cbcvebase.
CVE-2020-13933
published 2020-08-17

CVE-2020-13933: Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.

PriorityP262high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
44.41%
98.7th percentile
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.

Affected

8 ranges
VendorProductVersion rangeFixed in
apacheshiro< 1.6.01.6.0
apacheshiro>= 0 < 1.3.2-4+deb11u11.3.2-4+deb11u1
apacheshiro>= 0 < 1.3.2-51.3.2-5
apacheshiro>= 0 < 1.3.2-51.3.2-5
apacheshiro>= 0 < 1.3.2-4ubuntu0.21.3.2-4ubuntu0.2
apacheshiro>= 0 < 1.3.2-3ubuntu0.18.04.1~esm11.3.2-3ubuntu0.18.04.1~esm1
debiandebian_linux——
debianshiro< shiro 1.3.2-5 (bookworm)shiro 1.3.2-5 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • →Only web-application components of Apache Shiro are affected: shiro-web, shiro-spring, shiro-guice, and shiro-all artifacts are the ones altered in the fix; shiro-core alone is not impacted ↗
  • →The vulnerability is triggered by a specially crafted HTTP request; monitor for anomalous or malformed HTTP requests targeting Apache Shiro-protected endpoints that result in authentication bypass ↗
  • ·Only Apache Shiro deployments using the web application framework components are vulnerable; camel-shiro (shiro-core only) is not affected ↗
  • ·OpenDaylight (Red Hat OpenStack Platform) is not affected because it implements its own dynamic filter chain rather than using Shiro's web filter chain ↗
  • ·No known mitigation exists for this vulnerability; the only remediation is upgrading to Apache Shiro 1.6.0 or later ↗

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.