Known Vulnerabilities for Shiro by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Shiro" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-34478 json | Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication... | 9.8 - CRITICAL | 2023-07-24 | 2023-09-15 |
| CVE-2023-22602 json | When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentic... | 7.5 - HIGH | 2023-01-14 | 2023-11-07 |
| CVE-2022-40664 json | Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. | 9.8 - CRITICAL | 2022-10-12 | 2023-02-02 |
| CVE-2022-32532 json | Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications... | 9.8 - CRITICAL | 2022-06-29 | 2022-07-08 |
| CVE-2021-41303 json | Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentica... | 9.8 - CRITICAL | 2021-09-17 | 2023-11-07 |
| CVE-2020-17523 json | Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication ... | 9.8 - CRITICAL | 2021-02-03 | 2023-11-07 |
| CVE-2020-17510 json | Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication ... | 9.8 - CRITICAL | 2020-11-05 | 2023-11-07 |
| CVE-2020-13933 json | Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass. | 7.5 - HIGH | 2020-08-17 | 2023-11-07 |
| CVE-2020-11989 json | Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an ... | 9.8 - CRITICAL | 2020-06-22 | 2023-11-07 |
| CVE-2020-1957 json | Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an ... | 9.8 - CRITICAL | 2020-03-25 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Shiro | 1.7.1 | |||
| Application | Apache | Shiro | 1.7.0 | |||
| Application | Apache | Shiro | 1.6.0 | |||
| Application | Apache | Shiro | 1.5.3 | |||
| Application | Apache | Shiro | 1.5.2 | |||
| Application | Apache | Shiro | 1.5.1 | |||
| Application | Apache | Shiro | 1.5.0 | |||
| Application | Apache | Shiro | 1.4.2 | |||
| Application | Apache | Shiro | 1.4.1 | |||
| Application | Apache | Shiro | 1.4.0 | |||
| Application | Apache | Shiro | 1.4.0 | |||
| Application | Apache | Shiro | 1.4.0 | |||
| Application | Apache | Shiro | 1.3.2 | |||
| Application | Apache | Shiro | 1.3.1 | |||
| Application | Apache | Shiro | 1.3.0 | |||
| Application | Apache | Shiro | 1.2.6 | |||
| Application | Apache | Shiro | 1.2.5 | |||
| Application | Apache | Shiro | 1.2.4 | |||
| Application | Apache | Shiro | 1.2.3 | |||
| Application | Apache | Shiro | 1.2.2 |