CVE-2020-17523
published 2021-02-03CVE-2020-17523: Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
PriorityP275critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
85.91%
99.7th percentile
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.7.1 | 1.7.1 |
| debian | shiro | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Authentication bypass in Apache Shiro before 1.7.1 when used with Spring is triggered by a specially crafted HTTP request ↗
- ·Vulnerability only applies when Apache Shiro is used together with Spring; standalone Shiro deployments are not affected by this specific bypass vector ↗
- ·Red Hat OpenStack Platform's OpenDaylight includes the affected code but the vulnerable function is not used and therefore not exploitable; RHOSP impact is rated low and no update will be provided for OpenDaylight ↗
- ·The fix is present in Apache Shiro 1.7.1; any deployment running an earlier version with Spring integration should be considered vulnerable ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Authentication bypass in Apache Shiro
osv·2022-02-09
CVE-2020-17523 [CRITICAL] Authentication bypass in Apache Shiro
Authentication bypass in Apache Shiro
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
GHSA
Authentication bypass in Apache Shiro
ghsa·2022-02-09
CVE-2020-17523 [CRITICAL] CWE-287 Authentication bypass in Apache Shiro
Authentication bypass in Apache Shiro
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
OSV
CVE-2020-17523: Apache Shiro before 1
osv·2021-02-03·CVSS 9.8
CVE-2020-17523 [CRITICAL] CVE-2020-17523: Apache Shiro before 1
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Red Hat
shiro: Authentication bypass through specially crafted HTTP request
vendor_redhat·2021-01-01·CVSS 9.8
CVE-2020-17523 [CRITICAL] CWE-305 shiro: Authentication bypass through specially crafted HTTP request
shiro: Authentication bypass through specially crafted HTTP request
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
A flaw was found in Apache Shiro. When using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. The highest threat from this vulnerability is to data confidentiality, integrity as well as system availability.
Statement: Although Red Hat OpenStack Platform's OpenDaylight includes the affected code, the vulnerable function is not used and therefore not exploitable. For this reason, the RHOSP impact is low and no update will be provided at this time for OpenDaylight.
Package: shiro-core (Red Hat Fuse 7) - Will not fix
Package: shiro-core (Red Hat
Debian
CVE-2020-17523: shiro - Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially craf...
vendor_debian·2020·CVSS 9.8
CVE-2020-17523 [CRITICAL] CVE-2020-17523: shiro - Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially craf...
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r5b93ddf97e2c4cda779d22fab30539bdec454cfa5baec4ad0ffae235%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r679ca97813384bdb1a4c087810ba44d9ad9c7c11583979bb7481d196%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a2a1076817390ac%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc8533625f91253f1d%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rd4b613e121438b97e3eb263cac3137caddb1dbd8f648b73a4f1898a6%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2111ef7728e48e0%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r5b93ddf97e2c4cda779d22fab30539bdec454cfa5baec4ad0ffae235%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r679ca97813384bdb1a4c087810ba44d9ad9c7c11583979bb7481d196%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a2a1076817390ac%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc8533625f91253f1d%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rd4b613e121438b97e3eb263cac3137caddb1dbd8f648b73a4f1898a6%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2111ef7728e48e0%40%3Cdev.shiro.apache.org%3E
2021-02-03
Published