9.8
CVSSv3

CVE-2023-34478

Published: 24/07/2023 Updated: 15/09/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Apache Shiro, prior to 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache shiro 2.0.0

apache shiro

Vendor Advisories

Debian Bug report logs - #1051228 shiro: CVE-2023-34478 Package: src:shiro; Maintainer for src:shiro is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 4 Sep 2023 18:42:01 UTC Severity: important Tags: security, upstream Found ...