CVE-2021-41303

Related Vulnerabilities: CVE-2021-41303  

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

Description

The MITRE CVE dictionary describes this issue as:

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

Additional Information

  • Bugzilla 2006058: CVE-2021-41303 shiro: specially crafted HTTP request may cause an authentication bypass
  • CWE-287: Improper Authentication
  • FAQ: Frequently asked questions about CVE-2021-41303