CVE-2020-13933 | Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-08-180x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-13933 | ʱ ¼ä | 2020-08-18 |
Àà ÐÍ | µÈ ¼¶ | ¸ßΣ | |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Apache Shiro < 1.6.0 |
0x01 Îó²îÏêÇé

2020Äê6ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-11989£©£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóʹÓøÃÎó²îÀ´ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬²¢Ðû²¼1.5.3°æ±¾¡£¡£¡£¡£µ«Õâ¸öÐÞ¸´²¢²»ÍêÈ«£¬£¬£¬£¬£¬£¬ÓÉÓÚshiroÔÚ´¦Öóͷ£urlʱÓëspringÈÔÈ»±£´æ²î±ð£¬£¬£¬£¬£¬£¬shiro×îаæÈÔÈ»±£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£2020Äê8ÔÂ17ÈÕApache¹Ù·½ÔÙ´ÎÐû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬½øÒ»²½ÐÞ¸´Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-13933£©£¬£¬£¬£¬£¬£¬²¢Ðû²¼1.6.0°æ±¾¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
¹Ù·½ÒÑÐû²¼Ð°汾£¬£¬£¬£¬£¬£¬ÇëÉý¼¶µ½1.6.0°æ±¾£¬£¬£¬£¬£¬£¬ÏÂÔØµØµã£º
http://shiro.apache.org/download.html
0x03 Ïà¹ØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-13933
0x04 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r539f87706094e79c5da0826030384373f0041068936912876856835f%40%3Cdev.shiro.apache.org%3E
0x05 ʱ¼äÏß
2020-08-17 Apache¹Ù·½Ðû²¼Í¨¸æ
2020-08-18 VSRCÐû²¼Îó²îͨ¸æ



¾©¹«Íø°²±¸11010802024551ºÅ