Apache Shiro Padding Oracle·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-11-14·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Apache Shiro 1.2.5, 1.2.6, 1.3.0, 1.3.1, 1.3.2, 1.4.0-RC2, 1.4.0, 1.4.1°æ±¾¡£¡£¡£¡£¡£¡£¡£
·ì϶¸ÅÊö
Apache ShiroÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»Ì×ÓÃÓÚÖ´ÐÐÈÏÖ¤¡¢ÊÚȨ¡¢¼ÓÃܺͻỰÖÎÀíµÄJava°²È«¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£
Apache Shiro cookieÖеÄͨ¹ýAES-128-CBCģʽ¼ÓÃܵÄrememberMe×ֶδæÔÚÎÊÌ⣬£¬£¬£¬£¬£¬ÈÝÒ×Êܵ½Padding Oracle¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓÃRememberMe cookie×÷ΪPadding Oracle AttackµÄǰ׺£¬£¬£¬£¬£¬£¬¶øºóͨ¹ý¾«ÐÄÔì×÷µÄRememberMeÀ´Ö´ÐÐJava·´ÐòÁл¯¹¥»÷¡£¡£¡£¡£¡£¡£¡£
Õû¸ö¹ý³Ì¹¥»÷ÕßÎÞÐè֪·RememberMeµÄ¼ÓÃÜÃØÔ¿¡£¡£¡£¡£¡£¡£¡£²¢Í¨¹ýÒÔϲ½ÖèÌáÒé¹¥»÷£º
Ê×ÏȵÇÂ¼ÍøÕ¾£¬£¬£¬£¬£¬£¬²¢´ÓcookieÖлñÈ¡rememberMe£»£»£»£»£»£»£»£»
Æä´ÎʹÓÃrememberMe cookie×÷ΪPadding Oracle¹¥»÷µÄǰ׺£»£»£»£»£»£»£»£»
¶øºóͨ¹ýPadding Oracle¹¥»÷¼ÓÃÜÒ»Ìõysoserial¹¤¾ßÖеÄJavaÐòÁл¯PayloadÀ´»ú¹Ø¶ñÒârememberMe£»£»£»£»£»£»£»£»
×îºóʹÓøոջú¹ØµÄ¶ñÒârememberMe³ÁÐÂÒªÇóÍøÕ¾£¬£¬£¬£¬£¬£¬½øÐз´ÐòÁл¯¹¥»÷£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
¸Ã·ì϶±ØÐëÔڵǼApache ShiroǰÌáÏÂÄܹ»ÀûÓóɹ¦£¬£¬£¬£¬£¬£¬½øÐÐÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬·ì϶¸´ÏÖÈçͼËùʾ£º
怬
µÇ¼³É¹¦
Æô¶¯jrmp
Ö´ÐÐexp
·ì϶ÀûÓóɹ¦
½¨¸´½¨Òé
Ŀǰ¹Ù·½ÉÐδ°ä²¼·ì϶½¨¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£
һʱ½¨¸´½¨Ò飺
Åú¸ÄshiroÅäÖÃÖеÄAES¼ÓÃܲ½Ö費ΪCBCģʽ¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://issues.apache.org/jira/browse/SHIRO-721


¾©¹«Íø°²±¸11010802024551ºÅ