Apache ShiroÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-17523£©

°ä²¼¹¦·ò 2021-02-02

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-17523

ʱ  ¼ä

2021-02-02

Àà   ÐÍ

ÑéÖ¤ÈÆ¹ý

µÈ  ¼¶

ÖÐΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Apache Shiro < 1.7.1

 

0x01 ·ì϶ÏêÇé

image.png

 

Apache ShiroÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü,ÆäÖ§³ÖÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀíµÈ¡£Ê¹ÓÃShiroµÄAPIÄܹ»¼±¾ç¡¢ÇáËɵػñµÃÈκÎÀûÓ÷¨Ê½¡£

2021Äê02ÔÂ01ÈÕ  £¬Apache Shiro°ä²¼1.7.1°æ±¾  £¬½¨¸´ÁË Apache Shiro ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-17523£©¡£µ±Apache ShiroÓëSpring½áºÏʹÓÃʱ  £¬¹¥»÷ÕßÄܹ»Ê¹ÓöñÒâHTTPÒªÇóÀ´ÈƹýShiroµÄÉí·ÝÈÏÖ¤¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÈƹýÉí·ÝÑéÖ¤  £¬³É¹¦½Ó¼ûºó¶Ü¡£

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶Òѱ»½¨¸´  £¬½¨ÒéÉý¼¶ÖÁApache Shiro 1.7.1¡£

ÏÂÔØÁ´½Ó£º

https://shiro.apache.org/download.html

 

0x03 ²Î¿¼Á´½Ó

https://lists.apache.org/thread.html/r13fe9ddc4ebdbf17db22cf1dd2776144bf9fdbfbdf2887a0385538aa%40%3Ccommits.shiro.apache.org%3E

https://shiro.apache.org/news.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17523

 

0x04 ¹¦·òÏß

2021-02-01  Apache Shiro°ä²¼°²È«¸üÐÂ

2021-02-02  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png