QID 12374
Date Published: 2021-03-31
QID 12374: Apache Shiro Authentication Bypass Vulnerability
Apache Shiro is a powerful and easy-to-use Java security framework that performs authentication, authorization, password and session management.
CVE-2020-17523: Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Affected Versions:
Apache Shiro before version 1.7.1
QID Detection Logic:
This QID sends GET request to admin/%20 or admin/%2e webpage to detect the vulnerable version of Shiro.
A specially crafted HTTP request may cause an authentication bypass.
Solution
Customers are advised updated to the latest version of Apache Shiro.
Vendor References
CVEs related to QID 12374
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache shiro |
|