9.8
CVSSv3

CVE-2021-41303

Published: 17/09/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Shiro prior to 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache shiro

oracle financial services crime and compliance management studio 8.0.8.2.0

oracle financial services crime and compliance management studio 8.0.8.3.0

Vendor Advisories

Debian Bug report logs - #1014819 shiro: CVE-2021-41303 Package: src:shiro; Maintainer for src:shiro is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Tue, 12 Jul 2022 14:36:01 UTC Severity: important Tags: security, upstream Reply ...
Apache Shiro before 180, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass Users should update to Apache Shiro 180 ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2021-41303: Apache Shiro before 180, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause ...