Critical severity9.8NVD Advisory· Published Sep 17, 2021· Updated Jun 17, 2026
CVE-2021-41303
CVE-2021-41303
Description
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.shiro:shiro-coreMaven | < 1.8.0 | 1.8.0 |
Affected products
11- osv-coords7 versionspkg:deb/ubuntu/shiro?arch=src?distro=focalpkg:maven/org.apache.shiro/shiro-corepkg:deb/ubuntu/shiro?arch=src?distro=noblepkg:deb/ubuntu/shiro?arch=src?distro=esm-apps/xenialpkg:deb/ubuntu/shiro?arch=src?distro=jammypkg:deb/ubuntu/shiro?arch=src?distro=oracularpkg:deb/ubuntu/shiro?arch=src?distro=esm-apps/bionic
>= 0+ 6 more
- (no CPE)range: >= 0
- (no CPE)range: < 1.8.0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- Apache Software Foundation/Apache Shirov5Range: Apache Shiro
cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- www.oracle.com/security-alerts/cpujul2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-f6jp-j6w3-w9hmghsaADVISORY
- lists.apache.org/thread.html/re470be1ffea44bca28ccb0e67a4cf5d744e2d2b981d00fdbbf5abc13%40%3Cannounce.shiro.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-41303ghsaADVISORY
- security.netapp.com/advisory/ntap-20220609-0001/nvdThird Party Advisory
- lists.apache.org/thread.html/raae98bb934e4bde304465896ea02d9798e257e486d04a42221e2c41b@%3Cuser.shiro.apache.org%3EghsaWEB
- security.netapp.com/advisory/ntap-20220609-0001ghsaWEB
- lists.apache.org/thread.html/raae98bb934e4bde304465896ea02d9798e257e486d04a42221e2c41b%40%3Cuser.shiro.apache.org%3Envd
News mentions
0No linked articles in our index yet.