CVE-2020-17510 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-11-03

0x00 Îó²î¸ÅÊö

CNVD   ID

CVE-2020-17510

ʱ    ¼ä

2020-11-03

Àà    ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Shiro <1.7.0

 

Apache ShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü,ÆäÖ§³ÖÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀíµÈ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃShiroµÄAPI,¿ÉÒÔ¿ìËÙ¡¢ÇáËɵػñµÃÈκÎÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

 image.png


2020Äê10ÔÂ30ÈÕ£¬ £¬£¬£¬£¬Apache ShiroÐû²¼1.7.0°æ±¾£¬ £¬£¬£¬£¬ÐÞ¸´ÁË Apache Shiro Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î (CVE-2020-17510)¡£¡£¡£¡£¡£¡£¡£µ±Apache ShiroÓëSpringÁ¬ÏµÊ¹ÓÃʱ£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓöñÒâHTTPÇëÇóÀ´ÈƹýShiroµÄÉí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»á¼ûºǫ́¹¦Ð§£¬ £¬£¬£¬£¬Ç徲Σº¦½Ï¸ß¡£¡£¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

½¨Òéʵʱ¸üÐÂÖÁÇå¾²°æ±¾¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØµØµã£º

https://shiro.apache.org/download.html

 

0x03 ²Î¿¼Á´½Ó

https://www.mail-archive.com/user@shiro.apache.org/msg05870.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17510

 

0x04 ʱ¼äÏß

2020-10-30  Apache ShiroÐû²¼¸üÐÂ

2020-11-03  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

 

image.png