Apache Shiro ȨÏÞÈÆ¹ý·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-03-26·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-1957£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache Shiro < 1.5.2
·ì϶¸ÅÊö
Apache ShiroÊÇÒ»¸öJava°²È«¿ò¼Ü£¬Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂë¡¢»á»°ÖÎÀí¡£ShiroÊÇApache µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬Ç°ÉíÊÇJSecurity ÏîÄ¿£¬Ê¼ÓÚ2003ËêÊס£Shiro ¿ÉÒÔΪÈκÎÀûÓÃÌṩ°²È«±£ÏÕ - ´ÓºÅÁîÐÐÀûÓá¢Òƶ¯ÀûÓõ½´óÐÍÍøÂç¼°ÆóÒµÀûÓá£
½üÈÕ£¬Shiro¹Ù·½°ä²¼ÁËÒ»¸ö°²È«¸üв¼¸æ£º Shiro < 1.5.2 °æ±¾´æÔÚÒ»´¦È¨ÏÞÈÆ¹ý·ì϶£¬µ±ÊÜÓ°Ïì°æ±¾µÄ Shiro¿ò¼Ü½áºÏ Spring dynamic controllers ʹÓÃʱ£¬Î´¾ÊÚȨµÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¾«ÐÄ»ú¹ØµÄÒªÇó°ü½øÐÐȨÏÞÈÆ¹ý£¬¿ÉÄÜÔì³É¼øÈ¨ÏµÍ³Ê§Ð§ÒÔ¼°ºó¶ÜÖ°Äܶ³ö¡£
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£
½¨¸´½¨Òé
Ŀǰ¹Ù·½ÒѰ䲼а汾£¬Çë¸üе½ Shiro 1.5.2¼°ÒÔÉϰ汾£¬Á´½Ó£ºhttp://shiro.apache.org/download.html¡£
²Î¿¼Á´½Ó
https://seclists.org/oss-sec/2020/q1/120


¾©¹«Íø°²±¸11010802024551ºÅ