File size: 2,691 Bytes
020c337
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
[{
	"CVE": "FastJson-1.2.47",
	"CVSS": 9.8,
	"DESC": "FASTJSON 1.2.47 及以下版本存在 RCE 漏洞,利用条件较低,危害较大"
}, {
	"CVE": "FastJson-1.2.68",
	"CVSS": 9.8,
	"DESC": "FastJson 1.2.68 及以下版本存在 RCE 漏洞,有一定利用条件"
}, {
	"CVE": "FastJson-1.2.80",
	"CVSS": 8.1,
	"DESC": "FastJson 1.2.80 及以下版本存在 RCE 漏洞,有较高利用条件"
}, {
	"CVE": "CVE-2021-45105",
	"CVSS": 5.9,
	"DESC": "Apache Log4j2 可能由于不受限制的递归导致拒绝服务"
}, {
	"CVE": "CVE-2021-45046",
	"CVSS": 9.0,
	"DESC": "Apache Log4j2 2.15.0 修复不完善,存在拒绝服务和 RCE 漏洞"
}, {
	"CVE": "CVE-2021-44228",
	"CVSS": 10.0,
	"DESC": "Apache Log4j2 著名的 Log4Shell 漏洞,利用条件低,危害极大"
}, {
	"CVE": "CVE-2021-44832",
	"CVSS": 6.6,
	"DESC": "Apache Log4j2 JDBC Appender 配置可控时存在 RCE 漏洞"
}, {
	"CVE": "CVE-2023-46749",
	"CVSS": 6.5,
	"DESC": "Apache Shiro 开启 rewriting 存在目录遍历漏洞"
}, {
	"CVE": "CVE-2023-46750",
	"CVSS": 6.1,
	"DESC": "Apache Shiro 开启 form 存在开放重定向漏洞"
}, {
	"CVE": "CVE-2023-34478",
	"CVSS": 9.8,
	"DESC": "Apache Shiro 某些情况存在目录遍历导致权限绕过"
}, {
	"CVE": "CVE-2023-22602",
	"CVSS": 7.5,
	"DESC": "Apache Shiro 配合 SpringBoot 可能存在权限绕过"
}, {
	"CVE": "CVE-2022-40664",
	"CVSS": 9.8,
	"DESC": "Apache Shiro 存在权限绕过漏洞"
}, {
	"CVE": "CVE-2022-32532",
	"CVSS": 9.8,
	"DESC": "Apache Shiro 使用 RegExPatternMatcher 存在权限绕过漏洞"
}, {
	"CVE": "CVE-2021-41303",
	"CVSS": 9.8,
	"DESC": "Apache Shiro 配合 SpringBoot 可能存在权限绕过"
}, {
	"CVE": "CVE-2020-17523",
	"CVSS": 9.8,
	"DESC": "Apache Shiro 配合 Spring 可能存在权限绕过"
}, {
	"CVE": "CVE-2020-17510",
	"CVSS": 9.8,
	"DESC": "Apache Shiro 配合 Spring 可能存在权限绕过"
}, {
	"CVE": "CVE-2020-13933",
	"CVSS": 7.5,
	"DESC": "Apache Shiro 存在权限绕过漏洞"
}, {
	"CVE": "CVE-2020-11989",
	"CVSS": 9.8,
	"DESC": "Apache Shiro 配合 Spring 存在权限绕过漏洞"
}, {
	"CVE": "CVE-2020-1957",
	"CVSS": 9.8,
	"DESC": "Apache Shiro 配合 Spring 存在权限绕过漏洞"
}, {
	"CVE": "CVE-2019-12422",
	"CVSS": 9.8,
	"DESC": "Apache Shiro Padding Oracle 反序列化漏洞"
}, {
	"CVE": "CVE-2016-6802",
	"CVSS": 7.5,
	"DESC": "Apache Shiro 存在权限绕过漏洞"
}, {
	"CVE": "CVE-2016-4437",
	"CVSS": 9.8,
	"DESC": "Apache Shiro 反序列化漏洞"
}, {
	"CVE": "CVE-2014-0074",
	"CVSS": 7.5,
	"DESC": "Apache Shiro LDAP 存在权限绕过漏洞"
}, {
	"CVE": "CVE-2010-3863",
	"CVSS": 5.0,
	"DESC": "Apache Shiro /./account/index.jsp 权限绕过漏洞"
}]