Apache Shiro Padding OracleÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-11-14

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Apache Shiro 1.2.5, 1.2.6, 1.3.0, 1.3.1, 1.3.2, 1.4.0-RC2, 1.4.0, 1.4.1°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


Apache ShiroÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»Ì×ÓÃÓÚÖ´ÐÐÈÏÖ¤¡¢ÊÚȨ¡¢¼ÓÃܺͻỰÖÎÀíµÄJavaÇå¾²¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£¡£


Apache Shiro cookieÖеÄͨ¹ýAES-128-CBCģʽ¼ÓÃܵÄrememberMe×ֶα£´æÎÊÌ⣬£¬£¬£¬£¬ £¬ÈÝÒ×Êܵ½Padding Oracle¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓÃRememberMe cookie×÷ΪPadding Oracle AttackµÄǰ׺£¬£¬£¬£¬£¬ £¬È»ºóͨ¹ýÈ«ÐÄÖÆ×÷µÄRememberMeÀ´Ö´ÐÐJava·´ÐòÁл¯¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


Õû¸öÀú³Ì¹¥»÷ÕßÎÞÐèÖªµÀRememberMeµÄ¼ÓÃÜÃØÔ¿¡£¡£¡£¡£¡£¡£¡£¡£²¢Í¨¹ýÒÔϰ취Ìᳫ¹¥»÷£º


Ê×ÏȵÇÂ¼ÍøÕ¾£¬£¬£¬£¬£¬ £¬²¢´ÓcookieÖлñÈ¡rememberMe£»£»£»£»


Æä´ÎʹÓÃrememberMe cookie×÷ΪPadding Oracle¹¥»÷µÄǰ׺£»£»£»£»


È»ºóͨ¹ýPadding Oracle¹¥»÷¼ÓÃÜÒ»Ìõysoserial¹¤¾ßÖеÄJavaÐòÁл¯PayloadÀ´½á¹¹¶ñÒârememberMe£»£»£»£»


×îºóʹÓøոսṹµÄ¶ñÒârememberMeÖØÐÂÇëÇóÍøÕ¾£¬£¬£¬£¬£¬ £¬¾ÙÐз´ÐòÁл¯¹¥»÷£¬£¬£¬£¬£¬ £¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


¸ÃÎó²î±ØÐèÔڵǼApache ShiroÌõ¼þÏ¿ÉÒÔʹÓÃÀֳɣ¬£¬£¬£¬£¬ £¬¾ÙÐÐÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬ £¬Îó²î¸´ÏÖÈçͼËùʾ£º


怬

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



µÇ¼ÀÖ³É


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



Æô¶¯jrmp


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



Ö´ÐÐexp


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



Îó²îʹÓÃÀÖ³É


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÉÐδÐû²¼Îó²îÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£


ÔÝʱÐÞ¸´½¨Ò飺


ÐÞ¸ÄshiroÉèÖÃÖеÄAES¼ÓÃÜÒªÁ첻ΪCBCģʽ¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://issues.apache.org/jira/browse/SHIRO-721