Skip to content

Blackduck: Automated PR: Update org.apache.shiro:shiro-core:1.2.4 to 1.13.0 - #11

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
BD-PR-shiro-core_1.2.4_org.apache.shiro-1743703463
Open

Blackduck: Automated PR: Update org.apache.shiro:shiro-core:1.2.4 to 1.13.0#11
github-actions[bot] wants to merge 1 commit into
mainfrom
BD-PR-shiro-core_1.2.4_org.apache.shiro-1743703463

Conversation

@github-actions

@github-actions github-actions Bot commented Apr 3, 2025

Copy link
Copy Markdown

Vulnerabilities associated with org.apache.shiro:shiro-core:1.2.4

BDSA-2016-1727 (HIGH): Apache Shiro is vulnerable to remote code execution (RCE) and information disclosure due to the incorrect configuration of the remember me feature. This could allow an attacker to use a specially crafted request in order to achieve code execution, or to access content that would otherwise be protected by a security constraint.

This vulnerability is listed as exploitable by the Cybersecurity & Infrastructure Security Agency in their Known Exploited Vulnerabilities Catalog.

BDSA-2020-1491 (HIGH): Apache Shiro, when used with Spring dynamic controllers, is vulnerable to an authentication bypass issue. An attacker could bypass authentication using a specially crafted request.

BDSA-2020-2100 (HIGH): Apache Shiro is vulnerable to an authentication bypass vulnerability. An attacker could bypass authentication using a specially crafted HTTP request.

BDSA-2020-3205 (HIGH): Apache Shiro contains an authentication bypass vulnerability. Due to improper authentication an attacker could exploit this flaw using a crafted HTTP request to bypass authentication.

BDSA-2021-0276 (HIGH): Apache Shiro is vulnerable to a potential authentication bypass flaw when used with the Spring framework. A remote attacker could leverage this to bypass certain authentication checks.

BDSA-2021-2804 (HIGH): Apache Shiro is vulnerable to authentication bypass due to an undisclosed issue when Shiro is used with Spring Boot. An attacker could exploit this vulnerability by supplying a system with maliciously crafted HTTP requests.

BDSA-2022-1777 (HIGH): Apache Shiro contains an authorization bypass issue if the RegexRequestMatcher is configured incorrectly. The authorization bypass can be triggered by manipulating the . character within regular expressions.

BDSA-2022-2885 (HIGH): Apache Shiro contains an authentication bypass vulnerability when it is forwarding or including requests using RequestDispatcher component. This could allow an attacker to gain unauthorized access to the application.

BDSA-2023-0069 (HIGH): Apache Shiro is vulnerable to authentication bypass when it is used together with Spring Boot 2.6 and above. The bypass can be exploited via a crafted HTTP request.

BDSA-2023-1909 (HIGH): Apache Shiro contains a path traversal vulnerability when routing requests based on non-normalized requests. Successfully exploiting this could allow an attacker to bypass authentication and gain access to files they do not have permission to view.

CVE-2016-6802 (HIGH): Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

Click Here To See More Details On Server

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants