Apache Shiro Padding OracleÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-11-14Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Apache Shiro 1.2.5, 1.2.6, 1.3.0, 1.3.1, 1.3.2, 1.4.0-RC2, 1.4.0, 1.4.1°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
Îó²î¸ÅÊö
Apache ShiroÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»Ì×ÓÃÓÚÖ´ÐÐÈÏÖ¤¡¢ÊÚȨ¡¢¼ÓÃܺͻỰÖÎÀíµÄJavaÇå¾²¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£¡£
Apache Shiro cookieÖеÄͨ¹ýAES-128-CBCģʽ¼ÓÃܵÄrememberMe×ֶα£´æÎÊÌ⣬£¬£¬£¬£¬£¬ÈÝÒ×Êܵ½Padding Oracle¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓÃRememberMe cookie×÷ΪPadding Oracle AttackµÄǰ׺£¬£¬£¬£¬£¬£¬È»ºóͨ¹ýÈ«ÐÄÖÆ×÷µÄRememberMeÀ´Ö´ÐÐJava·´ÐòÁл¯¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
Õû¸öÀú³Ì¹¥»÷ÕßÎÞÐèÖªµÀRememberMeµÄ¼ÓÃÜÃØÔ¿¡£¡£¡£¡£¡£¡£¡£¡£²¢Í¨¹ýÒÔϰ취Ìᳫ¹¥»÷£º
Ê×ÏȵÇÂ¼ÍøÕ¾£¬£¬£¬£¬£¬£¬²¢´ÓcookieÖлñÈ¡rememberMe£»£»£»£»
Æä´ÎʹÓÃrememberMe cookie×÷ΪPadding Oracle¹¥»÷µÄǰ׺£»£»£»£»
È»ºóͨ¹ýPadding Oracle¹¥»÷¼ÓÃÜÒ»Ìõysoserial¹¤¾ßÖеÄJavaÐòÁл¯PayloadÀ´½á¹¹¶ñÒârememberMe£»£»£»£»
×îºóʹÓøոսṹµÄ¶ñÒârememberMeÖØÐÂÇëÇóÍøÕ¾£¬£¬£¬£¬£¬£¬¾ÙÐз´ÐòÁл¯¹¥»÷£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
¸ÃÎó²î±ØÐèÔڵǼApache ShiroÌõ¼þÏ¿ÉÒÔʹÓÃÀֳɣ¬£¬£¬£¬£¬£¬¾ÙÐÐÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬Îó²î¸´ÏÖÈçͼËùʾ£º
怬
µÇ¼ÀÖ³É
Æô¶¯jrmp
Ö´ÐÐexp
Îó²îʹÓÃÀÖ³É
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÉÐδÐû²¼Îó²îÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£
ÔÝʱÐÞ¸´½¨Ò飺
ÐÞ¸ÄshiroÉèÖÃÖеÄAES¼ÓÃÜÒªÁ첻ΪCBCģʽ¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://issues.apache.org/jira/browse/SHIRO-721


¾©¹«Íø°²±¸11010802024551ºÅ