CVE-2020-11989
published 2020-06-22CVE-2020-11989: Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
24.44%
97.6th percentile
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.5.3 | 1.5.3 |
| apache | shiro | >= 0 < 1.3.2-4+deb11u1 | 1.3.2-4+deb11u1 |
| apache | shiro | >= 0 < 1.3.2-5 | 1.3.2-5 |
| apache | shiro | >= 0 < 1.3.2-5 | 1.3.2-5 |
| apache_software_foundation | apache_shiro | — | — |
| debian | shiro | < shiro 1.3.2-5 (bookworm) | shiro 1.3.2-5 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Authentication bypass occurs when Apache Shiro is used with Spring dynamic controllers and receives a specially crafted request ↗
- ·Vulnerability only affects deployments combining Apache Shiro with Spring dynamic controllers; versions prior to 1.5.3 are affected ↗
- ·OpenDaylight in Red Hat OpenStack Platform includes the affected code but the vulnerable functionality is not used and therefore not exploitable ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Shiro vulnerabilities
vendor_ubuntu·2021-02-18
CVE-2020-1957 Apache Shiro vulnerabilities
Title: Apache Shiro vulnerabilities
Summary: Apache Shiro could be made to crash if it received specially crafted
input.
It was discovered that Apache Shiro mishandled specially crafted requests. An
attacker could use this vulnerability to bypass authentication mechanisms.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass
vendor_redhat·2020-06-22·CVSS 9.8
CVE-2020-11989 [CRITICAL] CWE-305 shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass
shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
A flaw was found in Apache Shiro in versions prior to 1.5.3. When using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Whilst the OpenDaylight version that is included in Red Hat OpenStack Platform includes the affected code, the vulnerable functionality is not used and therefore not exploitable.
Package: shiro-core (Red Hat JBoss A-MQ 6) - Not affected
Pac
Debian
CVE-2020-11989: shiro - Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controlle...
vendor_debian·2020·CVSS 9.8
CVE-2020-11989 [CRITICAL] CVE-2020-11989: shiro - Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controlle...
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Scope: local
bookworm: resolved (fixed in 1.3.2-5)
bullseye: resolved (fixed in 1.3.2-4+deb11u1)
sid: resolved (fixed in 1.3.2-5)
trixie: resolved (fixed in 1.3.2-5)
GHSA
Improper Authentication in Apache Shiro
ghsa·2021-05-07
CVE-2020-11989 [CRITICAL] CWE-287 Improper Authentication in Apache Shiro
Improper Authentication in Apache Shiro
Apache Shiro is a powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management. Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
OSV
Improper Authentication in Apache Shiro
osv·2021-05-07
CVE-2020-11989 [CRITICAL] Improper Authentication in Apache Shiro
Improper Authentication in Apache Shiro
Apache Shiro is a powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management. Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
OSV
CVE-2020-11989: Apache Shiro before 1
osv·2020-06-22·CVSS 9.8
CVE-2020-11989 [CRITICAL] CVE-2020-11989: Apache Shiro before 1
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11989 shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass [fedora-all]
bugzilla·2020-06-23·CVSS 9.8
CVE-2020-11989 [CRITICAL] CVE-2020-11989 shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass [fedora-all]
CVE-2020-11989 shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2020-11989 shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass
bugzilla·2020-06-23·CVSS 9.8
CVE-2020-11989 [CRITICAL] CVE-2020-11989 shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass
CVE-2020-11989 shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Reference:
https://lists.apache.org/thread.html/r72815a124a119c450b86189767d06848e0d380b1795c6c511d54a675%40%3Cuser.shiro.apache.org%3E
Discussion:
Created shiro tracking bugs for this issue:
Affects: fedora-all [bug 1850070]
---
Added affects for Red Hat OpenStack Platform 10 & 13. The vulnerable feature is not used by OpenDaylight.
---
Statement:
Whilst the OpenDaylight version that is included in Red Hat OpenStack Platform includes the affected code, the vulnerable functionality is not used and therefore not exploitable.
https://lists.apache.org/thread.html/r2d2612c034ab21a3a19d2132d47d3e4aa70105008dd58af62b653040%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r408fe60bc8fdfd7c74135249d646d7abadb807ebf90f6fd2b014df21%40%3Cdev.geode.apache.org%3Ehttps://lists.apache.org/thread.html/r72815a124a119c450b86189767d06848e0d380b1795c6c511d54a675%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r72815a124a119c450b86189767d06848e0d380b1795c6c511d54a675%40%3Cuser.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r72815a124a119c450b86189767d06848e0d380b1795c6c511d54a675%40%3Cuser.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rab1972d6b177f7b5c3dde9cfb0a40f03bca75f0eaf1d8311e5762cb3%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rc8b39ea8b3ef71ddc1cd74ffc866546182683c8adecf19c263fe7ac0%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rcf3d8041e1232201fe5d74fc612a193e435784d64002409b448b58fe%40%3Cdev.geode.apache.org%3Ehttps://lists.apache.org/thread.html/r2d2612c034ab21a3a19d2132d47d3e4aa70105008dd58af62b653040%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r408fe60bc8fdfd7c74135249d646d7abadb807ebf90f6fd2b014df21%40%3Cdev.geode.apache.org%3Ehttps://lists.apache.org/thread.html/r72815a124a119c450b86189767d06848e0d380b1795c6c511d54a675%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r72815a124a119c450b86189767d06848e0d380b1795c6c511d54a675%40%3Cuser.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r72815a124a119c450b86189767d06848e0d380b1795c6c511d54a675%40%3Cuser.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rab1972d6b177f7b5c3dde9cfb0a40f03bca75f0eaf1d8311e5762cb3%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rc8b39ea8b3ef71ddc1cd74ffc866546182683c8adecf19c263fe7ac0%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rcf3d8041e1232201fe5d74fc612a193e435784d64002409b448b58fe%40%3Cdev.geode.apache.org%3E
2020-06-22
Published