CVE-2020-17510
published 2020-11-05CVE-2020-17510: Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
9.06%
94.7th percentile
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.7.0 | 1.7.0 |
| apache | shiro | >= 0 < 1.3.2-4+deb11u1 | 1.3.2-4+deb11u1 |
| apache | shiro | >= 0 < 1.3.2-5 | 1.3.2-5 |
| apache | shiro | >= 0 < 1.3.2-5 | 1.3.2-5 |
| apache | shiro | >= 0 < 1.3.2-4ubuntu0.2 | 1.3.2-4ubuntu0.2 |
| apache | shiro | >= 0 < 1.3.2-3ubuntu0.18.04.1~esm1 | 1.3.2-3ubuntu0.18.04.1~esm1 |
| debian | debian_linux | — | — |
| debian | shiro | < shiro 1.3.2-5 (bookworm) | shiro 1.3.2-5 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →A specially crafted HTTP request may cause an authentication bypass when using Apache Shiro with Spring; monitor for anomalous or malformed HTTP requests targeting Shiro-protected endpoints ↗
- ·Vulnerability only affects Apache Shiro when used in conjunction with Spring; standalone Shiro deployments are not impacted by this specific bypass vector ↗
- ·OpenDaylight (included in Red Hat OpenStack Platform) contains the affected code but the vulnerable function is not used and therefore not exploitable ↗
- ·Red Hat Integration Camel K 1 (camel-shiro package) is confirmed not affected ↗
- ·The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Shiro vulnerabilities
vendor_ubuntu·2023-09-07·CVSS 7.5
CVE-2020-13933 [HIGH] Apache Shiro vulnerabilities
Title: Apache Shiro vulnerabilities
Summary: Several security issues were fixed in Apache Shiro.
It was discovered that Apache Shiro incorrectly handled certain HTTP
requests. A remote attacker could possibly use this issue to bypass
security restrictions. (CVE-2020-13933, CVE-2020-17510)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
shiro: specially crafted HTTP request may cause an authentication bypass
vendor_redhat·2020-11-05·CVSS 9.8
CVE-2020-17510 [CRITICAL] CWE-290 shiro: specially crafted HTTP request may cause an authentication bypass
shiro: specially crafted HTTP request may cause an authentication bypass
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
A flaw was found in Apache shiro. When using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. This highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Whilst the OpenDaylight version that is included in Red Hat OpenStack Platform includes the affected code, the vulnerable function is not used and therefore not exploitable.
Package: camel-shiro (Red Hat Integration Camel K 1) - Not affected
Package: shiro (Red Hat JBoss A-MQ 6) - Out of support scope
Package: shiro-co
Debian
CVE-2020-17510: shiro - Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially craf...
vendor_debian·2020·CVSS 9.8
CVE-2020-17510 [CRITICAL] CVE-2020-17510: shiro - Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially craf...
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Scope: local
bookworm: resolved (fixed in 1.3.2-5)
bullseye: resolved (fixed in 1.3.2-4+deb11u1)
sid: resolved (fixed in 1.3.2-5)
trixie: resolved (fixed in 1.3.2-5)
OSV
shiro vulnerabilities
osv·2023-09-07·CVSS 7.5
CVE-2020-13933 [HIGH] shiro vulnerabilities
shiro vulnerabilities
It was discovered that Apache Shiro incorrectly handled certain HTTP
requests. A remote attacker could possibly use this issue to bypass
security restrictions. (CVE-2020-13933, CVE-2020-17510)
GHSA
Authentication bypass in Apache Shiro
ghsa·2021-04-22
CVE-2020-17510 [CRITICAL] CWE-287 Authentication bypass in Apache Shiro
Authentication bypass in Apache Shiro
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
OSV
Authentication bypass in Apache Shiro
osv·2021-04-22
CVE-2020-17510 [CRITICAL] Authentication bypass in Apache Shiro
Authentication bypass in Apache Shiro
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
OSV
CVE-2020-17510: Apache Shiro before 1
osv·2020-11-05·CVSS 9.8
CVE-2020-17510 [CRITICAL] CVE-2020-17510: Apache Shiro before 1
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r575301804bfac87a064359cf4b4ae9d514f2d10db7d44120765f4129%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r70098e336d02047ce4d4e69293fe8d558cd68cde06f6430398959bc4%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r70b907ccb306e9391145e2b10f56cc6914a245f91720a17a486c020a%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a2a1076817390ac%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r95bdf3703858b5f958b5e190d747421771b430d97095880db91980d6%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc8533625f91253f1d%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rb47d88af224e396ee34ffb88ee99fb6d04510de5722cf14b7137e6bc%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rc2cff2538b683d480426393eecf1ce8dd80e052fbef49303b4f47171%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2111ef7728e48e0%40%3Cdev.shiro.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00002.htmlhttps://lists.apache.org/thread.html/r575301804bfac87a064359cf4b4ae9d514f2d10db7d44120765f4129%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r70098e336d02047ce4d4e69293fe8d558cd68cde06f6430398959bc4%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r70b907ccb306e9391145e2b10f56cc6914a245f91720a17a486c020a%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a2a1076817390ac%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r95bdf3703858b5f958b5e190d747421771b430d97095880db91980d6%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc8533625f91253f1d%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rb47d88af224e396ee34ffb88ee99fb6d04510de5722cf14b7137e6bc%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rc2cff2538b683d480426393eecf1ce8dd80e052fbef49303b4f47171%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2111ef7728e48e0%40%3Cdev.shiro.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00002.html
2020-11-05
Published