CVE-2020-13933 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-18

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-13933

ʱ    ¼ä

2020-08-18

Àà   ÐÍ



µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Shiro < 1.6.0



0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



2020Äê6ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-11989£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóʹÓøÃÎó²îÀ´ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼1.5.3°æ±¾¡£¡£¡£¡£¡£¡£¡£µ«Õâ¸öÐÞ¸´²¢²»ÍêÈ«£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚshiroÔÚ´¦Öóͷ£urlʱÓëspringÈÔÈ»±£´æ²î±ð£¬£¬£¬£¬£¬£¬£¬shiro×îаæÈÔÈ»±£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£2020Äê8ÔÂ17ÈÕApache¹Ù·½ÔÙ´ÎÐû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬£¬½øÒ»²½ÐÞ¸´Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-13933£©£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼1.6.0°æ±¾¡£¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


¹Ù·½ÒÑÐû²¼Ð°汾£¬£¬£¬£¬£¬£¬£¬ÇëÉý¼¶µ½1.6.0°æ±¾£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµØµã£º

http://shiro.apache.org/download.html


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-13933


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r539f87706094e79c5da0826030384373f0041068936912876856835f%40%3Cdev.shiro.apache.org%3E


0x05 ʱ¼äÏß


2020-08-17 Apache¹Ù·½Ðû²¼Í¨¸æ

2020-08-18 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨