cbcvebase.
CVE-2020-13933
published 2020-08-17

CVE-2020-13933: Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.

PriorityP262high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
48.02%
98.7th percentile
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.

Affected

8 ranges
VendorProductVersion rangeFixed in
apacheshiro< 1.6.01.6.0
apacheshiro>= 0 < 1.3.2-4+deb11u11.3.2-4+deb11u1
apacheshiro>= 0 < 1.3.2-51.3.2-5
apacheshiro>= 0 < 1.3.2-51.3.2-5
apacheshiro>= 0 < 1.3.2-4ubuntu0.21.3.2-4ubuntu0.2
apacheshiro>= 0 < 1.3.2-3ubuntu0.18.04.1~esm11.3.2-3ubuntu0.18.04.1~esm1
debiandebian_linux
debianshiro< shiro 1.3.2-5 (bookworm)shiro 1.3.2-5 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Only web-application components of Apache Shiro are affected: shiro-web, shiro-spring, shiro-guice, and shiro-all artifacts are the ones altered in the fix; shiro-core alone is not impacted
  • The vulnerability is triggered by a specially crafted HTTP request; monitor for anomalous or malformed HTTP requests targeting Apache Shiro-protected endpoints that result in authentication bypass
  • ·Only Apache Shiro deployments using the web application framework components are vulnerable; camel-shiro (shiro-core only) is not affected
  • ·OpenDaylight (Red Hat OpenStack Platform) is not affected because it implements its own dynamic filter chain rather than using Shiro's web filter chain
  • ·No known mitigation exists for this vulnerability; the only remediation is upgrading to Apache Shiro 1.6.0 or later

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.