CVE-2020-13933 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-08-18

0x00 ·ì϶¸ÅÊö



CVE   ID

CVE-2020-13933

ʱ    ¼ä

2020-08-18

Àà   ÐÍ



µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Apache Shiro < 1.6.0



0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



2020Äê6ÔÂ22ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬Apache¹Ù·½°ä²¼²¼¸æ£¬£¬£¬ £¬£¬£¬£¬£¬½¨¸´ÁËÒ»¸öApache ShiroÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-11989£©£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâÒªÇóÀûÓø÷ì϶À´ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬ £¬£¬£¬£¬£¬²¢°ä²¼1.5.3°æ±¾¡£¡£ ¡£¡£¡£¡£¡£¡£µ«Õâ¸ö½¨¸´²¢²»ÆëÈ«£¬£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚshiroÔÚ´¦ÖÃurlʱÓëspringÒÀÈ»´æÔÚ²î¾à£¬£¬£¬ £¬£¬£¬£¬£¬shiro×îаæÒÀÈ»´æÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£¡£ ¡£¡£¡£¡£¡£¡£2020Äê8ÔÂ17ÈÕApache¹Ù·½Ôٴΰ䲼²¼¸æ£¬£¬£¬ £¬£¬£¬£¬£¬½øÒ»²½½¨¸´Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-13933£©£¬£¬£¬ £¬£¬£¬£¬£¬²¢°ä²¼1.6.0°æ±¾¡£¡£ ¡£¡£¡£¡£¡£¡£


0x02 ´ëÖý¨Òé


¹Ù·½ÒѰ䲼а汾£¬£¬£¬ £¬£¬£¬£¬£¬ÇëÉý¼¶µ½1.6.0°æ±¾£¬£¬£¬ £¬£¬£¬£¬£¬ÏÂÔØµØÖ·£º

http://shiro.apache.org/download.html


0x03 ÓйØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-13933


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r539f87706094e79c5da0826030384373f0041068936912876856835f%40%3Cdev.shiro.apache.org%3E


0x05 ¹¦·òÏß


2020-08-17 Apache¹Ù·½°ä²¼²¼¸æ

2020-08-18 VSRC°ä²¼·ì϶¹«¸æ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website