QID 981875
QID 981875: Java (maven) Security Update for org.apache.shiro:shiro-core (GHSA-72w9-fcj5-3fcg)
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-72w9-fcj5-3fcg for updates pertaining to this vulnerability.
Vendor References
- GHSA-72w9-fcj5-3fcg -
github.com/advisories/GHSA-72w9-fcj5-3fcg
CVEs related to QID 981875
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-72w9-fcj5-3fcg | org.apache.shiro:shiro-core |
|