QID 12374

Date Published: 2021-03-31

QID 12374: Apache Shiro Authentication Bypass Vulnerability

Apache Shiro is a powerful and easy-to-use Java security framework that performs authentication, authorization, password and session management.

CVE-2020-17523: Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

Affected Versions:
Apache Shiro before version 1.7.1

QID Detection Logic:
This QID sends GET request to admin/%20 or admin/%2e webpage to detect the vulnerable version of Shiro.

A specially crafted HTTP request may cause an authentication bypass.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised updated to the latest version of Apache Shiro.

    CVEs related to QID 12374

    Software Advisories
    Advisory ID Software Component Link
    Apache shiro URL Logo lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3E