Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Aurora
APPApache0.10.0 – 0.18.1 (excl.)Apache Shiro
APPApache< 1.2.5Red Hat Fuse
APPRedhat1.0Red Hat Jboss Middleware Text Only Advisories
APPRedhat1.0
CISA KEV — detailsi
- Vendori
- Apache ↗
- Producti
- Shiro
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
Apply updates per vendor instructions.
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
Related vulnerabilities
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
Brak walidacji nagłówka Host w serwerze Undertow HTTP
Apache Aurora — padding oracle umożliwia fałszowanie cookie uwierzytelniającego
Apache Shiro: path traversal prowadzący do obejścia uwierzytelnienia
Apache Shiro – pominięcie uwierzytelnienia przez RequestDispatcher