NA

CVE-2022-40664

Published: 12/10/2022 Updated: 02/02/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Apache Shiro prior to 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache shiro

Vendor Advisories

Debian Bug report logs - #1021671 shiro: CVE-2022-40664 Package: src:shiro; Maintainer for src:shiro is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 12 Oct 2022 17:48:02 UTC Severity: important Tags: security, upstream Reply ...