Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
BID:65935
Info
Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
| Bugtraq ID: | 65935 |
| Class: | Configuration Error |
| CVE: |
CVE-2014-0074 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2014 12:00AM |
| Updated: | Feb 21 2014 12:00AM |
| Credit: | skis |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
Apache Shiro is prone to a remote authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Versions prior to Apache Shiro 1.2.3 are vulnerable.
Apache Shiro is prone to a remote authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Versions prior to Apache Shiro 1.2.3 are vulnerable.
Solution / Fix
Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
References:
References:
- Active Directory succeeds even if the user name and password is not passed. (Apache Software Foundation)
- Apache Shiro Homepage (Apache)
- Download Apache Shiro (Apache Software Foundation)