CVE-2020-13933 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-08-180x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-13933 | ʱ ¼ä | 2020-08-18 |
Àà ÐÍ | µÈ ¼¶ | ¸ßΣ | |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Apache Shiro < 1.6.0 |
0x01 ·ì϶ÏêÇé

2020Äê6ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½°ä²¼²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËÒ»¸öApache ShiroÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-11989£©£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâÒªÇóÀûÓø÷ì϶À´ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼1.5.3°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£µ«Õâ¸ö½¨¸´²¢²»ÆëÈ«£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚshiroÔÚ´¦ÖÃurlʱÓëspringÒÀÈ»´æÔÚ²î¾à£¬£¬£¬£¬£¬£¬£¬£¬shiro×îаæÒÀÈ»´æÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£2020Äê8ÔÂ17ÈÕApache¹Ù·½Ôٴΰ䲼²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬½øÒ»²½½¨¸´Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-13933£©£¬£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼1.6.0°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
¹Ù·½ÒѰ䲼а汾£¬£¬£¬£¬£¬£¬£¬£¬ÇëÉý¼¶µ½1.6.0°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµØÖ·£º
http://shiro.apache.org/download.html
0x03 ÓйØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-13933
0x04 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r539f87706094e79c5da0826030384373f0041068936912876856835f%40%3Cdev.shiro.apache.org%3E
0x05 ¹¦·òÏß
2020-08-17 Apache¹Ù·½°ä²¼²¼¸æ
2020-08-18 VSRC°ä²¼·ì϶¹«¸æ



¾©¹«Íø°²±¸11010802024551ºÅ