーザのウェブブラウザ上で、任意のスクリプトが実行される

認可処理回避(CVE-2026-82582) →グループウェアの共有ファイルにおいて、本来アクセス権持たないユーザによってファイルが取得される

 JVNでは、開発者提供する情報もと最新版にアップデートするよう呼びかけている。なお脆弱性は、SHIRASAGI v1.21.0で修正されている。

この記事の単語 (41)

×3
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×2
及び
および
and; as well as
×2
複数
ふくすう
plural; multiple; several
×2
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×2
提供
ていきょう
1. offer; tender; providing; supplying; making available; donating (blood, organs, etc.) 2. sponsoring (a TV program)
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
×1
情報処理推進機構
じょうほうしょりすいしんきこう
Information-technology Promotion Agency (organization)
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
発表
はっぴょう
announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
×1
東京電機大学
とうきょうでんきだいがく
Tokyo Denki University (organization)
×1
理工学部
りこうがくぶ
department of science and engineering
×1
外崎
そとさき
Sotosaki (surname)
×1
青波
あおなみ
Aonami (place; surname)
×1
野口
のくち
Nokuchi (surname)
×1
義氏
よしうじ
Yoshiuji (given)
×1
報告
ほうこく
report; information
×1
通り
とおり
1. avenue; street; way; road 2. coming and going; street traffic
×1
以前
いぜん
ago; since; before; previous
×1
下記
かき
the following
×1
可能性
かのうせい
potentiality; likelihood; possibility; availability
×1
存在
そんざい
existence; being
×1
当該
とうがい
appropriate (e.g. authorities); concerned; relevant; said; aforementioned; competent; applicable; respective
×1
製品
せいひん
manufactured goods; finished goods; product
×1
使用
しよう
use; application; employment; utilization; utilisation
×1
任意
にんい
1. optional; voluntary; arbitrary; random; discretionary; facultative; spontaneous; any 2. arbitrary
×1
実行
じっこう
execution (e.g. of a plan); carrying out; practice; action; implementation; fulfillment; realization
×1
認可
にんか
approval; license; licence; permission
×1
処理
しょり
processing; dealing with; treatment; disposition; disposal
×1
回避
かいひ
evasion; avoidance
×1
共有
きょうゆう
1. joint ownership; co-ownership; sharing (e.g. a viewpoint) 2. sharing (files, devices on a network, posts on social media, etc.)
×1
本来
ほんらい
1. originally; primarily 2. essentially; intrinsically; naturally; by nature; in (and of) itself
×1
アクセス権
アクセスけん
right of access; access permission; access right
×1
持つ
もつ
1. to hold (in one's hand); to take; to carry 2. to possess; to have; to own
×1
取得
しゅとく
acquisition; obtaining; gaining possession; purchase
×1
開発者
かいはつしゃ
developer
×1
情報
じょうほう
1. information; news; intelligence; advices 2. information; data contained in characters, signals, code, etc.
×1
もと
1. origin; source 2. base; basis; foundation; root
×1
最新版
さいしんばん
latest version; latest edition
×1
呼び掛ける
よびかける
1. to call out to; to hail; to address 2. to appeal
×1
なお
1. still; yet 2. more; still more; greater; further
×1
修正
しゅうせい
amendment; correction; revision; modification; alteration; retouching; update; fix