QID 730496
Date Published: 2022-05-25
QID 730496: Apache Shiro Remote Code Execution (RCE) Vulnerability
Apache Shiro is an open source software security framework that performs authentication, authorization, cryptography and session management.
CVE-2016-4437: Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Affected Versions:
Apache Shiro versions prior to 1.2.5
QID Detection Logic(Unauthenticated):
This QID checks for vulnerable Apache Shiro by sending a specially crafted payload for command execution or make a query that will trigger Qualys Periscope detection mechanism.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary command on the target system.
Either ensure a secret cipher key is configured, or disable the 'remember me' feature.
- Apache Shiro Advisory -
shiro.apache.org/security-reports.html#cve_2016_4437
CVEs related to QID 730496
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Shiro Advisory |
|