| [{ |
| "CVE": "FastJson-1.2.47", |
| "CVSS": 9.8, |
| "DESC": "FASTJSON 1.2.47 及以下版本存在 RCE 漏洞,利用条件较低,危害较大" |
| }, { |
| "CVE": "FastJson-1.2.68", |
| "CVSS": 9.8, |
| "DESC": "FastJson 1.2.68 及以下版本存在 RCE 漏洞,有一定利用条件" |
| }, { |
| "CVE": "FastJson-1.2.80", |
| "CVSS": 8.1, |
| "DESC": "FastJson 1.2.80 及以下版本存在 RCE 漏洞,有较高利用条件" |
| }, { |
| "CVE": "CVE-2021-45105", |
| "CVSS": 5.9, |
| "DESC": "Apache Log4j2 可能由于不受限制的递归导致拒绝服务" |
| }, { |
| "CVE": "CVE-2021-45046", |
| "CVSS": 9.0, |
| "DESC": "Apache Log4j2 2.15.0 修复不完善,存在拒绝服务和 RCE 漏洞" |
| }, { |
| "CVE": "CVE-2021-44228", |
| "CVSS": 10.0, |
| "DESC": "Apache Log4j2 著名的 Log4Shell 漏洞,利用条件低,危害极大" |
| }, { |
| "CVE": "CVE-2021-44832", |
| "CVSS": 6.6, |
| "DESC": "Apache Log4j2 JDBC Appender 配置可控时存在 RCE 漏洞" |
| }, { |
| "CVE": "CVE-2023-46749", |
| "CVSS": 6.5, |
| "DESC": "Apache Shiro 开启 rewriting 存在目录遍历漏洞" |
| }, { |
| "CVE": "CVE-2023-46750", |
| "CVSS": 6.1, |
| "DESC": "Apache Shiro 开启 form 存在开放重定向漏洞" |
| }, { |
| "CVE": "CVE-2023-34478", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro 某些情况存在目录遍历导致权限绕过" |
| }, { |
| "CVE": "CVE-2023-22602", |
| "CVSS": 7.5, |
| "DESC": "Apache Shiro 配合 SpringBoot 可能存在权限绕过" |
| }, { |
| "CVE": "CVE-2022-40664", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro 存在权限绕过漏洞" |
| }, { |
| "CVE": "CVE-2022-32532", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro 使用 RegExPatternMatcher 存在权限绕过漏洞" |
| }, { |
| "CVE": "CVE-2021-41303", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro 配合 SpringBoot 可能存在权限绕过" |
| }, { |
| "CVE": "CVE-2020-17523", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro 配合 Spring 可能存在权限绕过" |
| }, { |
| "CVE": "CVE-2020-17510", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro 配合 Spring 可能存在权限绕过" |
| }, { |
| "CVE": "CVE-2020-13933", |
| "CVSS": 7.5, |
| "DESC": "Apache Shiro 存在权限绕过漏洞" |
| }, { |
| "CVE": "CVE-2020-11989", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro 配合 Spring 存在权限绕过漏洞" |
| }, { |
| "CVE": "CVE-2020-1957", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro 配合 Spring 存在权限绕过漏洞" |
| }, { |
| "CVE": "CVE-2019-12422", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro Padding Oracle 反序列化漏洞" |
| }, { |
| "CVE": "CVE-2016-6802", |
| "CVSS": 7.5, |
| "DESC": "Apache Shiro 存在权限绕过漏洞" |
| }, { |
| "CVE": "CVE-2016-4437", |
| "CVSS": 9.8, |
| "DESC": "Apache Shiro 反序列化漏洞" |
| }, { |
| "CVE": "CVE-2014-0074", |
| "CVSS": 7.5, |
| "DESC": "Apache Shiro LDAP 存在权限绕过漏洞" |
| }, { |
| "CVE": "CVE-2010-3863", |
| "CVSS": 5.0, |
| "DESC": "Apache Shiro /./account/index.jsp 权限绕过漏洞" |
| }] |