Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The project has a shiro deserialization vulnerability #158

Open
linkinyy opened this issue Mar 8, 2024 · 0 comments
Open

The project has a shiro deserialization vulnerability #158

linkinyy opened this issue Mar 8, 2024 · 0 comments

Comments

@linkinyy
Copy link

linkinyy commented Mar 8, 2024

  1. First, build the environment locally to access the backend management system.
    index
  2. You can see that the project's pom.xml file relies on the vulnerable shiro package.
    shiro-package
  3. Using ShiroAttack2 Tools for vulnerability detection. Tool link:https://github.com/SummerSec/ShiroAttack2
    shiro-01
    You can see that Shiro’s secret key was revealed during the explosion.
  4. Detect current Shiro’s exploit chain
    shiro-02
  5. The whoami command was executed successfully, confirming that the vulnerability exists
    shiro-03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant