File size: 2,691 Bytes
020c337 | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 | [{
"CVE": "FastJson-1.2.47",
"CVSS": 9.8,
"DESC": "FASTJSON 1.2.47 及以下版本存在 RCE 漏洞,利用条件较低,危害较大"
}, {
"CVE": "FastJson-1.2.68",
"CVSS": 9.8,
"DESC": "FastJson 1.2.68 及以下版本存在 RCE 漏洞,有一定利用条件"
}, {
"CVE": "FastJson-1.2.80",
"CVSS": 8.1,
"DESC": "FastJson 1.2.80 及以下版本存在 RCE 漏洞,有较高利用条件"
}, {
"CVE": "CVE-2021-45105",
"CVSS": 5.9,
"DESC": "Apache Log4j2 可能由于不受限制的递归导致拒绝服务"
}, {
"CVE": "CVE-2021-45046",
"CVSS": 9.0,
"DESC": "Apache Log4j2 2.15.0 修复不完善,存在拒绝服务和 RCE 漏洞"
}, {
"CVE": "CVE-2021-44228",
"CVSS": 10.0,
"DESC": "Apache Log4j2 著名的 Log4Shell 漏洞,利用条件低,危害极大"
}, {
"CVE": "CVE-2021-44832",
"CVSS": 6.6,
"DESC": "Apache Log4j2 JDBC Appender 配置可控时存在 RCE 漏洞"
}, {
"CVE": "CVE-2023-46749",
"CVSS": 6.5,
"DESC": "Apache Shiro 开启 rewriting 存在目录遍历漏洞"
}, {
"CVE": "CVE-2023-46750",
"CVSS": 6.1,
"DESC": "Apache Shiro 开启 form 存在开放重定向漏洞"
}, {
"CVE": "CVE-2023-34478",
"CVSS": 9.8,
"DESC": "Apache Shiro 某些情况存在目录遍历导致权限绕过"
}, {
"CVE": "CVE-2023-22602",
"CVSS": 7.5,
"DESC": "Apache Shiro 配合 SpringBoot 可能存在权限绕过"
}, {
"CVE": "CVE-2022-40664",
"CVSS": 9.8,
"DESC": "Apache Shiro 存在权限绕过漏洞"
}, {
"CVE": "CVE-2022-32532",
"CVSS": 9.8,
"DESC": "Apache Shiro 使用 RegExPatternMatcher 存在权限绕过漏洞"
}, {
"CVE": "CVE-2021-41303",
"CVSS": 9.8,
"DESC": "Apache Shiro 配合 SpringBoot 可能存在权限绕过"
}, {
"CVE": "CVE-2020-17523",
"CVSS": 9.8,
"DESC": "Apache Shiro 配合 Spring 可能存在权限绕过"
}, {
"CVE": "CVE-2020-17510",
"CVSS": 9.8,
"DESC": "Apache Shiro 配合 Spring 可能存在权限绕过"
}, {
"CVE": "CVE-2020-13933",
"CVSS": 7.5,
"DESC": "Apache Shiro 存在权限绕过漏洞"
}, {
"CVE": "CVE-2020-11989",
"CVSS": 9.8,
"DESC": "Apache Shiro 配合 Spring 存在权限绕过漏洞"
}, {
"CVE": "CVE-2020-1957",
"CVSS": 9.8,
"DESC": "Apache Shiro 配合 Spring 存在权限绕过漏洞"
}, {
"CVE": "CVE-2019-12422",
"CVSS": 9.8,
"DESC": "Apache Shiro Padding Oracle 反序列化漏洞"
}, {
"CVE": "CVE-2016-6802",
"CVSS": 7.5,
"DESC": "Apache Shiro 存在权限绕过漏洞"
}, {
"CVE": "CVE-2016-4437",
"CVSS": 9.8,
"DESC": "Apache Shiro 反序列化漏洞"
}, {
"CVE": "CVE-2014-0074",
"CVSS": 7.5,
"DESC": "Apache Shiro LDAP 存在权限绕过漏洞"
}, {
"CVE": "CVE-2010-3863",
"CVSS": 5.0,
"DESC": "Apache Shiro /./account/index.jsp 权限绕过漏洞"
}] |