CVE-2020-13933 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-08-180x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-13933 | ʱ ¼ä | 2020-08-18 |
Àà ÐÍ | µÈ ¼¶ | ¸ßΣ | |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache Shiro < 1.6.0 |
0x01 Îó²îÏêÇé
2020Äê6ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-11989£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóʹÓøÃÎó²îÀ´ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼1.5.3°æ±¾¡£¡£¡£¡£¡£¡£¡£µ«Õâ¸öÐÞ¸´²¢²»ÍêÈ«£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚshiroÔÚ´¦Öóͷ£urlʱÓëspringÈÔÈ»±£´æ²î±ð£¬£¬£¬£¬£¬£¬£¬shiro×îаæÈÔÈ»±£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£2020Äê8ÔÂ17ÈÕApache¹Ù·½ÔÙ´ÎÐû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬£¬½øÒ»²½ÐÞ¸´Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-13933£©£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼1.6.0°æ±¾¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
¹Ù·½ÒÑÐû²¼Ð°汾£¬£¬£¬£¬£¬£¬£¬ÇëÉý¼¶µ½1.6.0°æ±¾£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµØµã£º
http://shiro.apache.org/download.html
0x03 Ïà¹ØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-13933
0x04 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r539f87706094e79c5da0826030384373f0041068936912876856835f%40%3Cdev.shiro.apache.org%3E
0x05 ʱ¼äÏß
2020-08-17 Apache¹Ù·½Ðû²¼Í¨¸æ
2020-08-18 VSRCÐû²¼Îó²îͨ¸æ