QID 981373
QID 981373: Java (maven) Security Update for org.apache.shiro:shiro-spring (GHSA-7cj4-gj8m-m2f7)
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7cj4-gj8m-m2f7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-7cj4-gj8m-m2f7 -
github.com/advisories/GHSA-7cj4-gj8m-m2f7
CVEs related to QID 981373
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7cj4-gj8m-m2f7 | org.apache.shiro:shiro-spring |
|