QID 996715
Date Published: 2024-01-17
QID 996715: Java (Maven) Security Update for org.apache.shiro:shiro-core (GHSA-jc7h-c423-mpjc)
Apache Shiro before 1.130 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-jc7h-c423-mpjc for updates and patch information.
Vendor References
- GHSA-jc7h-c423-mpjc -
github.com/advisories/GHSA-jc7h-c423-mpjc
CVEs related to QID 996715
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jc7h-c423-mpjc | org.apache.shiro:shiro-core |
|