CVE-2010-3863
published 2010-11-05CVE-2010-3863: Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote…
PriorityP351medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
54.80%
98.9th percentile
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | <= 1.0.0 | — |
| debian | shiro | — | — |
| jsecurity | jsecurity | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for URI paths containing non-canonicalized sequences (e.g., /./) in HTTP requests targeting protected resources, which may indicate an attempt to bypass Shiro/JSecurity access control rules defined in shiro.ini. ↗
- →Alert on HTTP GET requests where the URI path contains path traversal sequences such as /./ before a protected resource path segment. ↗
- ·Affected versions are Apache Shiro before 1.1.0 and JSecurity 0.9.x; access control bypass only occurs when URI path canonicalization is absent in the framework's filter chain evaluation against shiro.ini. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.0LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Shiro Path Traversal vulnerability
osv·2022-05-14
CVE-2010-3863 [MEDIUM] Apache Shiro Path Traversal vulnerability
Apache Shiro Path Traversal vulnerability
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
GHSA
Apache Shiro Path Traversal vulnerability
ghsa·2022-05-14
CVE-2010-3863 [MEDIUM] CWE-22 Apache Shiro Path Traversal vulnerability
Apache Shiro Path Traversal vulnerability
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
Debian
CVE-2010-3863: shiro - Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths ...
vendor_debian·2010·CVSS 5.0
CVE-2010-3863 [MEDIUM] CVE-2010-3863: shiro - Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths ...
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
trixie: resolved
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2010-11/0020.htmlhttp://osvdb.org/69067http://secunia.com/advisories/41989http://www.securityfocus.com/archive/1/514616/100/0/threadedhttp://www.securityfocus.com/bid/44616http://www.vupen.com/english/advisories/2010/2888https://exchange.xforce.ibmcloud.com/vulnerabilities/62959http://archives.neohapsis.com/archives/fulldisclosure/2010-11/0020.htmlhttp://osvdb.org/69067http://secunia.com/advisories/41989http://www.securityfocus.com/archive/1/514616/100/0/threadedhttp://www.securityfocus.com/bid/44616http://www.vupen.com/english/advisories/2010/2888https://exchange.xforce.ibmcloud.com/vulnerabilities/62959
2010-11-05
Published