Blackduck: Automated PR: Update org.apache.shiro:shiro-core:1.2.4 to 1.13.0 - #11
Open
github-actions[bot] wants to merge 1 commit into
Open
Blackduck: Automated PR: Update org.apache.shiro:shiro-core:1.2.4 to 1.13.0#11github-actions[bot] wants to merge 1 commit into
github-actions[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Vulnerabilities associated with org.apache.shiro:shiro-core:1.2.4
BDSA-2016-1727 (HIGH): Apache Shiro is vulnerable to remote code execution (RCE) and information disclosure due to the incorrect configuration of the
remember mefeature. This could allow an attacker to use a specially crafted request in order to achieve code execution, or to access content that would otherwise be protected by a security constraint.This vulnerability is listed as exploitable by the Cybersecurity & Infrastructure Security Agency in their Known Exploited Vulnerabilities Catalog.
BDSA-2020-1491 (HIGH): Apache Shiro, when used with Spring dynamic controllers, is vulnerable to an authentication bypass issue. An attacker could bypass authentication using a specially crafted request.
BDSA-2020-2100 (HIGH): Apache Shiro is vulnerable to an authentication bypass vulnerability. An attacker could bypass authentication using a specially crafted HTTP request.
BDSA-2020-3205 (HIGH): Apache Shiro contains an authentication bypass vulnerability. Due to improper authentication an attacker could exploit this flaw using a crafted HTTP request to bypass authentication.
BDSA-2021-0276 (HIGH): Apache Shiro is vulnerable to a potential authentication bypass flaw when used with the Spring framework. A remote attacker could leverage this to bypass certain authentication checks.
BDSA-2021-2804 (HIGH): Apache Shiro is vulnerable to authentication bypass due to an undisclosed issue when Shiro is used with Spring Boot. An attacker could exploit this vulnerability by supplying a system with maliciously crafted HTTP requests.
BDSA-2022-1777 (HIGH): Apache Shiro contains an authorization bypass issue if the
RegexRequestMatcheris configured incorrectly. The authorization bypass can be triggered by manipulating the.character within regular expressions.BDSA-2022-2885 (HIGH): Apache Shiro contains an authentication bypass vulnerability when it is forwarding or including requests using
RequestDispatchercomponent. This could allow an attacker to gain unauthorized access to the application.BDSA-2023-0069 (HIGH): Apache Shiro is vulnerable to authentication bypass when it is used together with Spring Boot 2.6 and above. The bypass can be exploited via a crafted HTTP request.
BDSA-2023-1909 (HIGH): Apache Shiro contains a path traversal vulnerability when routing requests based on non-normalized requests. Successfully exploiting this could allow an attacker to bypass authentication and gain access to files they do not have permission to view.
CVE-2016-6802 (HIGH): Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
Click Here To See More Details On Server