Maven package
org.apache.shiro/shiro-web
pkg:maven/org.apache.shiro/shiro-web
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-46750 | — | < 1.13.0 | 1.13.0 | Dec 14, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+. | ||
| CVE-2023-34478 | — | < 1.12.0 | 1.12.0 | Jul 24, 2023 | Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12 | ||
| CVE-2020-17523 | — | < 1.7.1 | 1.7.1 | Feb 3, 2021 | Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. | ||
| CVE-2016-6802 | Hig | 7.5 | < 1.3.2 | 1.3.2 | Sep 20, 2016 | Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path. |
- CVE-2023-46750Dec 14, 2023affected < 1.13.0fixed 1.13.0
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
- CVE-2023-34478Jul 24, 2023affected < 1.12.0fixed 1.12.0
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12
- CVE-2020-17523Feb 3, 2021affected < 1.7.1fixed 1.7.1
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
- affected < 1.3.2fixed 1.3.2
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.