QID 981904
QID 981904: Java (maven) Security Update for org.apache.shiro:shiro-core (GHSA-26gr-cvq3-qxgf)
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-26gr-cvq3-qxgf for updates pertaining to this vulnerability.
Vendor References
- GHSA-26gr-cvq3-qxgf -
github.com/advisories/GHSA-26gr-cvq3-qxgf
CVEs related to QID 981904
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-26gr-cvq3-qxgf | org.apache.shiro:shiro-core |
|