CVE-2020-13933 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-18

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-13933

ʱ    ¼ä

2020-08-18

Àà   ÐÍ



µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Shiro < 1.6.0



0x01 Îó²îÏêÇé


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



2020Äê6ÔÂ22ÈÕ£¬£¬£¬ £¬£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬ £¬£¬ÐÞ¸´ÁËÒ»¸öApache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-11989£©£¬£¬£¬ £¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóʹÓøÃÎó²îÀ´ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬ £¬£¬²¢Ðû²¼1.5.3°æ±¾¡£¡£¡£µ«Õâ¸öÐÞ¸´²¢²»ÍêÈ«£¬£¬£¬ £¬£¬ÓÉÓÚshiroÔÚ´¦Öóͷ£urlʱÓëspringÈÔÈ»±£´æ²î±ð£¬£¬£¬ £¬£¬shiro×îаæÈÔÈ»±£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£2020Äê8ÔÂ17ÈÕApache¹Ù·½ÔÙ´ÎÐû²¼Í¨¸æ£¬£¬£¬ £¬£¬½øÒ»²½ÐÞ¸´Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-13933£©£¬£¬£¬ £¬£¬²¢Ðû²¼1.6.0°æ±¾¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


¹Ù·½ÒÑÐû²¼Ð°汾£¬£¬£¬ £¬£¬ÇëÉý¼¶µ½1.6.0°æ±¾£¬£¬£¬ £¬£¬ÏÂÔØµØµã£º

http://shiro.apache.org/download.html


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-13933


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r539f87706094e79c5da0826030384373f0041068936912876856835f%40%3Cdev.shiro.apache.org%3E


0x05 ʱ¼äÏß


2020-08-17 Apache¹Ù·½Ðû²¼Í¨¸æ

2020-08-18 VSRCÐû²¼Îó²îͨ¸æ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾