VYPR

Shiro

by Apache

Source repositories

CVEs (27)

  • CVE-2016-4437CriKEVJun 7, 2016
    risk 0.79cvss 9.8epss 0.93

    Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

  • CVE-2021-41303CriSep 17, 2021
    risk 0.70cvss 9.8epss 0.77

    Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

  • CVE-2022-32532CriJun 29, 2022
    risk 0.66cvss 9.8epss 0.25

    Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

  • CVE-2020-11989CriJun 22, 2020
    risk 0.66cvss 9.8epss 0.24

    Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

  • CVE-2020-1957CriMar 25, 2020
    risk 0.66cvss 9.8epss 0.23

    Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

  • CVE-2022-40664CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.03

    Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

  • CVE-2020-19229CriApr 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.

  • CVE-2026-49268CriJun 17, 2026
    risk 0.59cvss 9.1epss 0.00

    A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an…

  • CVE-2023-34478CriJul 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro…

  • CVE-2020-17510CriNov 5, 2020
    risk 0.57cvss 9.8epss 0.09

    Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

  • CVE-2020-13933HigAug 17, 2020
    risk 0.53cvss 7.5epss 0.48

    Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.

  • CVE-2023-22602HigJan 14, 2023
    risk 0.49cvss 7.5epss 0.02

    When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot <…

  • CVE-2019-12422HigNov 18, 2019
    risk 0.49cvss 7.5epss 0.09

    Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.

  • CVE-2016-6802HigSep 20, 2016
    risk 0.43cvss 7.5epss 0.10

    Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

  • CVE-2026-43828MedMay 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the…

  • CVE-2026-43827MedMay 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions,…

  • CVE-2023-46749MedJan 15, 2024
    risk 0.42cvss 6.5epss 0.01

    Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this…

  • CVE-2026-48589MedMay 25, 2026
    risk 0.35cvss 5.4epss 0.00

    Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the…

  • CVE-2026-44598MedMay 25, 2026
    risk 0.35cvss 5.4epss 0.00

    With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration…

  • CVE-2023-46750MedDec 14, 2023
    risk 0.33cvss 6.1epss 0.01

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.

Page 1 of 2