¡¾Ç徲ͨ¸æ¡¿Apache?ShiroȨÏÞÈÆ¹ýÎó²î£¨CVE-2020-17523£©Í¨¸æ
2021-02-04
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½Apache Shiro¹Ù·½Ðû²¼Çå¾²¸üУ¬ÐÞ¸´ÁËÒ»¸öеÄȨÏÞÈÆ¹ýÎó²î£¨CVE-2020-17523£©¡£µ±Apache ShiroÓëSpringÍŽáʹÓÃʱ£¬¹¥»÷Õß¿ÉÒÔ½á¹¹ÌØ¶¨µÄHTTPÇëÇóÈÆ¹ýÉí·ÝÑéÖ¤»á¼ûºǫ́¹¦Ð§£»ÏÖÔÚÎó²îϸ½ÚÒѹûÕæ£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
Apache ShiroÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢ÇÒÒ×ÓÚʹÓõÄJavaÇå¾²¿ò¼Ü£¬¹¦Ð§°üÀ¨Éí·ÝÑéÖ¤¡¢ÊÚȨ¡¢¼ÓÃܺͻỰÖÎÀí¡£Ê¹ÓÃShiroµÄAPI£¬¿ÉÒÔÇáËɵء¢¿ìËٵر£»¤ÈκÎÓ¦ÓóÌÐò£¬¹æÄ£´ÓСÐ͵ÄÒÆ¶¯Ó¦ÓóÌÐòµ½´óÐ͵ÄWebºÍÆóÒµÓ¦ÓóÌÐò¡£
²Î¿¼Á´½Ó£º
https://shiro.apache.org/security-reports.html
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
Apache Shiro < 1.7.1
²»ÊÜÓ°Ïì°æ±¾
Apache Shiro = 1.7.1
Èý. Îó²î¼ì²â
3.1 È˹¤¼ì²â
Ïà¹ØÓû§¿Éͨ¹ý°æ±¾¼ì²âµÄ·½·¨ÅжÏÄ¿½ñÓ¦ÓÃÊÇ·ñ±£´æÎ£º¦¡£
ÔÚconfig\pom.xmlµÄversion±êÇ©ÖÐÉó²éÄ¿½ñʹÓõÄshiro°æ±¾ºÅ:

Èô°æ±¾ÔÚÊÜÓ°Ïì¹æÄ£ÄÚÔò¿ÉÄܱ£´æÇ徲Σº¦¡£
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£ºhttps://shiro.apache.org/download.html
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







