CVE-2020-1957
published 2020-03-25CVE-2020-1957: Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
PriorityP184critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
24.16%
97.6th percentile
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.5.2 | 1.5.2 |
| apache | shiro | >= 0 < 1.3.2-4+deb11u1 | 1.3.2-4+deb11u1 |
| apache | shiro | >= 0 < 1.3.2-5 | 1.3.2-5 |
| apache | shiro | >= 0 < 1.3.2-5 | 1.3.2-5 |
| apache_software_foundation | apache_shiro | <= 2.99.99 | — |
| apache_software_foundation | apache_shiro | 3.0.0-alpha-0 – 3.0.0-alpha-1 | — |
| debian | debian_linux | — | — |
| debian | shiro | < shiro 1.3.2-5 (bookworm) | shiro 1.3.2-5 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Authentication bypass occurs specifically when Apache Shiro is used together with Spring dynamic controllers — detection should focus on requests that exploit URL path discrepancies between Shiro's filter chain and Spring's controller routing. ↗
- →The vulnerability affects Apache Shiro versions prior to 1.5.2; identify and flag any deployment running Shiro < 1.5.2 combined with Spring dynamic controllers as at-risk. ↗
- →Threat impact spans confidentiality, integrity, and availability — monitor for unauthorized access to protected resources following anomalous request patterns to Spring-mapped endpoints. ↗
- ·OpenDaylight (as shipped in Red Hat OpenStack Platform) includes the affected Shiro code but the vulnerable function is not used, making it not exploitable in that context. ↗
- ·Red Hat Fuse 7, JBoss A-MQ 6, JBoss Fuse 6, and JBoss Fuse Service Works 6 ship shiro-core but are listed as Not Affected, so detections targeting those products should be suppressed to avoid false positives. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Shiro vulnerabilities
vendor_ubuntu·2021-02-18
CVE-2020-1957 Apache Shiro vulnerabilities
Title: Apache Shiro vulnerabilities
Summary: Apache Shiro could be made to crash if it received specially crafted
input.
It was discovered that Apache Shiro mishandled specially crafted requests. An
attacker could use this vulnerability to bypass authentication mechanisms.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass
vendor_redhat·2020-03-25·CVSS 9.8
CVE-2020-1957 [CRITICAL] CWE-287 shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass
shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
A flaw was found in Apache Shiro. When using Spring dynamic controllers, a specially crafted request may cause an authentication bypass. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Whilst the OpenDaylight version that is included in Red Hat OpenStack Platform includes the affected code, the vulnerable function is not used and therefore not exploitable.
Package: shiro-core (Red Hat Fuse 7) - Not affected
Package: shiro-core (Red Hat JBoss A-MQ 6) - Not affected
Debian
CVE-2020-1957: shiro - Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controlle...
vendor_debian·2020·CVSS 9.8
CVE-2020-1957 [CRITICAL] CVE-2020-1957: shiro - Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controlle...
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Scope: local
bookworm: resolved (fixed in 1.3.2-5)
bullseye: resolved (fixed in 1.3.2-4+deb11u1)
sid: resolved (fixed in 1.3.2-5)
trixie: resolved (fixed in 1.3.2-5)
GHSA
When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass.
ghsa_unreviewed·2026-06-25·CVSS 9.8
CVE-2026-56091 [CRITICAL] CWE-289 When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass.
When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass.
This vulnerability is similar to https://www.cve.org/CVERecord?id=CVE-2020-1957 https://www.cve.org/CVERecord , except that it affects the `shiro-guice` module instead of the `shiro-spring` module.
This issue affects all Apache Shiro versions through 2.x, and 3.0.0-alpha-1 only when using `shiro-guice` module in a web servlet context.
Upgrade to version 3.0.0 or later, which fixes the issue.
GHSA
Improper Authentication in Apache Shiro
ghsa·2021-05-07
CVE-2020-1957 [CRITICAL] CWE-287 Improper Authentication in Apache Shiro
Improper Authentication in Apache Shiro
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
OSV
Improper Authentication in Apache Shiro
osv·2021-05-07
CVE-2020-1957 [CRITICAL] Improper Authentication in Apache Shiro
Improper Authentication in Apache Shiro
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
OSV
CVE-2020-1957: Apache Shiro before 1
osv·2020-03-25·CVSS 9.8
CVE-2020-1957 [CRITICAL] CVE-2020-1957: Apache Shiro before 1
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
VulnCheck
Apache Shiro with Spring Dynamic Controllers Authentication Bypass
vulncheck·2020·CVSS 9.8
CVE-2020-1957 [CRITICAL] Apache Shiro with Spring Dynamic Controllers Authentication Bypass
Apache Shiro with Spring Dynamic Controllers Authentication Bypass
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Affected: Apache Shiro
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/
No detection rules found.
No public exploits indexed.
Unit42
Network Attack Trends: Internet of Threats (November 2020-January 2021)
blogs_unit42·2021-04-12·CVSS 7.5
CVE-2020-28188 [HIGH] Network Attack Trends: Internet of Threats (November 2020-January 2021)
# Executive Summary
Unit 42 researchers analyzed network attack trends over Winter 2020 and discovered many interesting exploits in the wild. During the period of Nov. 2020 to Jan. 2021, the majority of the attacks we observed were classified as critical (75%), compared to the 50.4% we reported in the fall of 2020. Several newly observed exploits, including CVE-2020-28188, CVE-2020-17519, and CVE-2020-29227, have emerged and were continuously being exploited in the wild as of late 2020 to early 2021.
This blog provides details of the newly observed exploits as well as a dive deep into the exploitation analysis, vendor analysis, attack origin, and attack category distribution.
Palo Alto Networks Next-Generation Firewall customers are protected from these attacks with the URL Filtering an
Unit42
Network Attack Trends: Internet of Threats (November 2020-January 2021)
blogs_unit42·2021-04-12·CVSS 7.5
[HIGH] Network Attack Trends: Internet of Threats (November 2020-January 2021)
Threat Research Center
Trend Reports
Vulnerabilities
## Network Attack Trends: Internet of Threats (November 2020-January 2021)
Lei Xu
Yue Guan
Vaibhav Singhal
Published: April 12, 2021
Malware
Trend Reports
Vulnerabilities
Botnet
DDoS
Exploit kit
IoT
Network security trends
## Executive Summary
Unit 42 researchers analyzed network attack trends over Winter 2020 and discovered many interesting exploits in the wild. During the period of Nov. 2020 to Jan. 2021, the majority of the attacks we observed were classified as critical (75%), compared to the 50.4% we reported in the fall of 2020 . Several newly observed exploits, including CVE-2020-28188 , CVE-2020-17519 , and CVE-2020-29227 , have emerged and were continuously being exploited in the wild as of late 2020 to earl
Bugzilla
CVE-2020-2230 jenkins: stored XSS vulnerability in project naming strategy
bugzilla·2020-09-03·CVSS 5.4
CVE-2020-2230 [MEDIUM] CVE-2020-2230 jenkins: stored XSS vulnerability in project naming strategy
CVE-2020-2230 jenkins: stored XSS vulnerability in project naming strategy
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description that is displayed on item creation. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
Discussion:
External References:
https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1957
---
Created jenkins tracking bugs for this issue:
Affects: fedora-31 [bug 1875233]
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3841 https://access.redhat.com/errata/RHSA-2020:3841
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(
Bugzilla
CVE-2020-1957 shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass
bugzilla·2020-04-29·CVSS 9.8
CVE-2020-1957 [CRITICAL] CVE-2020-1957 shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass
CVE-2020-1957 shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass
When using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Upstream Advisory:
https://lists.apache.org/thread.html/r17f371fc89d34df2d0c8131473fbc68154290e1be238895648f5a1e6%40%3Cdev.shiro.apache.org%3E
Discussion:
Created shiro tracking bugs for this issue:
Affects: fedora-all [bug 1829282]
---
Statement:
Whilst the OpenDaylight version that is included in Red Hat OpenStack Platform includes the affected code, the vulnerable function is not used and therefore not exploitable.
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/s
Bugzilla
CVE-2020-1957 shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass [fedora-all]
bugzilla·2020-04-29·CVSS 9.8
CVE-2020-1957 [CRITICAL] CVE-2020-1957 shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass [fedora-all]
CVE-2020-1957 shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
https://lists.apache.org/thread.html/r17f371fc89d34df2d0c8131473fbc68154290e1be238895648f5a1e6%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r2d2612c034ab21a3a19d2132d47d3e4aa70105008dd58af62b653040%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rab1972d6b177f7b5c3dde9cfb0a40f03bca75f0eaf1d8311e5762cb3%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rb3982edf8bc8fcaa7a308e25a12d294fb4aac1f1e9d4e14fda639e77%40%3Cdev.geode.apache.org%3Ehttps://lists.apache.org/thread.html/rc64fb2336683feff3580c3c3a8b28e80525077621089641f2f386b63%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/rc8b39ea8b3ef71ddc1cd74ffc866546182683c8adecf19c263fe7ac0%40%3Ccommits.shiro.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/04/msg00014.htmlhttps://lists.apache.org/thread.html/r17f371fc89d34df2d0c8131473fbc68154290e1be238895648f5a1e6%40%3Cdev.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/r2d2612c034ab21a3a19d2132d47d3e4aa70105008dd58af62b653040%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rab1972d6b177f7b5c3dde9cfb0a40f03bca75f0eaf1d8311e5762cb3%40%3Ccommits.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/rb3982edf8bc8fcaa7a308e25a12d294fb4aac1f1e9d4e14fda639e77%40%3Cdev.geode.apache.org%3Ehttps://lists.apache.org/thread.html/rc64fb2336683feff3580c3c3a8b28e80525077621089641f2f386b63%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/rc8b39ea8b3ef71ddc1cd74ffc866546182683c8adecf19c263fe7ac0%40%3Ccommits.shiro.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/04/msg00014.html
2020-03-25
Published
Exploited in the wild