CVE-2020-13933 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-18

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-13933

ʱ    ¼ä

2020-08-18

Àà   ÐÍ



µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Shiro < 1.6.0



0x01 Îó²îÏêÇé


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!



2020Äê6ÔÂ22ÈÕ £¬Apache¹Ù·½Ðû²¼Í¨¸æ £¬ÐÞ¸´ÁËÒ»¸öApache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-11989£© £¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóʹÓøÃÎó²îÀ´ÈƹýÉí·ÝÑéÖ¤ £¬²¢Ðû²¼1.5.3°æ±¾¡£µ«Õâ¸öÐÞ¸´²¢²»ÍêÈ« £¬ÓÉÓÚshiroÔÚ´¦Öóͷ£urlʱÓëspringÈÔÈ»±£´æ²î±ð £¬shiro×îаæÈÔÈ»±£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£2020Äê8ÔÂ17ÈÕApache¹Ù·½ÔÙ´ÎÐû²¼Í¨¸æ £¬½øÒ»²½ÐÞ¸´Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-13933£© £¬²¢Ðû²¼1.6.0°æ±¾¡£


0x02 ´¦Öóͷ£½¨Òé


¹Ù·½ÒÑÐû²¼Ð°汾 £¬ÇëÉý¼¶µ½1.6.0°æ±¾ £¬ÏÂÔØµØÖ·£º

http://shiro.apache.org/download.html


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-13933


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r539f87706094e79c5da0826030384373f0041068936912876856835f%40%3Cdev.shiro.apache.org%3E


0x05 ʱ¼äÏß


2020-08-17 Apache¹Ù·½Ðû²¼Í¨¸æ

2020-08-18 VSRCÐû²¼Îó²îͨ¸æ


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!