CVE-2020-17510 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-11-030x00 Îó²î¸ÅÊö
CNVD ID | CVE-2020-17510 | ʱ ¼ä | 2020-11-03 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache Shiro <1.7.0 |
Apache ShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü,ÆäÖ§³ÖÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀíµÈ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃShiroµÄAPI,¿ÉÒÔ¿ìËÙ¡¢ÇáËɵػñµÃÈκÎÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
2020Äê10ÔÂ30ÈÕ£¬£¬£¬£¬£¬Apache ShiroÐû²¼1.7.0°æ±¾£¬£¬£¬£¬£¬ÐÞ¸´ÁË Apache Shiro Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î (CVE-2020-17510)¡£¡£¡£¡£¡£¡£¡£µ±Apache ShiroÓëSpringÁ¬ÏµÊ¹ÓÃʱ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓöñÒâHTTPÇëÇóÀ´ÈƹýShiroµÄÉí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»á¼ûºǫ́¹¦Ð§£¬£¬£¬£¬£¬Ç徲Σº¦½Ï¸ß¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
½¨Òéʵʱ¸üÐÂÖÁÇå¾²°æ±¾¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØµØµã£º
https://shiro.apache.org/download.html
0x03 ²Î¿¼Á´½Ó
https://www.mail-archive.com/user@shiro.apache.org/msg05870.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17510
0x04 ʱ¼äÏß
2020-10-30 Apache ShiroÐû²¼¸üÐÂ
2020-11-03 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/