CVE-2020-13933 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-08-18

0x00 ·ì϶¸ÅÊö



CVE   ID

CVE-2020-13933

ʱ    ¼ä

2020-08-18

Àà   ÐÍ



µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Apache Shiro < 1.6.0



0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



2020Äê6ÔÂ22ÈÕ£¬Apache¹Ù·½°ä²¼²¼¸æ£¬½¨¸´ÁËÒ»¸öApache ShiroÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-11989£©£¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâÒªÇóÀûÓø÷ì϶À´ÈƹýÉí·ÝÑéÖ¤£¬²¢°ä²¼1.5.3°æ±¾¡£µ«Õâ¸ö½¨¸´²¢²»ÆëÈ«£¬ÓÉÓÚshiroÔÚ´¦ÖÃurlʱÓëspringÒÀÈ»´æÔÚ²î¾à£¬shiro×îаæÒÀÈ»´æÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£2020Äê8ÔÂ17ÈÕApache¹Ù·½Ôٴΰ䲼²¼¸æ£¬½øÒ»²½½¨¸´Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-13933£©£¬²¢°ä²¼1.6.0°æ±¾¡£


0x02 ´ëÖý¨Òé


¹Ù·½ÒѰ䲼а汾£¬ÇëÉý¼¶µ½1.6.0°æ±¾£¬ÏÂÔØµØÖ·£º

http://shiro.apache.org/download.html


0x03 ÓйØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-13933


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r539f87706094e79c5da0826030384373f0041068936912876856835f%40%3Cdev.shiro.apache.org%3E


0x05 ¹¦·òÏß


2020-08-17 Apache¹Ù·½°ä²¼²¼¸æ

2020-08-18 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾