CVE-2021-41303
published 2021-09-17CVE-2021-41303: Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update…
PriorityP275critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
76.66%
99.5th percentile
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.8.0 | 1.8.0 |
| apache_software_foundation | apache_shiro | >= Apache Shiro < 1.8.0 | 1.8.0 |
| debian | shiro | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Apply the Fortinet IPS signature 'Apache.Shiro.Authentication.Bypass' (released 11 August 2022) to detect and block exploitation attempts against CVE-2021-41303. ↗
- ·The authentication bypass only affects deployments where Apache Shiro is used together with Spring Boot. Standalone Shiro deployments or other integrations are not impacted by this specific bypass vector. ↗
- ·Red Hat OpenStack Platform's OpenDaylight includes the affected code but the vulnerable function is not used, making it not exploitable in that specific configuration. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Shiro) — CVE-2021-41303
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2021-41303 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Shiro) — CVE-2021-41303
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Shiro) vulnerability
CVE: CVE-2021-41303
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Red Hat
shiro: specially crafted HTTP request may cause an authentication bypass
vendor_redhat·2021-09-16·CVSS 9.8
CVE-2021-41303 [CRITICAL] CWE-287 shiro: specially crafted HTTP request may cause an authentication bypass
shiro: specially crafted HTTP request may cause an authentication bypass
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
A flaw was found in Apache Shiro. When using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. The highest threat from this vulnerability is to data confidentiality, integrity as well as system availability.
Statement: Although Red Hat OpenStack Platform's OpenDaylight includes the affected code, the vulnerable function is not used, therefore, not exploitable. For this reason, the RHOSP impact is low, and no update will be provided at this time for OpenDaylight.
Package: shiro-web (Red Hat Fu
Debian
CVE-2021-41303: shiro - Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially...
vendor_debian·2021·CVSS 9.8
CVE-2021-41303 [CRITICAL] CVE-2021-41303: shiro - Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially...
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
Scope: local
bookworm: open
bullseye: open
sid: open
trixie: open
GHSA
Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
ghsa·2021-09-20
CVE-2021-41303 [CRITICAL] CWE-287 Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
OSV
Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
osv·2021-09-20
CVE-2021-41303 [CRITICAL] Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
OSV
CVE-2021-41303: Apache Shiro before 1
osv·2021-09-17·CVSS 9.8
CVE-2021-41303 [CRITICAL] CVE-2021-41303: Apache Shiro before 1
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
No detection rules found.
No public exploits indexed.
Fortinet
More Path Filter Bypass Vulnerabilities on Java Open Source Projects | FortiGuard Labs
blogs_fortinet·2022-09-09·CVSS 9.8
[CRITICAL] More Path Filter Bypass Vulnerabilities on Java Open Source Projects | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
More Path Filter Bypass Vulnerabilities on Java Open Source Projects
By Thanh Nguyen Nguyen | September 09, 2022
A Uniform Resource Locator (URL), colloquially termed a web address, comprises five components: scheme, authority, path, query, and fragment. Each element is shown in this example: http://host-authority/path/?query-param=1#fragment
In the web application world, an URL path is always used to map a web request to a designated web service on the backend. As a security precaution, a web application typically has a path filter mechanism to prevent an unauthorized user from exploiting an unintended functionality via URL.
The Java web framework is one of the most widely deployed web services on the Internet. Based on our experience, many web servlets
Wiz
CVE-2026-23901 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-23901 [CRITICAL] CVE-2026-23901 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23901 :
Apache Shiro vulnerability analysis and mitigation
Observable Timing Discrepancy vulnerability in Apache Shiro.
This issue affects Apache Shiro: from 1. , 2. before 2.0.7.
Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue.
Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough,
that a brute-force attack may be able to tell, by timing the requests only, determine if
the request failed because of a non-existent user vs. wrong password.
The most likely attack vector is a local attack only.
Shiro security model https://shiro.apache.org/security-model.html#username_enumeration discusses this as well.
Typically, brute force attack can be mitigated at the infrastructure level.
Source : NVD
## 1
Scor
https://lists.apache.org/thread.html/raae98bb934e4bde304465896ea02d9798e257e486d04a42221e2c41b%40%3Cuser.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/re470be1ffea44bca28ccb0e67a4cf5d744e2d2b981d00fdbbf5abc13%40%3Cannounce.shiro.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20220609-0001/https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://lists.apache.org/thread.html/raae98bb934e4bde304465896ea02d9798e257e486d04a42221e2c41b%40%3Cuser.shiro.apache.org%3Ehttps://lists.apache.org/thread.html/re470be1ffea44bca28ccb0e67a4cf5d744e2d2b981d00fdbbf5abc13%40%3Cannounce.shiro.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20220609-0001/https://www.oracle.com/security-alerts/cpujul2022.html
2021-09-17
Published