QID 997309
Date Published: 2024-02-20
QID 997309: Java (Maven) Security Update for org.apache.shiro:shiro-root (GHSA-3jx9-mgwx-4q83)
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-3jx9-mgwx-4q83 for updates and patch information.
Vendor References
- GHSA-3jx9-mgwx-4q83 -
github.com/advisories/GHSA-3jx9-mgwx-4q83
CVEs related to QID 997309
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3jx9-mgwx-4q83 | org.apache.shiro:shiro-root |
|