CVE-2016-6802
published 2016-09-20CVE-2016-6802: Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
PriorityP351high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
9.68%
95.0th percentile
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | — | — |
| apache | shiro | >= 0 < 1.3.2-1 | 1.3.2-1 |
| apache | shiro | >= 0 < 1.3.2-1 | 1.3.2-1 |
| apache | shiro | >= 0 < 1.3.2-1 | 1.3.2-1 |
| apache | shiro | >= 0 < 1.2.4-1ubuntu0.1~esm2 | 1.2.4-1ubuntu0.1~esm2 |
| apache | shiro | >= 0 < 1.3.2-5ubuntu0.24.04.1~esm1 | 1.3.2-5ubuntu0.24.04.1~esm1 |
| debian | shiro | < shiro 1.3.2-1 (bookworm) | shiro 1.3.2-1 (bookworm) |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Shiro vulnerabilities
vendor_ubuntu·2024-12-10·CVSS 7.5
CVE-2023-34478 [HIGH] Apache Shiro vulnerabilities
Title: Apache Shiro vulnerabilities
Summary: Several security issues were fixed in Apache Shiro.
It was discovered that Apache Shiro incorrectly handled path traversal when
used with other web frameworks or path rewriting. An attacker could
possibly use this issue to obtain sensitive information or administrative
privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749)
It was discovered that Apache Shiro incorrectly handled web redirects when
used together with the form authentication method. An attacker could
possibly use this issue to perform phishing attacks. This update provides
the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2023-46750)
It was discovered that Apache Shiro incorrectly handled re
Red Hat
Shiro: Security servlet filters bypass
vendor_redhat·2016-09-13·CVSS 7.5
CVE-2016-6802 [HIGH] CWE-287 Shiro: Security servlet filters bypass
Shiro: Security servlet filters bypass
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
Package: shiro-core (Red Hat JBoss A-MQ 6) - Not affected
Package: shiro-core (Red Hat JBoss Fuse 6) - Not affected
Package: shiro-web (Red Hat JBoss Fuse Service Works 6.0) - Affected
Package: shiro-core (Red Hat OpenShift Enterprise 2) - Affected
Debian
CVE-2016-6802: shiro - Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters an...
vendor_debian·2016·CVSS 7.5
CVE-2016-6802 [HIGH] CVE-2016-6802: shiro - Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters an...
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
Scope: local
bookworm: resolved (fixed in 1.3.2-1)
bullseye: resolved (fixed in 1.3.2-1)
sid: resolved (fixed in 1.3.2-1)
trixie: resolved (fixed in 1.3.2-1)
OSV
shiro vulnerabilities
osv·2024-12-10·CVSS 7.5
CVE-2023-34478 [HIGH] shiro vulnerabilities
shiro vulnerabilities
It was discovered that Apache Shiro incorrectly handled path traversal when
used with other web frameworks or path rewriting. An attacker could
possibly use this issue to obtain sensitive information or administrative
privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749)
It was discovered that Apache Shiro incorrectly handled web redirects when
used together with the form authentication method. An attacker could
possibly use this issue to perform phishing attacks. This update provides
the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2023-46750)
It was discovered that Apache Shiro incorrectly handled requests through
servlet filtering. An attacker could possibly use this issue
GHSA
Improper Access Control in Apache Shiro
ghsa·2022-05-14
CVE-2016-6802 [HIGH] CWE-284 Improper Access Control in Apache Shiro
Improper Access Control in Apache Shiro
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
OSV
Improper Access Control in Apache Shiro
osv·2022-05-14
CVE-2016-6802 [HIGH] Improper Access Control in Apache Shiro
Improper Access Control in Apache Shiro
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
OSV
CVE-2016-6802: Apache Shiro before 1
osv·2016-09-20·CVSS 7.5
CVE-2016-6802 [HIGH] CVE-2016-6802: Apache Shiro before 1
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6802 Apache Shiro: Security servlet filters bypass [fedora-24]
bugzilla·2016-09-14·CVSS 7.5
CVE-2016-6802 [HIGH] CVE-2016-6802 Apache Shiro: Security servlet filters bypass [fedora-24]
CVE-2016-6802 Apache Shiro: Security servlet filters bypass [fedora-24]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussion
Bugzilla
CVE-2016-6802 Apache Shiro: Security servlet filters bypass
bugzilla·2016-09-14·CVSS 7.5
CVE-2016-6802 [HIGH] CVE-2016-6802 Apache Shiro: Security servlet filters bypass
CVE-2016-6802 Apache Shiro: Security servlet filters bypass
Apache Shiro before 1.3.2, when using a non-root servlet context path, specifically crafted requests can be used to by pass some security servlet filters, resulting in unauthorized access.
References:
http://seclists.org/oss-sec/2016/q3/488
Discussion:
Created shiro tracking bugs for this issue:
Affects: fedora-24 [bug 1375885]
---
shiro-1.3.2-1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.
http://packetstormsecurity.com/files/138709/Apache-Shiro-Filter-Bypass.htmlhttp://www.securityfocus.com/archive/1/539397/100/0/threadedhttp://www.securityfocus.com/bid/92947http://packetstormsecurity.com/files/138709/Apache-Shiro-Filter-Bypass.htmlhttp://www.securityfocus.com/archive/1/539397/100/0/threadedhttp://www.securityfocus.com/bid/92947
2016-09-20
Published