Apache ShiroÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-17523£©
°ä²¼¹¦·ò 2021-02-020x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-17523 | ʱ ¼ä | 2021-02-02 |
Àà ÐÍ | ÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ÖÐΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | Apache Shiro < 1.7.1 |
0x01 ·ì϶ÏêÇé

Apache ShiroÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü,ÆäÖ§³ÖÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀíµÈ¡£Ê¹ÓÃShiroµÄAPIÄܹ»¼±¾ç¡¢ÇáËɵػñµÃÈκÎÀûÓ÷¨Ê½¡£
2021Äê02ÔÂ01ÈÕ£¬Apache Shiro°ä²¼1.7.1°æ±¾£¬½¨¸´ÁË Apache Shiro ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-17523£©¡£µ±Apache ShiroÓëSpring½áºÏʹÓÃʱ£¬¹¥»÷ÕßÄܹ»Ê¹ÓöñÒâHTTPÒªÇóÀ´ÈƹýShiroµÄÉí·ÝÈÏÖ¤¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÈƹýÉí·ÝÑéÖ¤£¬³É¹¦½Ó¼ûºó¶Ü¡£
0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶Òѱ»½¨¸´£¬½¨ÒéÉý¼¶ÖÁApache Shiro 1.7.1¡£
ÏÂÔØÁ´½Ó£º
https://shiro.apache.org/download.html
0x03 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r13fe9ddc4ebdbf17db22cf1dd2776144bf9fdbfbdf2887a0385538aa%40%3Ccommits.shiro.apache.org%3E
https://shiro.apache.org/news.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17523
0x04 ¹¦·òÏß
2021-02-01 Apache Shiro°ä²¼°²È«¸üÐÂ
2021-02-02 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ