Hi, In /nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-thymeleaf-shiro,there is a dependency org.apache.shiro:shiro-web:1.3.2 that calls the risk method.
The scope of this CVE affected version is [,1.6.0)
After further analysis, in this project, the main Api called is org.apache.shiro.web.mgt.CookieRememberMeManager: getRememberedSerializedIdentity(org.apache.shiro.subject.SubjectContext)[B
Hi, In /nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-thymeleaf-shiro,there is a dependency org.apache.shiro:shiro-web:1.3.2 that calls the risk method.
CVE-2020-13933
The scope of this CVE affected version is [,1.6.0)
After further analysis, in this project, the main Api called is org.apache.shiro.web.mgt.CookieRememberMeManager: getRememberedSerializedIdentity(org.apache.shiro.subject.SubjectContext)[B
Risk method repair link : GitHub
CVE Bug Invocation Path--
Path Length : 8
Dependency tree--
Suggested solutions:
Update dependency version
Thank you very much.